11 ms·
Lasershark: Fast, bidirectional communication into air-gapped systems
- abi 5y agoHow do I go about installing receiver in the air-gapped system in the first place? I'm a little confused on that.
- kybernetyk 5y agoYes, and why not install a WiFi dongle instead if I have physical access?
- lann 5y agoTo this specific point, SCIFs (https://en.m.wikipedia.org/wiki/Sensitive_compartmented_information_facility https://en.m.wikipedia.org/wiki/Sensitive_compartmented_info...) are (allegedly) protected by faraday cages.
- tgsovlerkhgsel 5y agoThis does not help with the initial compromise, but they demonstrate that with a software-only change, you can use existing LEDs as receivers in addition to senders!
- abi 5y agoCool, good to know!
- iam-TJ 5y agoOne caveat to note is the LED needs to be connected to a GPIO port that the software can control. That leads to the obvious question for high-value systems that may be targeted - presumably fixed systems not laptops/notebooks/tablets - are the activity/power LEDs commonly connected via software-controlled GPIOs or mostly part of the electronic circuit only ?
- R0b0t1 5y agoThey are usually connected to software controlled GPIOs, or at least should be assumed to be connected to them. What is not normal (for now) is analog peripherals hanging off of arbitrary pins or even being on the chip. Looks like it's all doable digitally. For a lot of chips changing the purpose of a pin may not be possible unless you are a nation state and have all of the design info on an ASIC.
- bentcorner 5y agoThe pre-print goes over the infiltration process - basically you shoot a laser at an LED on the air-gapped system, it induces a current, and you measure that current.
- jonititan 5y agoIt's neat but the characterisation of the sensing potential of LEDs as relatively unknown is laughable. It's been known as far back as Forest Mims seminal books on circuits.
- yencabulator 5y agoThe pull quote I wanted to see: > While LEDs are designed to emit light and can thus unnoticeably encode information through high-frequency flickering, their ability to also perceive light is largely unknown in the security community. In particular, by directing a laser on the LEDs of office devices, we induce a measurable current in the hardware that can be picked up by its firmware and used to receive incoming data.
- camjohnson26 5y agoReminds me of this tweet: “Tech enthusiasts: My entire house is smart. Tech workers: The only piece of technology in my house is a printer and I keep a gun next to it so I can shoot it if it makes a noise I don't recognize.” Honestly I’m starting to operate under the assumption that anything can be hacked with enough focus and determination. Obscurity isn’t such a bad defense in the long run. https://twitter.com/PPathole/status/1116670170980859905?s=20&t=U49p7sakIHZgs4IXwbqtIQ https://twitter.com/PPathole/status/1116670170980859905?s=20...
- batch12 5y agoAs a part of a defense-in-depth strategy, sure. Where we get in trouble is when it's the only layer.
- buscoquadnary 5y agoTo this I respond with the only valuable treat matrix for an individual I've ever seen. Threat: Ex-girlfriend/boyfriend breaking into your email account and publicly releasing your correspondence with the My Little Pony fan club Solution: Strong Passwords Threat: Organized criminals breaking into your email account and sending spam using your identity Solution: Strong passwords + common sense (don’t click on unsolicited herbal Viagra ads that result in keyloggers and sorrow) Threat: The Mossad doing Mossad things with your email account Solution: ◆ Magical amulets? ◆ Fake your own death, move into a submarine? ◆ YOU’RE STILL GONNA BE MOSSAD’ED UPON All credit to James Mickens for the above. My point being that if someone is that committed to compromising your air gapped system they're going to find a way. Especially if they can just slip the janitor $10,000 to put a USB labelled "Barely Legal Gone Wild" into the machine while vaccumming.
- na85 5y ago> Especially if they can just slip the janitor $10,000 to put a USB labelled "Barely Legal Gone Wild" into the machine while vaccumming. Part of Defensive Depth includes vetting and requiring the janitor who cleans the SCIF to themselves also hold a security clearance. Your cited example is also why Counterintelligence is a thing. It's not enough to trust your processes; you also have to probe them. When I was in the military I met a guy whose job was to pentest (among other things) nuclear weapons facilities and NORAD defense installations, specifically their computer equipment. He had some pretty wild stories; suffice it to say the ladder trick doesn't work when you are trying to access an ICBM solo.
- vajrabum 5y agoI'd guess that means that going forward security conscious people will be putting tape or covers over not only their cameras but also over their LEDs. In high security settings the buildings have no windows or have fake windows to keep external laser signals out so that's not new. That's been true since about the time someone figured out you can reconstruct audio from the doppler of a laser reflected off windows.
- t-3 5y agoI already cover all the LEDs with electrical tape. Not for security, just because I hate unnecessary, over-bright blue lights shining everywhere.
- sgc 5y agoI recently learned the black sharpie tip somewhere. It works like a charm.
- suifbwish 5y agoWouldn’t they need physical access or at least line of sight to the machine for this? Lasers don’t go through walls or metal
- Ansil849 5y ago> or at least line of sight to the machine for this? Correct, and not just line of sight, but static line of sight. The potential scenario here is something like if there is a desk phone on someone's desk visible from the window that you want to monitor (and you also manage to successfully install custom firmware on the phone).
- suifbwish 5y agoHmm I was under the impression that this attack was for spying on airgapped systems. I have never heard of an airgapped phone, unless it’s just for internal purposes.
- anfractuosity 5y agoRelated to reading information from LEDs, thought this paper was cool - http://www.applied-math.org/optical_tempest.pdf http://www.applied-math.org/optical_tempest.pdf (from 2002) "Dial-up and leased-line modems were found to faithfully broadcast data transmitted and received by the device" Edit: Also it looks like Loughry has proposed similar work, using lasers and LEDs https://arxiv.org/pdf/1907.00479.pdf https://arxiv.org/pdf/1907.00479.pdf
- KennyBlanken 5y agoResearch 10+ years ago found that activity lights on many network cards and switches at 10BaseT could reveal actual network traffic. Very quickly, major device manufacturers switched to buffered activity LEDs and the attack became useless. I remember at one point modems switched from flickering with actual traffic to just slow blinking with activity.
- jppope 5y agoI had to upvote just based on the name. the doctor evil reference is hilarious
- deleted 5y ago[deleted]
- forgotmyoldacc 5y agoHow often are attackers hacking a air-gapped device but have line of sight? It seems fairly implausible.
- phoe-krk 5y agoA telescope looking through a proper window at nighttime could be enough. Some LEDs are powerful enough to illuminate a large chunk of an otherwise dark room.
- jaywalk 5y agoThe point is that the air-gapped system would have to be compromised first.
- 0xCMP 5y agoAnd not in a windowless room already. How many air gapped systems are running next to a Window? Although I guess you can use this as evidence: if it needs to be air-gapped it also needs to be in a windowless room or some kind of sealed container.
- bentcorner 5y agoHow long before we have people shooting cosmic rays at air-gapped systems in windowless rooms and measuring bit flips?
- rgj 5y agoMost of the time the system is compromised before being in an air gapped setup, for instance in the supply chain.
- deleted 5y ago[deleted]
- locusofself 5y agoRight. In the SCIFs I have been in, if there even are windows, the blinds remain drawn at all times.
- Jerrrry 5y agoyou can exfiltrate data at a bit/hour through power consumption. Run while(1){sin(cos(tan(rand(1))) for 1, nothing for 0, every half hour, with a correctional bit thrown in for good measure. measure the heat of the room via remote sensing, power consumption, AC/air frequency analysis. the NSA will have to add a layer of thermodynamic static noise in addition to their rooms full of stereo's blasting white noise. a technically proficient attacker could infer the value of a encryption key given the GDP of the nation-state, if the data was granular enough.
- aaaaaaaaaaab 5y ago>a technically proficient attacker could infer the value of a encryption key given the GDP of the nation-state, if the data was granular enough Hm. So maybe the recent spike in inflation is just a series of ones in an RSA key?
- extrapickles 5y agoAdding noise helps, but an attacker can trade bitrate for noise immunity. Probably the only way of keeping data secure would be to heavily insulate (noise, thermal, RF, power, etc) the room so that any signal would take weeks to pass through the insulation, and then rotate your key material more often than that. Opening the door would have to dump power to the room before the door can be opened so an attacker couldn't leak data out when people entered/left.
- Jerrrry 5y agorotating the keys quicker than they can be exfiltrated, and expanded. similar to the original reason password rotation exists - that the hashes of passwords to all users were known to all parties, and were assumed cracked after a certain timeframe - passwords were required to be changed before that cyclic window. similarly, captcha's for high-sensitive sites embed the domain in the captcha, and only allow the captcha for a small timeframe. it then has a delay to show/fetch the captcha challenge, and must be completed/expires quickly. this reduces the chance of a MitM attack or a phishing attack to nil. ultimately, if you want to prevent information leakage, you'll have to create a event horizon surrounding the secret. and even then, Hawking predicts that black holes sweat, so even then, your 2^^8^^8 key is still derivable from collecting and de-entrophizing the sweated muons of a photon-sphere. *: unless you use reversible computing to generate the secret, then reverse the computation, but keep the result. this prevents people in the future from collecting information on current wave-states, barring entanglement.
- sigg3 5y agoIf you want to effectively bridge an airgap you compromise someone on the inside.
- etrautmann 5y agoCould an LCD display be used as a sensor?
- giantrobot 5y agoIIRC the Apple Newtons used a thermocoupler integrated into the LCD to help keep the contrast adjusted to the user-set level as the temperature of the device changed. There was at least one application that would read the current contrast setting of the screen and infer the temperature. I don't remember it being super accurate but it worked. The Newtons had grayscale LCDs with manually adjusted contrast. The MP130 and later also had an electro-luminescent backlight but it was not always active. So the user contrast setting was very important to maintain for screen visibility.
- upofadown 5y agoThe display processor would have to have some way to turn off the backlight LEDs and then sense the voltage generated by the laser. It is unlikely that the signal would be able to get back through whatever power device controlled the backlight power to get to a processor pin. The rest of the LED strings would probably load the signal down.
- R0b0t1 5y agoYou wouldn't need to turn the backlight off, but yes, you'd need to do complicated processing on the display CPU which is already at its limit doing screen ops.
- upofadown 5y agoIn practice the backlight would be off because the input/output pin on the controller would need to be switched to the input mode from the output mode. If the backlight was driven, that drive current would swamp out the current induced by the LED(s). See Appendix E [1]. This attack only works in very specific circumstances. [1] https://intellisec.de/pubs/2021-acsac.pdf https://intellisec.de/pubs/2021-acsac.pdf
- 1970-01-01 5y agoWhen you have sensitive data that needs to be air-gapped, but not so sensitive it can't be behind a pane of glass.
- jason-phillips 5y agoBehind pane-of-glass is not good enough, unfortunately. You typically have counter-measures in place to detect when someone is firing a laser at your exterior glass windows to exfiltrate data/IP. I assume it can/does happen.
- Ansil849 5y ago> You typically have counter-measures in place to detect when someone is firing a laser at your exterior glass windows to exfiltrate data/IP. I assume it can/does happen. It does, either in films or intelligence lore, but not for all intents and purposes, in regular life (regular life including corporate espionage). As for counter-measures: curtains.
- jason-phillips 5y agoI guess I don't live a "regular life", but those counter-measures exist where I've worked.
- Ansil849 5y agoUnless you were working for an intelligence agency, if your organization was sold TSCM against laser-based surveillance, then the organization was taken for a ride by the security contractor; you weren't also sold birds of prey to protect against UAS too, were you? (Yeah, that's a thing too [1]). It's a bit like being sold flood protection insurance if your data warehouse is in the desert. In other words, it just doesn't happen realistically, and there are a million and one other much more practical technical surveillance counter measures to spend a likely very-limited security budget on. [1] https://guardfromabove.com/ https://guardfromabove.com/
- Ansil849 5y ago> For our attacker model, we assume that an initial compromise has happened on the target device through the software supply-chain similar to the incidents at SolarWinds [8] and CodeCov [7]. For example, a regular update of the device’s firmware might unnoticeably add the necessary code for sending and receiving data through a built-in LED. I mean, sure, if you have the ability to compromise the airgapped device by running code on it then you could presumably be doing a lot of things besides just leveraging potential LED line of sight.
- londons_explore 5y agoLots of systems rely on air gaps heavily, and then aren't too worried what the software on the machines is up to. For example, if you are running a nuclear power plant and need a printer, you probably aren't going to be hiring a team of printer firmware developers. You're just going to buy an off-the-shelf non-wifi printer, and use it offline.
- Ansil849 5y ago> you probably aren't going to be hiring a team of printer firmware developers. You're just going to buy an off-the-shelf non-wifi printer, and use it offline. In such a scenario, you're also probably never, ever going to be manually updating the printer's firmware.
- londons_explore 5y agoBut there's a reasonable chance someone evil works for the printer company and every printer sold contains this backdoor. Or the FedEx driver who delivered it to the nuclear plant flashed a modded firmware with the same version number? How often have you disassembled your printer firmware and given it a decent audit?
- Ansil849 5y ago> But there's a reasonable chance someone evil works for the printer company and every printer sold contains this backdoor. If your threat model does legitimately consider this to be a "reasonable chance", then your facility will be printer-free.
- squarefoot 5y agoI briefly skimmed the paper; it looks like they're using pwm but not at its full potential. I would use it also as a synchronization mean, that is, the attacker points the led/laser and receiver to the target led, the attacker sends a signal like say a 10% modulated pwm, save for a 50% wide start bit which marks the start of the word being transmitted, then the bits are modulated like 10% for 1 and 20% for 0, or the other way around. Basically, the attacker talks 20% of each cycle, and listens the remaining 80%. The target led can be then read to detect those signals and sync itself to the signal received so that when replying it just modulates the led during the remaining time of each duty cycle. The attacker just by maintaining the link will receive both the echo of its transmission and the target's reply. That's just an idea, however, I'm not implying I could be able to implement it effectively:).
- contingencies 5y agoWhile LEDs are designed to emit light and can thus unnoticeably encode information through high-frequency flickering, their ability to also perceive light is largely unknown in the security community. In particular, by directing a laser on the LEDs of office devices, we induce a measurable current in the hardware that can be picked up by its firmware and used to receive incoming data. They are firing a laser at an LED under the following assumptions. 1. They already have arbitrary code execution on the device but want to open a bidirectional communication channel. 2. It is possible to reprogram the GPIO port to function as an input (not always possible, since ports may be output only). 3. They can induce a large enough current through firing a laser at the LED to exceed the GPIO threshold voltage for said port. 4. They have a suitable line of sight to the LED, ie. it is both facing them and not recessed, and there is no oblique or low-opacity window between them and the air-gapped asset. 5. They can get close enough to launch the attack.
- Ansil849 5y agoYup. Which is all why it's an academic paper, not a case study of a real-world example in the field.
- djinnandtonic 5y agoI don't understand why this is called an attack. Looks like just a (very cool!) communication protocol, over an unusual medium?
- jeremyjh 5y agoThe idea would be to covertly compromise an air-gapped system and ex-filtrate data from it over time while it remains in use. Maybe you've compromised it before it has any useful data, or maybe you want remote control of an agent like stuxnet, so that you can launch an attack at the time of your chooosing.
- supercoffee 5y agoThis concept sounded familiar, and it turns out that somebody else researched a similar technique a few years ago. https://cris.bgu.ac.il/en/publications/xled-covert-data-exfiltration-from-air-gapped-networks-via-switch-3 https://cris.bgu.ac.il/en/publications/xled-covert-data-exfi...
- triactual 5y agoThere are some pretty simple hardware mitigations that would render this and similar attacks nearly impossible and they only add pennies to the design.
- rdtwo 5y agoWhy not just use the fan as a speaker and modulate fan noise is that too slow? The response time on the led to get a clear one or zero would be pretty slow too
- zeeed 5y agoThat would be several orders of magnitude slower in fact. Plus it would only be one-way communication (sending information, not receiving).
- lokimedes 5y agoThere goes my office windows. Next up: how thermal control systems can be exploited to enhance band-gap transition probability to covertly cause bit-flips in air-gapped facilities. Vacuum it is.
- mikewarot 5y agoIf you're going to try this at home, it is important to know that LEDs work as photodiodes only when the impinging light is of a higher energy that the photons the LED emits normally. A given LED color below will only detect colors to the right of it Infrared < Red < Orange < Yellow < Green < Blue < Ultraviolet Back in the 1990s I breadboarded an alarm circuit that used a normal cheap bicolor LED as both transmitter and receiver, feeding some BiFET op amps. I could detect a bicycle reflector to about 6 feet