AIR-FI: Leaking Data From Air-Gapped Computers Using Wi-Fi Frequencies

被引:4
|
作者
Guri, Mordechai [1 ]
机构
[1] Ben Gurion Univ Negev, Cyber Secur Res Ctr, Dept Software & Informat Syst Engn, IL-84105 Beer Sheva, Israel
关键词
Wireless fidelity; Computers; Receivers; Air gaps; Hardware; Universal Serial Bus; Smart phones; Network-level security and protection; covert channels; air-gap; Wi-Fi; exfiltration; electromagnetic; EXFILTRATING DATA; NETWORKS;
D O I
10.1109/TDSC.2022.3186627
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
This article presents a new attack allowing attackers to exfiltrate data from isolated, air-gapped computers via Wi-Fi frequencies. We show that malware in a compromised air-gapped computer can generate signals in the Wi-Fi frequency bands. The signals are generated through the memory buses - no special hardware is required. Sensitive data can be modulated and secretly exfiltrated on top of the signals. We show that nearby Wi-Fi-capable devices (e.g., smartphones, laptops, and IoT devices) can intercept these signals, decode them, and send them to the attacker over the Internet. We utilized the physical layer information exposed by the Wi-Fi chips to extract the signals. We further implemented the transmitter and receiver and discussed design considerations and implementation details. We evaluated this covert channel in terms of bandwidth and distance and presented a set of countermeasures. Our evaluation shows that data can be exfiltrated from air-gapped computers to nearby Wi-Fi receivers located meters away at bit rates of 16 bit/sec.
引用
收藏
页码:2547 / 2564
页数:18
相关论文
共 50 条
  • [1] GSMem: Data Exfiltration from Air-Gapped Computers over GSM Frequencies
    Guri, Mordechai
    Kachlon, Assaf
    Hasson, Ofer
    Kedma, Gabi
    Mirsky, Yisroel
    Elovici, Yuval
    PROCEEDINGS OF THE 24TH USENIX SECURITY SYMPOSIUM, 2015, : 849 - 864
  • [2] GAIROSCOPE: Leaking Data from Air-Gapped Computers to Nearby Smartphones using Speakers-to-Gyro Communication
    Guri, Mordechai
    2021 18TH INTERNATIONAL CONFERENCE ON PRIVACY, SECURITY AND TRUST (PST), 2021,
  • [3] CTRL-ALT-LED: Leaking Data from Air-Gapped Computers via Keyboard LEDs
    Guri, Mordechai
    Zadov, Boris
    Bykhovsky, Dima
    Elovici, Yuval
    2019 IEEE 43RD ANNUAL COMPUTER SOFTWARE AND APPLICATIONS CONFERENCE (COMPSAC), VOL 1, 2019, : 801 - 810
  • [4] Exfiltrating data from air-gapped computers via ViBrAtIoNs
    Guri, Mordechai
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2021, 122 : 69 - 81
  • [5] Data Exfiltration from Air-Gapped Computers based on ARM CPU
    Yamamoto, Kenta
    Hirose, Miyuki
    Saito, Taiichi
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2018, 9 (01) : 183 - 190
  • [6] BRIGHTNESS: Leaking Sensitive Data from Air-Gapped Workstations via Screen Brightness
    Guri, Mordechai
    Bykhovsky, Dima
    Elovici, Yuval
    2019 12TH CMI CONFERENCE ON CYBERSECURITY AND PRIVACY (CMI), 2019, : 8 - 13
  • [7] Passwords in the Air: Harvesting Wi-Fi Credentials from SmartCfg Provisioning
    Li, Changyu
    Cai, Quanpu
    Li, Juanru
    Liu, Hui
    Zhang, Yuanyuan
    Gu, Dawu
    Yu, Yu
    WISEC'18: PROCEEDINGS OF THE 11TH ACM CONFERENCE ON SECURITY & PRIVACY IN WIRELESS AND MOBILE NETWORKS, 2018, : 1 - 11
  • [8] PowerHammer: Exfiltrating Data From Air-Gapped Computers Through Power Lines
    Guri, Mordechai
    Zadov, Boris
    Bykhovsky, Dima
    Elovici, Yuval
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2020, 15 : 1879 - 1890
  • [9] BeatCoin: Leaking Private Keys from Air-Gapped Cryptocurrency Wallets
    Guri, Mordechai
    IEEE 2018 INTERNATIONAL CONGRESS ON CYBERMATICS / 2018 IEEE CONFERENCES ON INTERNET OF THINGS, GREEN COMPUTING AND COMMUNICATIONS, CYBER, PHYSICAL AND SOCIAL COMPUTING, SMART DATA, BLOCKCHAIN, COMPUTER AND INFORMATION TECHNOLOGY, 2018, : 1308 - 1316
  • [10] Carrier Grade Wi-Fi: Air Interface Requirements and Technologies
    Wang, Xiaofei
    Lou, Hanqing
    Ghosh, Monisha
    Zhang, Guodong
    Xia, Pengfei
    Oteri, Oghenekome
    La Sita, Frank
    Olesen, Robert
    Shah, Nirav
    2014 IEEE LONG ISLAND SYSTEMS, APPLICATIONS AND TECHNOLOGY CONFERENCE (LISAT), 2014,