Bridging the Air Gap between Isolated Networks and Mobile Phones in a Practical Cyber-Attack

被引:29
|
作者
Guri, Mordechai [1 ]
Monitz, Matan [1 ]
Elovici, Yuval [1 ]
机构
[1] Ben Gurion Univ Negev, POB 653, IL-8410501 Beer Sheva, Israel
关键词
Air-gap; data exfiltration; TEMPEST; EMSEC; FM Radio; APT; cyber-attack; bridging the air-gap;
D O I
10.1145/2870641
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Information is the most critical asset of modern organizations, and accordingly it is one of the resources most coveted by adversaries. When highly sensitive data is involved, an organization may resort to air gap isolation in which there is no networking connection between the inner network and the external world. While infiltrating an air-gapped network has been proven feasible in recent years, data exfiltration from an air-gapped network is still considered one of the most challenging phases of an advanced cyber-attack. In this article, we present "AirHopper," a bifurcated malware that bridges the air gap between an isolated network and nearby infected mobile phones using FM signals. While it is known that software can intentionally create radio emissions from a video card, this is the first time that mobile phones serve as the intended receivers of the maliciously crafted electromagnetic signals. We examine the attack model and its limitations and discuss implementation considerations such as modulation methods, signal collision, and signal reconstruction. We test AirHopper in an existing workplace at a typical office building and demonstrate how valuable data such as keylogging and files can be exfiltrated from physically isolated computers to mobile phones at a distance of 1-7 meters, with an effective bandwidth of 13-60 bytes per second.
引用
收藏
页数:25
相关论文
共 50 条
  • [21] Bridging the gap between different social networks
    Qiao, Jian
    Huang, Hong-Qiao
    Li, Guo-Ying
    Fan, Ying
    [J]. PHYSICA A-STATISTICAL MECHANICS AND ITS APPLICATIONS, 2014, 410 : 535 - 549
  • [22] Enhanced Cyber-Attack Detection in Intelligent Motor Drives: A Transfer Learning Approach With Convolutional Neural Networks
    Yang, Bowen
    Wu, Shushan
    Hu, Kun
    Ye, Jin
    Song, Wenzhan
    Ma, Ping
    Shi, Jianjun
    Liu, Peng
    [J]. IEEE Journal of Emerging and Selected Topics in Industrial Electronics, 2024, 5 (02): : 710 - 719
  • [23] PRACTICAL ASPECTS OF TRANSLATION: BRIDGING THE GAP BETWEEN THEORY AND PRACTICE
    Libeg, Andrea
    [J]. EUROPEAN INTEGRATION: BETWEEN TRADITION AND MODERNITY, VOL 1, 2005, : 352 - 358
  • [24] Cyber-Attack Detection in Discrete-Time Nonlinear Multi-Agent Systems Using Neural Networks
    Mousavi, Amirreza
    Aryankia, Kiarash
    Selmic, Rastko R.
    [J]. 5TH IEEE CONFERENCE ON CONTROL TECHNOLOGY AND APPLICATIONS (IEEE CCTA 2021), 2021, : 911 - 916
  • [25] FEAR: Federated Cyber-Attack Reaction in Distributed Software-Defined Networks with Deep Q-Network
    Phan, Trung, V
    Nguyen, Tri Gia
    [J]. 2022 WIRELESS TELECOMMUNICATIONS SYMPOSIUM (WTS), 2022,
  • [26] An ensemble learning and fog-cloud architecture-driven cyber-attack detection framework for IoMT networks
    Kumar, Prabhat
    Gupta, Govind P.
    Tripathi, Rakesh
    [J]. COMPUTER COMMUNICATIONS, 2021, 166 : 110 - 124
  • [27] Mobile-to-grid middleware: Bridging the gap between mobile and grid environments
    Jameel, H
    Kalim, U
    Sajjad, A
    Lee, S
    Jeon, T
    [J]. ADVANCES IN GRID COMPUTING - EGC 2005, 2005, 3470 : 932 - 941
  • [28] Bridging the gap between pervasive devices and global networks
    Henrici, Dirk
    de Waha, Patric
    Mueller, Paul
    [J]. PROCEEDINGS OF THE 2008 INTERNATIONAL SYMPOSIUM ON COLLABORATIVE TECHNOLOGIES AND SYSTEMS: CTS 2008, 2008, : 1 - 8
  • [29] SocBridge: Bridging the gap between Online Social Networks
    Nepali, Raj Kumar
    Wang, Yong
    [J]. AMCIS 2014 PROCEEDINGS, 2014,
  • [30] Bridging the Gap between Simulation and Experimentation in Vehicular Networks
    Khalfallah, Sofiane
    Ducourthial, Bertrand
    [J]. 2010 IEEE 72ND VEHICULAR TECHNOLOGY CONFERENCE FALL, 2010,