AIR-Jumper: Covert air-gap exfiltration/infiltration via security cameras & infrared (IR). Issue 82 (May 2019)
- Record Type:
- Journal Article
- Title:
- AIR-Jumper: Covert air-gap exfiltration/infiltration via security cameras & infrared (IR). Issue 82 (May 2019)
- Main Title:
- AIR-Jumper: Covert air-gap exfiltration/infiltration via security cameras & infrared (IR)
- Authors:
- Guri, Mordechai
Bykhovsky, Dima - Abstract:
- Abstract: Breaching highly secure networks with advanced persistent threats (APTs) has been proven feasible in the last decade, however communication between the attacker outside the organization and the APT inside the organization is not possible if the compromised network is disconnected from the Internet. In this paper, we show how attackers can exploit surveillance cameras to establish covert communication between the air-gapped networks of organizations and remote attackers. We present bidirectional communication allowing inbound and outbound data transfer. Infiltration. An attacker standing in a public area (e.g., in the street) uses near infrared light (NIR) to transmit hidden signals to the surveillance camera(s). Such NIR signals at a wavelength of 800–900 nm are invisible to humans, but cameras are optically sensitive to this type of light. Binary data is encoded and modulated on top of the IR signals. The signals hidden in the video stream are then intercepted and decoded by the malware residing in the internal network. Exfiltration. Surveillance and security cameras are equipped with controllable IR LEDs which are used for night vision. We show that the malware can control the strength of the IR illumination. Sensitive data such as PIN codes, passwords, and encryption keys are then modulated, encoded, and transmitted over the IR signals. An attacker in a public area (e.g., in the street) with a line of sight to the surveillance camera records the IR signals andAbstract: Breaching highly secure networks with advanced persistent threats (APTs) has been proven feasible in the last decade, however communication between the attacker outside the organization and the APT inside the organization is not possible if the compromised network is disconnected from the Internet. In this paper, we show how attackers can exploit surveillance cameras to establish covert communication between the air-gapped networks of organizations and remote attackers. We present bidirectional communication allowing inbound and outbound data transfer. Infiltration. An attacker standing in a public area (e.g., in the street) uses near infrared light (NIR) to transmit hidden signals to the surveillance camera(s). Such NIR signals at a wavelength of 800–900 nm are invisible to humans, but cameras are optically sensitive to this type of light. Binary data is encoded and modulated on top of the IR signals. The signals hidden in the video stream are then intercepted and decoded by the malware residing in the internal network. Exfiltration. Surveillance and security cameras are equipped with controllable IR LEDs which are used for night vision. We show that the malware can control the strength of the IR illumination. Sensitive data such as PIN codes, passwords, and encryption keys are then modulated, encoded, and transmitted over the IR signals. An attacker in a public area (e.g., in the street) with a line of sight to the surveillance camera records the IR signals and decodes the leaked information. We discuss related work on air-gap covert channels and provide scientific background about our optical channel. Our evaluation shows that an attacker can establish bidirectional communication with the internal networks from distances of tens of meters to kilometers away via surveillance cameras and IR light. … (more)
- Is Part Of:
- Computers & security. Issue 82(2019)
- Journal:
- Computers & security
- Issue:
- Issue 82(2019)
- Issue Display:
- Volume 82, Issue 82 (2019)
- Year:
- 2019
- Volume:
- 82
- Issue:
- 82
- Issue Sort Value:
- 2019-0082-0082-0000
- Page Start:
- 15
- Page End:
- 29
- Publication Date:
- 2019-05
- Subjects:
- Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2018.11.004 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 9510.xml