论文标题
脉络
ETHERLED: Sending Covert Morse Signals from Air-Gapped Devices via Network Card (NIC) LEDs
论文作者
论文摘要
由于其处理的机密信息,高度安全的设备通常与Internet或其他公共网络隔离。这种隔离水平称为“气隙”。 在本文中,我们提出了一种名为Etherled的新技术,允许攻击者泄漏来自PC,打印机,网络摄像头,嵌入式控制器和服务器等空气网络设备的数据。网络设备具有一个集成的网络接口控制器(NIC),其中包括状态和活动指标LED。我们表明,设备上安装的恶意软件可以使用记录的方法或无证件固件命令来通过眨眼和交替的颜色来控制状态LED。信息可以通过简单编码(例如Morse代码)进行编码,并在这些光学信号上进行调制。攻击者可以拦截并将这些信号从数十米到几百米处解码。我们展示了评估并讨论这种渗透攻击的防御和预防对策。
Highly secure devices are often isolated from the Internet or other public networks due to the confidential information they process. This level of isolation is referred to as an 'air-gap .' In this paper, we present a new technique named ETHERLED, allowing attackers to leak data from air-gapped networked devices such as PCs, printers, network cameras, embedded controllers, and servers. Networked devices have an integrated network interface controller (NIC) that includes status and activity indicator LEDs. We show that malware installed on the device can control the status LEDs by blinking and alternating colors, using documented methods or undocumented firmware commands. Information can be encoded via simple encoding such as Morse code and modulated over these optical signals. An attacker can intercept and decode these signals from tens to hundreds of meters away. We show an evaluation and discuss defensive and preventive countermeasures for this exfiltration attack.