Dr. Mordechai Guri

Know all about my research

Near Field Air-Gap Covert Channel Attack

Air-gapped systems are isolated from the Internet due to the sensitive information they handle.This paper presents a new covert channel attack that enables the leaking of sensitive information from highly isolated, air-gapped systems to nearby mobile phones. Malware running on an air-gapped computer can generate radio waves by executing crafted code on the target system. The malicious code exploits the dynamic power consumption of modern computers and manipulates the momentary loads on CPU cores. With this technique, malware can control the computer's internal utilization and generate low-frequency electromagnetic radiation in the 0-60 kHz band. Sensitive information (e.g., files, encryption keys, biometric data, and keylogging) can be modulated over the emanated signals and received by a nearby mobile phone at a max speed of 1000 bit/sec. We show that a standard smartphone with a simple antenna carried by a malicious insider or visitor can be used as a covert receiver. Finally, we present a set of countermeasures to this air-gap attack.

Publication language English
Pages 490-497
Publication status Published - 01.01.2022

Keywords

air-gap
covert channel
electromagnetic
exfiltration
leakage
network

ASJC Scopus subject areas

Information Systems and Management
Safety, Risk, Reliability and Quality
Health Informatics
Computer Networks and Communications
Information Systems