יובל אלוביץ

אקדמי בכיר

PowerHammer

Exfiltrating Data from Air-Gapped Computers through Power Lines

Mordechai Guri, Boris Zadov, Dima Bykhovsky, Yuval Elovici

In this article, we provide an implementation, evaluation, and analysis of PowerHammer - an attack that uses power lines to exfiltrate data from air-gapped computers. A malicious code running on a compromised computer intentionally controls the utilization of the CPU cores. The CPU utilization is electromagnetically conducted and propagated through the power lines in the form of a parasitic signal that is modulated, encoded, and transmitted on top of the current flow fluctuations. This electromagnetic phenomenon is known as 'conducted emission'. In this attack, the attacker taps the indoor electrical power wiring that is connected to the electrical outlet of the compromised computer. The conducted electromagnetic emission of the compromised computer is analyzed and the exfiltrated data is decoded. The proposed attack is then experimentally evaluated and characterized. The communication performance is discussed and a set of defensive countermeasures is presented. A crucial aspect of the proposed covert communication scheme is that it fully conforms to civilian and military conductive emission standards.

שפת פרסום אנגלית
דפים 1879-1890
כתב עת IEEE Transactions on Information Forensics and Security
כרך 15
סטטוס פרסום פורסם - 01.01.2020
8894040

Keywords

air gap
covert channel
exfiltration
Network security
power line communication

ASJC Scopus subject areas

Safety, Risk, Reliability and Quality
Computer Networks and Communications
גישה למסמך
10.1109/TIFS.2019.2952257
קבצים וקישורים אחרים
Link to publication in Scopus