Stealthy Passive Spliced Network Tap
janitha.com
janitha.com
The notion that a network team would actually use a TDR to find passive spliced taps on their network --- or, for that matter, even take the time to spot unexpected 802.11 wireless activity --- is laughable. Pick any company in the Fortune 100. Put on a dress shirt and a tie. Follow someone with a proxcard in through the side door after their smoke break. You will have their mainframe batch apps for months or years afterwards.
The system is not that over-engineered, that you can throw away a bunch of the engineering and still have a working link. To look at a single line on a scope is often to see almost no signal at all. It's all noise. Only by looking at the signal differentially, does the data appear.
As for inductive coupling. Even if you used the entire differential signal, you still will fail, I think. The currents are quite low, which means your inductive pickup will need to be extremely sensitive. So sensitive, that I would anticipate the system noise of your inductive pickup to be on the same level as the signal you're trying to read, resulting in too much misread data to do anything with.
Plus, it's not worth it. There's no way to tell that another high impedance device has been added to the system, It won't change the impedance that some hypothetical tamper detection system would be able to measure, in any measurable way, so why not just add it using a direct connection?
Thinking about things more, you'd need to do the same common mode rejection in the tap in order to not be overwhelmed by line noise, necessitating the use of two pickups per pair. Careful physical design could allow a very sensitive pickup to be designed while canceling noise common to both. However, as you pointed out, low current could make things impossible still. But... the line is driving an inductive coupling in the form of a transformer at the end in order for things to work in normal operation though, so instinctively I think that something could be made to work.
As for not being worth it, you are probably right, especially since both approaches could be detected with the proper equipment.
The secondary syslog server would only be connected to the "receive" pair of the primary syslog server and therefore only physically able to receive data - making it difficult to tamper with logs.
> Within minutes of cutting the cable, three black SUV’s pulled up carrying men in suits who complained that their line was severed.
“The construction manager was shocked,” a worker told the Washington Post. “He had never seen a line get cut and people show up within seconds. Usually you’ve got to figure out whose line it is. To garner that kind of response that quickly was amazing.”
AT&T crews arrived the same day to fix the line, an unusually prompt response.