This technology would spot a secret chip in seconds
spectrum.ieee.org
spectrum.ieee.org
1) They might be, and it's being fooled. But...
2) ...they're likely not using it. Consider the following:
> "So why isn’t this system in widespread use? After all, much of it has been available since 2014."
With the compromised servers being purchased in 2015 it's assuming the ubiquitous implementation of the described system a year after "much of it" was available. Big companies don't move that fast to begin with (budgets, politics, entrenchment of current processes, etc.). Also, the article doesn't site anywhere this tech has been proven in the wild. Do you want to make that case to your boss that your job can be replaced (and maybe theirs) with this, probably expensive to purchase and implement, unproven tech? That's even if you've heard or thought of this system coming together in 2014 to prevent an attack that would've infiltrated your network by 2015.
The only defense they give for why it hasn't been used was they were waiting for a huge attack to help justify company's spend. That would help, but FICS would be better off taking on the initial capital costs and charging these big companies on a per server basis to use FICS's system (or spinning of a company to do so, idk how FICS could make this happen).
It's like saying a day after SpaceX's flight around the moon that if your company wants to get to the moon have your company purchase a BFR and send their own people up. Cool. Take a hike.
Could it detect a change within a chip? If not, then it makes such an attack harder to execute, but not impossible. Especially for a nation state.
Simply supply 'alternate' devices for normal manufacture.
There is research going into it, this article would interest you:
https://www.nature.com/articles/nature21698
Its the only article I know if that nondestructively can imagine a chip.
Maybe testing could work? Hook it up to a testing device and have it run through a suite of tests not known by the manufacturer, as well as fuzzing tests. They might find additional bugs in their own design as well that way.
Imagine a subverted NOR FLASH device with malicious firmware booting your board-management device. Its still a SPI FLASH with the same (apparent) device id. The contents would just be different.
It's purpose is to ensure that designs aren't modified in manufacture.
What you're talking about is a software problem, and should be carried out in addition to this.
The first idea that comes to mind is that I would sign the contents of the flash devices and have them verified once the board layout has been verified.
Essentially, you'd have your board schematic, and then a signature "schematic" of firmware to verify against. Of course, you'd also need a way of signing the schematic/signature list to verify those once they're updated.
In this case, the technology would have identified this additional component added out-of-spec. Once you've identified that a component that doesn't belong has been added you don't need to bother identifying any software attacks, it's already compromised.
some people noted that some 'hardware' attacks can't be seen because they use original parts. -> that's a silly statement, as that would make it a firmware attack, not a hardware attack (even though physical access might be needed to flash the chip, it's the firmware which is malicious, not the chip itsefl. i.e. other type of threat / use-case).
i think the problem with x-rays, apart from them being hazardous in themselves, the cost and availibility of equipment is not practical for reverse engineers and researchers apart from some highest tier companies doing this.
A question to NH about this which might be more interesting: do you think you can get similar results using ultrasound? Because ultrasound devices are fairly cheap and can be made at home fairly easily compared to x-ray technology. It's also much less hazardous to the researchers....
You can have original looking part. Imagine a 8Mbit SOIC SPI NOR flash chip. Looks the part, belongs in its spot, you decap it and it sure does look like a flash Die with its normal Flash controller. Now consider this: http://travisgoodspeed.blogspot.com/2012/07/emulating-usb-de... I cant find it right now, but Afair Travis (or maybe it was hak5 RubberDucky folks) noticed early on that its pretty trivial to detect what is happening on the Host side of the interface - what operating system am I plugged into and at what phase of the operation are we on (bios query, OS loading drivers).
Imagine a Flash chip that is able to tell (power sequencing, timing and order of commands) if its booting a particular controller on the board, or if its being read in a flash programmer. Flash chips have processors running their own firmware nowadays, turtles all the way own.
Original parts can also have attacks not in firmware, without changing the transistor layouts, via dopant attacks [1, paper at 2].
[1] https://www.researchgate.net/publication/262211582_Stealthy_... [2] https://sharps.org/wp-content/uploads/BECKER-CHES.pdf
This can be used to insert alternative boot code, firmware, microcode, or even FPGA structures.
Note that the component would not have to generate its own signal source, because by merely inserting a lower than normal resistance or capacitance it could alter an existing bitstream to reflect the desired payload.
It would require a high degree of integration and power management finesse, but is certainly doable to replace an existing SMT resistor or Capacitor with such a device. .
These surface mount components are so small that the variation in the volume of solder on the joints alone would render your technique moot.
Add to that, the fact that manufacturers often use multiple suppliers for parts, they could have different materials, densities and casing designs, this particular problem is beyond weighing.
the article describe how to spot a supposed spying chip when it happens, but why they single China? Just replace it with Israel and the article would still valid.
It's equally credible that they would never want to acknowledge that.
The general idea doesn't seem new or novel.
https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...
There is suggestion that at least one of the companies involved is lying about related goings-on.
According to
> https://www.theregister.co.uk/2018/10/04/supermicro_bloomber...
"Bloomberg reporters receive bonuses based indirectly on how much they shift markets with their reporting. This story undoubtedly did that. The publisher employs roughly 2,000 journalists, who are encouraged to work together and share information through their Bloomberg Terminals, with many layers of editing and fact checking, and it has a zero tolerance on errors: it is inconceivable that it would publish a story this huge that wasn't watertight."
It's almost like reading, a couple of days ago that Riz Ahmed taped over his parent's wedding video with an Eminem song a decade or so ago.
A proper chain of trust that starts on the BMC chip could absolutely protect against that. At that point any modification to the boot image would leave the BMC refusing to boot rather giving attacker control.
It would significantly raise the cost and difficulty of this sort of attack.
In my opinion, modifying the board layout with the additional chip and modifying the production process for the server boards stealthily already has a pretty high cost and difficulty.
That's true, but properly implemented secure boot could serve to increase it by an order of magnitude.
And one of the most common attacks aka. malicious firmware is prevented by using secure boot.
Many other classes of attacks like forcing the microcontroller to delete all its data, opening up the debug JTAG port of the microcontroller, preventing the log of certain security events etc. can be achieved with the right settings.
Though these are just remote possibilities with high levels of complexity, so is changing a production design of a board.
But by Trusted Computing (at least in some implementations).