SATAn: Air-Gap Exfiltration Attack via Radio Signals from SATA Cables
arxiv.org
arxiv.org
See the other ≈50 copycat papers of the author: https://www.semanticscholar.org/author/Mordechai-Guri/226003...
At some point the author is going to run out of clever puns...
Let me tell you about these chemists that publish paper after paper involving carbon bonds. Like, give it a rest.
It’s simply restating the obvious. Nothing has changed, unshielded electronics continue to let out measurable EM emissions. The people who worry about this sort of thing have been shielding their electronics since well before computers as we know them existed.
> Probably took non-zero effort to develop?
In the sense that doing anything takes non-zero effort by definition.
I won't be surprised if even the power connection becomes a future (unintended) means of data transmission.
That's already a thing. From the same author as the TFA, PowerHammer [1] exfiltrates data using current flow fluctuations. There's also Powermitter [2] (from some researchers at Wuhan University), which is exfiltration via power supply EMF leakage.
[1] https://arxiv.org/pdf/1804.04014.pdf - by the same guy as the OP paper
The author is clearly an expert in exfiltration and has deep insights in the area. But instead of working on presenting the big picture, prefers to throw breadcrumbs to the community. After a dozen of "exfiltration using X" papers, one would at least expect an SoK paper.
If the answer was "we tried really hard, but couldn't figure it out" pretty sure the paper would not get published.
If it was so trivial other people would be doing it.
None of the SCIFs I've been in had TEMPEST gear.
I'm only half joking.
He's done that one: https://arxiv.org/abs/1702.06715
now this is something id like to see!
None of it makes for a practical attack.
Identifying attack vectors is just building up an arsenal of tools that can potentially be used depending on the circumstance.
Isn't this basically the exact thing that everyone thought before the Intel CPU bugs began emerging en-masse?
Notably, most of the attacks from Mordechai's lab describe low-bandwidth channels for deliberate data exfiltration. These attacks would only apply in unusual situations where an attacker can run arbitrary code on a machine, but the machine is isolated from the outside world. (Scenarios like Iranian nuclear facilities come to mind.)
And the range is VERY low for normal PC's that have had to pass EMC tests. For an all glass gamer RGB PC the things will be different.
Not with this - it’s a one way channel
So, in short, it only affects ineptly managed secure environments.
Yes.
> It's irrelevant to users who have intentionally enabled any kind of network communications on their computer
No, there are lots of use-cases at least for LAN communications.
> it's also irrelevant to users who have robust controls on what code is executing on their system, or who run untrusted code in an environment which isolates it from hardware (like a virtual machine).
No, it's relevant in those cases too, as part of a defense in depth strategy.
What I'm trying to get at here is that bizarre sidechannels like fan noise or SATA EMI are only relevant when the system administrator has thoroughly locked down all other possible channels of communication. If the system is connected to a wired network, it can communicate with other systems over that; if the network is connected to the Internet, even indirectly, there are probably ways to get data out through there. If the system has a WiFi card or Bluetooth adapter, that can be used to transmit data, even if there isn't an applicable network in range. Etc, etc.
For most people, if you are trying to exfiltrate some customer data to sell on the black market, are you going to spend a bunch of development time blinking a LED and setting up a receiver? Nah you’d just move to some other victim because you are trying to make a profit, not waste more money
But someone like a government trying to spy on another country… the cost of spies is pretty high… but pay some engineers to spend all day trying to make a LED blink some data is relatively cheap
That said, I think a lot of these attacks are kind of boring even if they were unpublished. If anyone here was paid 6 figures to do nothing all day but figure out some obscure variables in your computers to flip to exfiltrate some data, I’d be disappointed if you couldn’t figure anything out. I think most of these attacks are kind of obvious.
None of what gets released publicly makes for a practical attack.
No quicker way to get people to stop looking for your attack vector than to convince them it doesn't work.
Now if you'll excuse me, I need to go and re-wrap my head in tin foil.
But have any of these extreme exploits ever been used in the wild? They all seem impossible to pull off in anything but lab controlled conditions.
I suspect you're going to find out in 50 years when government documents (not inherently US gov) are declassified.
State level spying is the only thing I can think of where the value of the information is so high (making the effort of this kind of attack is worth it) and where there are many scenarios where the volume of highly valuable information is comparatively tiny.
Just as some very off the cuff examples of what I mean by the latter. We don't need to exfiltrate satellite photos of things (gigabytes of data), but, it could be very valuable to exfiltrate the metadata of what they are looking at (coordinates and time)
Also, exfiltrating information like names of sources or meeting points or other methods can be trivial amounts of data but finding even a single compromised person on our side would be immensely valuable!
I'm reminded of "The Thing": https://en.wikipedia.org/wiki/The_Thing_%28listening_device%...
I would expect so. I'm fairly certain there's a big difference between pulling fuzzy data out and figuring out what it means as opposed to trying to electromagnetically fling fuzzy data into a system that's not supposed to have information flung at it and having the system accept what you mean.
https://media.defense.gov/2021/Jul/13/2002761779/-1/-1/0/LEA...
Read Google's Project Zero blog, too: https://googleprojectzero.blogspot.com/ We don't know that these exploits in particular are used, but consider that Project Zero is the moral equivalent of a hobby for Google. What would it look like to have hundreds of people at that rough skill level, training each other, practicing all the time, and building software support for each other?
The capabilities of attackers are not bounded by your imagination.
that said I've seen signal recovery from LVDS
Not at all. I've seen clearly with my own eyes the image of one persons VT100 CRT tube appearing on another across the room because the ground shielding had disconnected. If you have a high gain YAGI antenna, digital RF buffers and some fancy modern DSP lord only knows what you can snoop through the walls.
Most of this is solved by having a simple metal (steel) PC case and grounding the PSU though. Use good quality cables with FCC/IEC badges not the bargain bucket Chinese ones.
We could be playing a video game or movie, and set all the other tv's to channel 2 or something like that, while we played on channel 1. You could see the action on each of them. Almost 1:1 on the reaction times, albeit a little fuzzy.
"The antenna was invented in 1926 by Shintaro Uda of Tohoku Imperial
University, Japan, with a lesser role played by his colleague
Hidetsugu Yagi." [1]
[1] https://en.wikipedia.org/wiki/Yagi%E2%80%93Uda_antenna#Origi...It's a neat attack, but to pull it off you pretty much need both physical access AND the ability to install virused software on the target. Perhaps something the CIA/NSA pull off such as stuxnet? Even then, the point of an air-gapped computer is that installing such software would be pretty difficult in the first place.
If I told you that you could make 500 million dollars (after taxes) if you figured this out, suddenly you would be on top of this.
The stakes of Stuxnet was probably “the safety of the free world” in the eyes of the people who paid for the work
With each of those requirements, there are easier and faster ways to get data off a machine. If you can install software you can likely download data that software would access. If you can access the machine twice and install software that runs in the background between visits, you can install your keylogger/data collectors and simply record the data on the device.
Stuxnet wasn't about getting data out of the machine, it was about breaking machines. It worked well because it didn't require physical access to the machines. It spread as a virus through the regular updates that Iran was doing for their machines.
If you had such a stuxnet virus in your back pocket, then you can likely steal the data and record it back on the USB device (or any plugged in USB device) on the system.
Spy agencies have definitely used obscure data exfiltration techniques and they can afford spies.
> We transmitted the data with a bit rate of 1 bit/sec, which is shown to be the minimal time to generate a signal which is strong enough for modulation. The BER for PC-1 is presented in Table VI. As can be seen, the BER of 1% - 5% is maintained between 0 - 90 cm. With a greater distance of 120 cm, the BER is significantly higher and reaches 15%. With PC-2 and PC-3, the bit error rates (BER) are less than 5% only in short proximity up to 30 cm, and hence the attack is relevant only for short ranges in these computers.
This particular attack is a weak 6 GHz signal that can exfil about 1 bit/s from a metre away. It's neat, but impractical.
Still, publishing which methods are a risk, and which ones aren't, is quite useful.
apparently it was demonstrated practically during the Korean War; but I can't find anything much about that.
[0]: https://yro.slashdot.org/story/09/11/22/027229/Brazilian-Bre...
That said, for most of these kinds of things, you have to get a malicious payload on such a system. The stuxnet approach is one way, if you have specific targets. Aside from that, you pretty much need phyxical access and be able to load a malicious software. At that point, you may as well stick a small usb bluetooth/wireless dongle, depending on the situation... assuming it's a standard desktop, there's a good chance of unused USB 2 header you could piggy back on.
At that point, an actual faraday cage or mesh on the room in question would be the next practical vector. Some secure buildings are up to 6' thick walls, no communications out except through known devices on wired ports with software checking in place (seen this in finance).
I can, in this example, just have the computer use more power to signal a 1 and less power to signal a 0. For a DC I just ramp up the entire DC load. Do that over the span of a week or so to make it less noticable.
Right, but there are places where if you stick an unapproved USB device into a computer's USB port, a nice person from security taps you on the shoulder 10 minutes later. In those cases, you may well have the ability to run code on the computer, but no ability to attach removable storage. It's at least plausible (if not exactly probable) that something like this could come into play for somebody looking to exfiltrate a small amount of data from a system they have access to.
I'm thinking something closer to (but perhaps not exactly) like the Edward Snowden kind of scenario. Something where you access to the computer, but can't use the other common place means of getting data off of the machine and out the door. Yeah, it's a stretch, but it's not beyond the bounds of imagination.
And if you're wondering, I can confirm that I've definitely worked at places where you were not allowed to plug in a USB device (I literally saw a co-worker get the "tap on the shoulder" from Security for doing that), but yet many (most?) Internet downloads were allowed. Does that make sense? Arguably not. Does it happen in the real world? Absolutely yes.
I'm not sure what kind of practical implementation this could really have.
Certainly very limited utility, and definitely not something any of us should actually be worried about. But it probably is something to be aware of if you run IT for an embassy or any other entity that could be targeted by a highly motivated state sponsored actor.
I, of course, will continue to advocate for full-on grindcore. “Putrid Air Carries Pestilent Waves of Betrayal and Decay” or gtfo.
https://en.m.wikipedia.org/wiki/Security_Administrator_Tool_...
>http://www.porcupine.org/satan/release-2-plan.html
>Release 2 is currently in the works - the original plan was to update SATAN on its first birthday, but that schedule has slipped.
sensiblechuckle.jpg