Scientist-developed malware covertly jumps air gaps using inaudible sound
arstechnica.com
arstechnica.com
It would be quite impressive, though, if a vulnerability in an audio driver allowed an uninfected computer to be infected simply by "hearing" the exploit sound!
It's an interesting idea I think, which will have more applications in the future than it does now as more computers start to be always on, listening and watching, but mostly because audio or video is not an infection vector we take seriously yet in the same way that we do network infection.
That would be one hell of an exploit.
It's not as significant as one might imagine.
But it does have the significance that you still have to worry whether your air-gapped machine is infected since it could secretly leak info even unplugged.
The transfer rate of ~20 bytes per second is tiny, but of course that tiny amount could be the difference between two machines appearing to communicate and not appearing to. If your network traffic is confirmed to be zero, that's a state of confidence that's easy to take advantage of, and a deeply-rooted bit of malware like this could strike in extremely subtle and devious ways.
What surprises me is how people regarding this as "novel" not too long ago quite a few people used a "modem". That was a mythical device that used phone networks to transmit information. Regular phones would pick up that as sound.
Sure there are few technical hurdles - covert communication and stringent error correction are most visible, but concepts are remarkably similar.
Pardon the snark, but what is surprising about that? Every person with access to the internet born since about 1997* will have no memory of using dialup. The ratio of people who used dialup relative to the people on the internet is going to continue to dwindle rapidly from here on out. Even then, I probably spent 6 or 7 years dialing up, and the connection of that to this story never happened in my brain.
* say 2003-2004 was when broadband went mainstream, at that point, people born in 1997 will be 6-7 years old.
IE: I was having a conversation with some techie friends back when the SOPA scare was still at its peak. We were discussing purely hypothetical doomsday scenarios that would involve a "darknet" and the technical implications of creating an entirely subversive network. The idea was brought up that we could use our existing telephone infrastructure to send data, and only a way to transfer data via sound would need to be developed. This was shared amongst a few of the participants until I piped up and said "you know dialup has done this already, right? The information is already there."
This is a conversation amongst people who are involved with and passionate about technology and are around my age or older. These are the kinds of people that I'd expect, if not to think of specifics right away, but to at least be lead to something that was as pervasive as dialup. True, I don't expect an 18y/o of today to know or think about it, or even a 20y/o, but a 25+ hacker, developer, or general tech geek? I'm just surprised at how many in that former category just don't remember it.
Smartmodems of the 1980s didn't use sound to transmit data, they modulated an electrical signal directly on the line. They were silent (except during call set up, but that was just a "Monster Rancher" to confirm set up was proceeding in the normal way)
Telephone handsets used data to transmit sound.
e.g. client library - https://code.google.com/p/sonicread/
Are mics common on desktops? I would like to think I'm not that out of touch. I get that in laptops they are common.
Still pretty cool. There could be an application for this that isn't malicious.
They'd both need to be infected it's true, but that is quite achievable with USB social engineering or if an attacker can gain physical access to any of the terminals on the network. If that were the case then an attacker could get any information out that they wanted (flight data, prison routines, defence asset refueling movements, even just information enumeration and vulnerabilities in the network).
The terminal probably wouldn't have a microphone it's true (typically very old hardware that everyone is too scared to upgrade), but if it did it would also give remote trigger access to abuse that infrastructure.
It's actually good information for security architects. If you can't get approval to start using software updates, make sure your damn microphones are turned off.
That's some wishful thinking.
Most 'white noise generators' are really outputting some sort of spectrally shaped pseudo-random noise, e.g. sound masking systems in offices closely follow the response curve of the human voice and output basically nothing under 200Hz nor over 7kHz. Even if playing pure 'pink noise', which is logarithmically flat and thus much more reasonable to listen to, there would be very little power in the band the authors of the paper are using (17kHz to 20kHz). I would also doubt that many white noise generator products are capable of producing usable output at those frequencies in the first place. Most laptop speakers probably can as a result of their size and design. 'White noise generators' should be targeting low end extension over high frequency output and I doubt many have multiple drivers per channel to accomplish both goals. Given all this, I highly doubt off the shelf 'white noise generator' products would have much effect on this communication method.
There are ultrasonic 'blasters' for lack of a better term that may work. I know some convenience stores mount them outside the store in order to deter younger folks loitering outside. As you age the limits of your high frequency hearing is reduced in a fairly predictable way; e.g. at age 15 you may be able to hear up to 22kHz, at 35 you may only be able to hear up to 18kHz. If you want to drive away younger people, blast out noise in the 19kHz to 22kHz range, it's really annoying to listen to and older folks won't even notice it. A similar thing may work to deter this communication channel, as long as you don't have too many young people around, or older folks with exceptional hearing range for their age.
Anybody interested in the noise colors might take an interest in
http://playnoise.com/ (hint, hit more and enable stereo, I find that much more interesting for some reason).
I haven't played with this site in particular but they are probably using incoherent sources for each channel. i.e. using two separate random noise generators that aren't working off the same seed value. Even though the spectral content of each channel may be the same, it's not the same at any instant which causes your brain to get a bit 'lost', it doesn't sound like a point source anymore but instead just a 'room filling' sound that you can't pin point. The same principal (in a more targeted manner) is used in mixing stereo music to create a 'sound stage', usually only the voice mix is actually identical in both channels even though you can hear the guitar in each channel independently.
BAM!
Solved!
Of course, if one were playing music or something, it would be obvious that the switch had been circumvented.
Also consider that if you played the sound at maximum volume it might actually be audible some distance away from the headphones.
On Linux you can choose different behavior; so it's apparently software. At least, on machines I've worked on. Depending on that dropdown, I can plug in headphones and the built-in speakers will continue to output.
Send to the airgapped computer(s) software updates and new commands to run? 20 bytes per second is enough for that, or is it bits? A shellcode is about 40bytes or less.
I guess if you want to guard against this the reasonable thing to do would be to physically take out the mic and speakers of any to-be-secure-computers. Or have one computer listen in on these high frequencies on the perimeter or whatever. Would be interesting to discover chats.