Busca avançada
Ano de início
Entree


Platform-agnostic Low-intrusion Optical Data Exfiltration

Texto completo
Autor(es):
Lopes, Arthur Costa ; Aranha, Diego F. ; Mori, P ; Furnell, S ; Camp, O
Número total de Autores: 5
Tipo de documento: Artigo Científico
Fonte: ICISSP: PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS SECURITY AND PRIVACY; v. N/A, p. 7-pg., 2017-01-01.
Resumo

Information leakage through covert channels is a growing and persistent threat, even for physical perimeters considered as highly secure. We study a new approach for data exfiltration using a malicious storage device which subtly transmits data through blinking infrared LEDs. This approach could be used by an attacker trying to leak sensitive data stored in the device, such as credentials, cryptographic keys or a small classified document. An ideal application for this approach is when an attacker is capable of sneaking a malicious device inside a protected perimeter and has remote control over a camera inside such perimeter. The device can then collect information and transmit directly to the attacker, without the need of recovering the device to obtain the captured information, erase evidence or prevent a forensic investigation. We discuss techniques for improving communication efficiency up to 15 bits per second per LED, and possible countermeasures for mitigation. (AU)

Processo FAPESP: 15/13876-7 - Exfiltração óptica de dados em máquinas fisicamente isoladas
Beneficiário:Arthur Costa Lopes
Modalidade de apoio: Bolsas no Brasil - Iniciação Científica