Skip to main content
QUICK REVIEW

[論文レビュー] PowerHammer: Exfiltrating Data from Air-Gapped Computers through Power Lines

Mordechai Guri, Boris Zadov|arXiv (Cornell University)|Apr 10, 2018
Cryptographic Implementations and Security被引用数 5
ひとこと要約

PowerHammer は、CPU の負荷を調整して電源ラインの電流変動を生じさせることで、AC 電源ラインを通じて検出可能な電流変動を引き起こし、空気ギャップが空けられたコンピュータからデータを漏洩させるサイバー攻撃である。攻撃は個々のコンセント経由で 1,000 ビット/秒、メイン電気盤に接続する場合に 10 ビット/秒の速度を達成し、導波によるサイドチャネルを介した傍受不能かつ非侵襲的なデータ漏洩チャネルを実証した。

ABSTRACT

In this paper we provide an implementation, evaluation, and analysis of PowerHammer, a malware (bridgeware [1]) that uses power lines to exfiltrate data from air-gapped computers. In this case, a malicious code running on a compromised computer can control the power consumption of the system by intentionally regulating the CPU utilization. Data is modulated, encoded, and transmitted on top of the current flow fluctuations, and then it is conducted and propagated through the power lines. This phenomena is known as a 'conducted emission'. We present two versions of the attack. Line level powerhammering: In this attack, the attacker taps the in-home power lines1 that are directly attached to the electrical outlet. Phase level power-hammering: In this attack, the attacker taps the power lines at the phase level, in the main electrical service panel. In both versions of the attack, the attacker measures the emission conducted and then decodes the exfiltrated data. We describe the adversarial attack model and present modulations and encoding schemes along with a transmission protocol. We evaluate the covert channel in different scenarios and discuss signal-to-noise (SNR), signal processing, and forms of interference. We also present a set of defensive countermeasures. Our results show that binary data can be covertly exfiltrated from air-gapped computers through the power lines at bit rates of 1000 bit/sec for the line level power-hammering attack and 10 bit/sec for the phase level power-hammering attack.

研究の動機と目的

  • 空気ギャップが空けられたコンピュータから、電源ラインの電磁放射をサイドチャネルとして用いて、データを隠蔽的に漏洩させることの可能性を示すこと。
  • 2 種類の攻撃バージョン(ラインレベルおよびフェーズレベルの電源ハンマー攻撃)の実現可能性と性能を評価すること。
  • 実環境下での信号整合性、干渉、伝送信頼性を分析すること。
  • このような電源ライン側帯域攻撃に対する実用的な対策を提案および評価すること。

提案手法

  • 空気ギャップが空けられたシステムに仕込んだマルウェアが、CPU の使用率を操作して電力消費の制御された変動を引き起こす。
  • バイナリデータは、オンオフキーイングなどのベースバンド変調技術を用いて、得られた電流変動に符号化される。
  • 攻撃者は個々のコンセント(ラインレベル)またはメイン電気盤(フェーズレベル)に接続して、導波による放射を取得する。
  • 信号処理技術(フィルタリングおよびデモジュレーションなど)を用いて、測定された電流波形から元のデータを回復する。
  • ノイズや干渉が存在する状況でも同期と誤り耐性を確保するため、独自の送信プロトコルが採用される。
  • 対策として、EMI フィルタ、ハードウェア ジャンパー、ホストベースのインシデント検知システムが用いられ、隠蔽信号を遮断または検出する。

実験結果

リサーチクエスチョン

  • RQ1空気ギャップが空けられたシステムから、電源ラインの電流変動のみを用いてバイナリデータを信頼性高く漏洩させることは可能か?
  • RQ2実環境下における電源ラインベースの隠蔽チャネルで達成可能なデータレートは何か?
  • RQ3異なる干渉源やシステム構成は、信号整合性および伝送信頼性にどのように影響を与えるか?
  • RQ4このような攻撃に対して最も効果的な技術的およびソフトウェアベースの対策は何か?

主な発見

  • ラインレベルの電源ハンマー攻撃は 1,000 ビット/秒のデータ漏洩レートを達成し、実用的で現実的な攻撃手法であることが示された。
  • フェーズレベルの電源ハンマー攻撃は、低いが依然として実用的な 10 ビット/秒のデータレートを達成し、低帯域幅の漏洩に適している。
  • 一般的な電気的ノイズや仮想マシン環境が存在する中でも、隠蔽チャネルは依然として有効であり、耐障害性が高いことが示された。
  • 多くの商業用 EMI フィルタは、PowerHammer が使用する低周波数信号(24kHz 未満)を遮断できないため、この攻撃に対して無効である。
  • 非特権 CPU 指令の使用と、マルウェアが信頼できるプロセス内に隠れることで、ホストベースの検知は困難である。
  • ハードウェア ジャンパーは、メイン電気盤にアクセスできる必要があるため、フェーズレベルの攻撃にのみ効果的である。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。