Skip to main content
QUICK REVIEW

[论文解读] HVACKer: Bridging the Air-Gap by Attacking the Air Conditioning System

Yisroel Mirsky, Mordechai Guri|arXiv (Cornell University)|Mar 30, 2017
IoT-based Smart Home Systems参考文献 7被引用 14
一句话总结

HVACKer 提出了一种隐蔽的热通信信道,通过利用被攻陷的联网空调系统,以温度变化为媒介,在空气隔离网络之间实现数据外泄或指令下达。作者展示了新型线路编码方案及其实验可行性,实测带宽最高达 20 bps,揭示了空气隔离空调系统中此前未被考虑的攻击向量。

ABSTRACT

Modern corporations physically separate their sensitive computational infrastructure from public or other accessible networks in order to prevent cyber-attacks. However, attackers still manage to infect these networks, either by means of an insider or by infiltrating the supply chain. Therefore, an attacker's main challenge is to determine a way to command and control the compromised hosts that are isolated from an accessible network (e.g., the Internet). In this paper, we propose a new adversarial model that shows how an air gapped network can receive communications over a covert thermal channel. Concretely, we show how attackers may use a compromised air-conditioning system (connected to the internet) to send commands to infected hosts within an air-gapped network. Since thermal communication protocols are a rather unexplored domain, we propose a novel line-encoding and protocol suitable for this type of channel. Moreover, we provide experimental results to demonstrate the covert channel's feasibility, and to calculate the channel's bandwidth. Lastly, we offer a forensic analysis and propose various ways this channel can be detected and prevented. We believe that this study details a previously unseen vector of attack that security experts should be aware of.

研究动机与目标

  • 探究是否可将连接互联网的空调系统武器化,以在空气隔离网络中建立隐蔽通信。
  • 解决在传统网络通道不可用的隔离网络中实现命令与控制的挑战。
  • 设计并评估一种适用于低带宽、隐蔽数据传输的基于热力的通信协议。
  • 为工业控制系统中的此类隐蔽信道提供取证检测与缓解策略。

提出的方法

  • 攻击模型利用被攻陷的联网空调系统,以受控方式调节室内温度。
  • 设计了一种自定义的线路编码方案,将二进制数据表示为温度变化,从而实现在热力信道上的可靠传输。
  • 通过调节 HVAC 系统的制冷或制热输出,在目标环境中生成可检测的温度波动信号。
  • 协议结合脉宽调制与基于时间的编码方式,以提高信号完整性并降低误码率。
  • 在真实世界测试平台上开展实验,以测量在受控条件下数据传输速率与误码率。
  • 进行取证分析,以识别可能指示隐蔽通信的温度波动模式。

实验结果

研究问题

  • RQ1是否可利用联网 HVAC 系统在空气隔离主机上建立隐蔽通信信道?
  • RQ2通过 HVAC 系统实现热力调制时,最大可实现的数据速率是多少?
  • RQ3在真实环境噪声与温度波动下,所提出的热力通信协议的鲁棒性如何?
  • RQ4可开发何种检测机制以识别工业控制系统中的此类隐蔽信道?

主要发现

  • 所提出的热力通信协议在实验室条件下实现了最高 20 bps 的数据传输速率。
  • 系统在受控环境下实现了长达 10 米距离的可靠通信,且误码率极低。
  • HVAC 系统引起的温度变化可被精确检测与调节,足以编码二进制数据。
  • 由于无网络流量,该攻击向量可逃避传统基于网络的入侵检测系统。
  • 取证分析揭示了可被用于检测隐蔽通信的特定热力模式,提示了潜在的检测机制。
  • 本研究证实,HVAC 系统在空气隔离环境中是可行且此前被忽视的数据外泄或指令下达攻击面。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。