[论文解读] POWER-SUPPLaY: Leaking Data from Air-Gapped Systems by Turning the Power-Supplies Into Speakers
该论文提出了一种名为 POWER-SUPPLaY 的新型声学隐蔽信道,通过操控计算机电源供应单元(PSU)的内部开关频率,将 PSU 转变为扬声器,从而生成可听及超声波音调。该技术可在无需音频硬件或特权提升的情况下,实现高达 50 bit/sec 的数据外泄,适用于空气隔离和音频隔离的系统。
It is known that attackers can exfiltrate data from air-gapped computers through their speakers via sonic and ultrasonic waves. To eliminate the threat of such acoustic covert channels in sensitive systems, audio hardware can be disabled and the use of loudspeakers can be strictly forbidden. Such audio-less systems are considered to be \ extit{audio-gapped}, and hence immune to acoustic covert channels. In this paper, we introduce a technique that enable attackers leak data acoustically from air-gapped and audio-gapped systems. Our developed malware can exploit the computer power supply unit (PSU) to play sounds and use it as an out-of-band, secondary speaker with limited capabilities. The malicious code manipulates the internal \ extit{switching frequency} of the power supply and hence controls the sound waveforms generated from its capacitors and transformers. Our technique enables producing audio tones in a frequency band of 0-24khz and playing audio streams (e.g., WAV) from a computer power supply without the need for audio hardware or speakers. Binary data (files, keylogging, encryption keys, etc.) can be modulated over the acoustic signals and sent to a nearby receiver (e.g., smartphone). We show that our technique works with various types of systems: PC workstations and servers, as well as embedded systems and IoT devices that have no audio hardware at all. We provide technical background and discuss implementation details such as signal generation and data modulation. We show that the POWER-SUPPLaY code can operate from an ordinary user-mode process and doesn't need any hardware access or special privileges. Our evaluation shows that using POWER-SUPPLaY, sensitive data can be exfiltrated from air-gapped and audio-gapped systems from a distance of five meters away at a maximal bit rates of 50 bit/sec.
研究动机与目标
- 证明即使在音频硬件被禁用或不存在的情况下,仍可从空气隔离系统中实现数据外泄。
- 探究电源供应单元(PSU)是否可被利用为非预期的声学发射器。
- 开发一种隐蔽的、仅在用户模式下运行的恶意软件技术,无需特殊权限或硬件访问。
- 评估在多种系统(包括嵌入式系统和物联网设备)中,利用 PSU 实现声学数据外泄的可行性。
- 探索针对此新型隐蔽信道的实际防护对策。
提出的方法
- 恶意软件通过调节 PSU 的 DC-DC 转换器的开关频率,利用电感器和电容器产生受控的声学波形。
- 该技术通过 CPU 密集型的空转循环来调节开关频率,产生 0–24 kHz 范围内的调制音频音调。
- 使用标准调制技术(如 FSK)将二进制数据调制到声学信号上以实现传输。
- 附近的接收设备(如智能手机)捕获声学信号,并通过标准音频处理技术解码数据。
- 该方法完全在用户空间运行,无需内核访问、硬件 I/O 或特殊权限。
- 通过精确控制软件循环的时序,实现信号生成,利用 PSU 元件的固有机械共振特性。
实验结果
研究问题
- RQ1能否将计算机的电源供应单元作为次级扬声器,无需音频硬件即可通过声学方式传输数据?
- RQ2是否可能仅通过 PSU 生成的声学辐射,从空气隔离或音频隔离的系统中实现数据外泄?
- RQ3此类隐蔽信道是否可在无特权或直接硬件访问的情况下运行?
- RQ4使用基于 PSU 的声学传输,最大可实现的数据速率是多少?
- RQ5现有检测与缓解技术对此新型隐蔽信道的有效性如何?
主要发现
- POWER-SUPPLaY 技术成功地在无任何音频硬件或特权的情况下,从 PSU 生成了可听及超声波音调。
- 该方法在最长 5 米的距离内实现了最高 50 bit/sec 的数据外泄速率。
- 该技术在多种系统上均有效,包括无音频硬件的个人电脑工作站、服务器以及嵌入式/IoT 设备。
- 恶意软件可在标准用户模式进程中运行,使其对静态和动态分析具有高度隐蔽性。
- 声学辐射通过操控 PSU 的开关频率生成,利用了电容器和变压器的固有机械振动特性。
- 由于信噪比低且在安静环境中难以与背景噪声区分,信号检测和干扰均具挑战性。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。