ETHERLED: Sending Covert Morse Signals from Air-Gapped Devices via Network Card (NIC) LEDs

08/21/2022
by   Mordechai Guri, et al.
0

Highly secure devices are often isolated from the Internet or other public networks due to the confidential information they process. This level of isolation is referred to as an 'air-gap .' In this paper, we present a new technique named ETHERLED, allowing attackers to leak data from air-gapped networked devices such as PCs, printers, network cameras, embedded controllers, and servers. Networked devices have an integrated network interface controller (NIC) that includes status and activity indicator LEDs. We show that malware installed on the device can control the status LEDs by blinking and alternating colors, using documented methods or undocumented firmware commands. Information can be encoded via simple encoding such as Morse code and modulated over these optical signals. An attacker can intercept and decode these signals from tens to hundreds of meters away. We show an evaluation and discuss defensive and preventive countermeasures for this exfiltration attack.

READ FULL TEXT
research
12/12/2020

AIR-FI: Generating Covert Wi-Fi Signals from Air-Gapped Computers

In this paper, we show that attackers can exfiltrate data from air-gappe...
research
09/30/2021

LANTENNA: Exfiltrating Data from Air-Gapped Networks via Ethernet Cables

Air-gapped networks are wired with Ethernet cables since wireless connec...
research
11/09/2017

Exfiltration of Data from Air-gapped Networks via Unmodulated LED Status Indicators

The light-emitting diode(LED) is widely used as an indicator on the info...
research
05/07/2008

Fabrication of Embedded Microvalve on PMMA Microfluidic Devices through Surface Functionalization

The integration of a PDMS membrane within orthogonally placed PMMA micro...
research
01/10/2018

IREXF: Data Exfiltration from Air-gapped Networks by Infrared Remote Control Signals

he technology on infrared remote control is widely applied in human dail...
research
04/12/2023

Distributed Gesture Controlled Systems for Human-Machine Interface

This paper presents the design flow of an IoT human machine touchless in...
research
07/15/2022

SATAn: Air-Gap Exfiltration Attack via Radio Signals From SATA Cables

This paper introduces a new type of attack on isolated, air-gapped works...

Please sign up or login with your details

Forgot password? Click here to reset