("Oops! Had the silly thing in reverse")---Optical injection attacks in through LED status indicators

06/30/2019
by   Joe Loughry, et al.
0

It is possible to attack a computer remotely through the front panel LEDs. Following on previous results that showed information leakage at optical wavelengths, now it seems practicable to inject information into a system as well. It is shown to be definitely feasible under realistic conditions (by infosec standards) of target system compromise; experimental results suggest it further may be possible, through a slightly different mechanism, even under high security conditions that put extremely difficult constraints on the attacker. The problem is of recent origin; it could not have occurred before a confluence of unrelated technological developments made it possible. Arduino-type microcontrollers are involved; this is an Internet of Things (IoT) vulnerability. Unlike some previous findings, the vulnerability here is moderate---at present---because it takes the infosec form of a classical covert channel. However, the architecture of several popular families of microcontrollers suggests that a Rowhammer-like directed energy optical attack that requires no malware might be possible. Phase I experiments yielded surprising and encouraging results; a covert channel is definitely practicable without exotic hardware, bandwidth approaching a Mbit/s, and the majority of discrete LEDs tested were found to be reversible on GPIO pins. Phase II experiments, not yet funded, will try to open the door remotely.

READ FULL TEXT
research
07/13/2023

Information Leakage from Optical Emanations

A previously unknown form of compromising emanations has been discovered...
research
04/19/2021

A Language for Modelling False Data Injection Attacks in Internet of Things

Internet of Things (IoT) is now omnipresent in all aspects of life and p...
research
08/10/2018

A Security Analysis of IoT Encryption: Side-channel Cube Attack on Simeck32/64

Simeck, a lightweight block cipher has been proposed to be one of the en...
research
08/26/2020

Measurement-driven Security Analysis of Imperceptible Impersonation Attacks

The emergence of Internet of Things (IoT) brings about new security chal...
research
01/18/2019

Smart-Lock Security Re-engineered using Cryptography and Steganography

After the rise of E-commerce, social media and messenger bots, rapid dev...
research
03/23/2021

Metal Fillers as Potential Low Cost Countermeasure against Optical Fault Injection Attacks

Physically accessible devices such as sensor nodes in Wireless Sensor Ne...

Please sign up or login with your details

Forgot password? Click here to reset