SATAn: Air-Gap Exfiltration Attack via Radio Signals From SATA Cables

07/15/2022
by   Mordechai Guri, et al.
0

This paper introduces a new type of attack on isolated, air-gapped workstations. Although air-gap computers have no wireless connectivity, we show that attackers can use the SATA cable as a wireless antenna to transfer radio signals at the 6 GHz frequency band. The Serial ATA (SATA) is a bus interface widely used in modern computers and connects the host bus to mass storage devices such as hard disk drives, optical drives, and solid-state drives. The prevalence of the SATA interface makes this attack highly available to attackers in a wide range of computer systems and IT environments. We discuss related work on this topic and provide technical background. We show the design of the transmitter and receiver and present the implementation of these components. We also demonstrate the attack on different computers and provide the evaluation. The results show that attackers can use the SATA cable to transfer a brief amount of sensitive information from highly secured, air-gap computers wirelessly to a nearby receiver. Furthermore, we show that the attack can operate from user mode, is effective even from inside a Virtual Machine (VM), and can successfully work with other running workloads in the background. Finally, we discuss defense and mitigation techniques for this new air-gap attack.

READ FULL TEXT

page 3

page 4

page 6

research
09/30/2021

LANTENNA: Exfiltrating Data from Air-Gapped Networks via Ethernet Cables

Air-gapped networks are wired with Ethernet cables since wireless connec...
research
12/07/2022

COVID-bit: Keep a Distance of (at least) 2m From My Air-Gap Computer!

Air-gapped systems are isolated from the Internet due to the sensitive i...
research
04/13/2020

AiR-ViBeR: Exfiltrating Data from Air-Gapped Computers via Covert Surface ViBrAtIoNs

Air-gap covert channels are special types of covert communication channe...
research
02/08/2018

ODINI : Escaping Sensitive Data from Faraday-Caged, Air-Gapped Computers via Magnetic Fields

Air-gapped computers are computers which are kept isolated from the Inte...
research
03/01/2023

Dishing Out DoS: How to Disable and Secure the Starlink User Terminal

Satellite user terminals are a promising target for adversaries seeking ...
research
08/21/2022

ETHERLED: Sending Covert Morse Signals from Air-Gapped Devices via Network Card (NIC) LEDs

Highly secure devices are often isolated from the Internet or other publ...
research
03/09/2018

MOSQUITO: Covert Ultrasonic Transmissions between Two Air-Gapped Computers using Speaker-to-Speaker Communication

In this paper we show how two (or more) airgapped computers in the same ...

Please sign up or login with your details

Forgot password? Click here to reset