{"id":13857,"date":"2021-01-06T14:19:12","date_gmt":"2021-01-06T19:19:12","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=13857"},"modified":"2023-04-07T15:29:14","modified_gmt":"2023-04-07T19:29:14","slug":"researchers-breach-air-gapped-systems-by-turning-ram-into-wi-fi-card","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/researchers-breach-air-gapped-systems-by-turning-ram-into-wi-fi-card\/","title":{"rendered":"Researchers Breach Air-Gapped Systems by Turning RAM Into Wi-Fi Cards"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\" id=\"h-a-new-type-of-attack-uses-signals-generated-by-ram-to-steal-data-from-systems-without-wi-fi-cards\">A New Type of Attack Uses Signals Generated by RAM to Steal Data From Systems Without Wi-Fi Cards<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Keeping secrets is easier said than done. The measures required to safeguard a secret are usually proportional to its importance. If we\u2019re talking about a bit of juicy gossip that you don\u2019t want the neighbors to hear, then you\u2019re probably safe with simply not telling the wrong people. For data that\u2019s a bit more important, like your bank account login or your email account, there\u2019s things like <a href=\"https:\/\/www.thesslstore.com\/extended-validation-ssl-certificates.aspx\">SSL\/TLS certificates<\/a>. But for the highest level of security, in the event that you\u2019re dealing with state secrets or mission-critical, proprietary company information, you\u2019ll want to go with an <a href=\"https:\/\/www.thesslstore.com\/blog\/air-gapped-computer\/\">air-gapped system<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Air gapping refers to there being a physical barrier (or \u201cair\u201d) between the data-repository and the outside world. Basically, it means that the storage machine has no way to access any sort of networks or means of communication. And considering the day and age we\u2019re living in, where even a <a href=\"https:\/\/www.thesslstore.com\/blog\/java-ransomware-literally-not-even-your-coffee-maker-is-safe\/\">coffee pot can fall victim to a ransomware attack<\/a>, a total disconnect seems like the only way to 100% security. So air gapping &#8211; sounds good, right?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Not so fast, my friend. Researchers from Israel\u2019s Ben-Gurion University of the Negev would like to have a word with you. In their recently published paper, <a href=\"https:\/\/arxiv.org\/abs\/2012.06884\"><em>AIR-FI: Generating Covert Wi-Fi Signals from Air-Gapped Computers<\/em><\/a><em>, <\/em>they explain a method they\u2019ve discovered that allows one to essentially convert a RAM card into a wireless emitter. That said emitter is able to send sensitive data from an air-gapped computer that doesn\u2019t even have a Wi-Fi card on board.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Noted air-gap researcher Mordechai Guri spearheaded the project, dubbed \u201cAIR-FI\u201d, and came up with the idea of exploiting the electromagnetic waves that are produced by an air-gapped system. The way the attack is carried out is via malware that has been loaded onto the machine. As Dr. Guri explains,<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Malware in a compromised air-gapped computer can generate signals in the Wi-Fi frequency bands. The signals are generated through the memory buses \u2014 no special hardware is required.<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">An attacker would then use a Wi-Fi capable receiving device to grab the data as it\u2019s being sent out.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So what lead the researchers down this path?&nbsp; How exactly does the exploit work?&nbsp; And how can air-gapped systems be protected from such an attack?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s hash it out.<span id=\"newline\"><\/span><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-a-history-of-air-gap-research\">A History of Air Gap Research<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">AIR-FI isn\u2019t the first air-gap attack method to come from Guri\u2019s group. Guri, who is head of R&amp;D at the Ben-Gurion University of the Negev in Israel, has spent the last five years working on projects that aim to find new vulnerabilities in air-gapped systems.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some of the other notable air-gap attack vectors discovered by Dr. Guri and his team include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/cyber.bgu.ac.il\/advanced-cyber\/system\/files\/LED-it-GO_0.pdf\">LED-it-Go<\/a> &#8211; uses an HDD\u2019s activity LED to extract data.<\/li>\n\n\n\n<li><a href=\"https:\/\/arxiv.org\/abs\/1608.08397\">USBee<\/a> &#8211;&nbsp; steals data by instructing a USB connector\u2019s data bus to emit electromagnetic emissions that can be measured.<\/li>\n\n\n\n<li><a href=\"https:\/\/arxiv.org\/abs\/1709.05742\">aIR-Jumper<\/a> &#8211; takes advantage of the infrared capabilities of security cameras.<\/li>\n\n\n\n<li><a href=\"https:\/\/arxiv.org\/abs\/1803.03422\">MOSQUITO<\/a> \u2013 uses headphones and speakers as the means of attack.<\/li>\n\n\n\n<li><a href=\"https:\/\/arxiv.org\/abs\/2004.06195v1\">AiR-ViBeR<\/a> \u2013 looks at the fan vibrations of a user\u2019s machine<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-why-do-it\">Why Do It?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Dr. Guri focuses his research on methods that are referred to as \u201ccovert data exfiltration channels.\u201d These aren\u2019t the conventional attack types that we usually see from hackers (which are usually more straightforward, with the goal of simply gaining access to a particular computer), but rather unusual, unconventional, and unexpected ways to steal data that defenders aren\u2019t anticipating. It\u2019s not the typical thing that average users like you or I would worry about, but at the same time it\u2019s a constant worry for the keepers of air-gapped networks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Since air-gapped systems usually hold the highest of the high-value information, even the tiniest vulnerability could lead to a breach and a catastrophic chain of events. Those that depend on air-gapped systems, like government, military, or corporate entities, rely on research like Dr. Guri\u2019s to continuously keep their secrets safe against a litany of ever-emerging new attack vectors. Studies like these force organizations to (hopefully) reexamine their system architecture and ensure the optimal level of protection can be maintained.<\/p>\n\n\n<span style=\"--tl-form-height-m:150.25px;--tl-form-height-t:121.4583px;--tl-form-height-d:121.4583px;\" class=\"tl-placeholder-f-type-shortcode_12753 tl-preload-form\"><span><\/span><\/span>\n\n\n<h2 class=\"wp-block-heading\" id=\"h-how-it-works\">How It Works<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-theory-behind-it\">The Theory Behind It<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">It all starts with electromagnetic waves. Every electronic component generates them as long as there is current flow present. Wi-Fi signals are a type of radio wave, which are in turn a type of electromagnetic wave. The theory behind AIR-FI is that a piece of code can theoretically play with the amount of current a RAM card is using in order to generate a wave whose frequency is within the normal Wi-Fi signal spectrum of 2.4 GHz. As Guri explains, <\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Since the clock speed of memory modules is typically around the frequency of 2.4 GHz or its harmonics, the memory operations generate electromagnetic emissions around the IEEE 802.11b\/g\/n Wi-Fi frequency bands.<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The signal, which is a result of precisely timed read and write operations to RAM, can thus be received by any device with a Wi-Fi antenna that\u2019s in relatively close physical proximity to an air-gapped system. This includes things like smartphones, laptops, smartwatches, and IoT devices. To achieve this end, the researchers made use of a feature designed by Intel, Extreme Memory Profile (XMP), that was created to let gamers overclock their PC\u2019s for increased performance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What\u2019s even scarier is that root or admin privileges aren\u2019t needed beforehand, so this is a pretty easy exploit to pull off if the other pieces of the puzzle are in place. Since AIR-FI can be deployed from a regular user process, it allows the attack to work on any OS as well as virtual machines.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-infection-process\">The Infection Process<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">One major thing to note is that there are prerequisites for a hacker to carry out this type of attack successfully. It isn\u2019t enough to just get physically close to an air-gapped system \u2013 they must first get malicious code onto the targeting machine. This could be achieved by a nefarious party while the device is being manufactured, during the testing or shipping process, or by a compromised USB storage drive inserted into the air-gapped computer. Social engineering and staff deception are oft-effective means to this end, and unfortunately no piece of code can fully protect against human error.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There also needs to be a method of extraction. As we discussed earlier, there\u2019s no shortage of capable devices that have Wi-Fi capability including phones, laptops, tablets, and IoT machines. Smart devices aren\u2019t safe either, and Guri has previously shown that IoT devices like smart locks and light bulbs could be used as part of the export process. Whatever the method, the basic steps are the same:<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\">\n<li>Load malware onto air-gapped system.<\/li>\n\n\n\n<li>The malware steals data from the system.<\/li>\n\n\n\n<li>The malware uses the RAM to emit the data as a wireless signal that can be read by the receiving device.<\/li>\n\n\n\n<li>The receiving device collects the emitted data.<\/li>\n<\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">As the research paper explains,<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">As a part of the exfiltration phase, the attacker might collect data from the compromised computers. The data can be documents, key logging, credentials, encryption keys, etc. Once the data is collected, the malware initiates the AIR-FI covert channel. It encodes the data and transmits it to the air (in the Wi-Fi band at 2.4 GHz) using the electromagnetic emissions generated from the DDR SDRAM buses.<\/p>\n<\/blockquote>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-the-test-setup-results\">The Test Setup &amp; Results<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Now let\u2019s take a look at the nitty gritty details of Dr. Guri\u2019s test setup. Four workstations were used\/hacked with the exploit. Each one was outfitted with 4GB DIMM DDR4 or DDR3 RAM memory sticks. No special hardware was used, just normal PC\u2019s that were running on the Ubuntu operating system.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s important to remember that the wireless signals being emitted by the RAM don\u2019t have a very long range. An attacker would need to be no more than a few feet away from an air-gapped system in order to be able to pull it off.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">As for the specifics of the RAM\u2019s signal output, researchers were able to reach a maximum transfer rate of about 100 bytes per second. If you\u2019re looking to transmit a 1MB file, then hopefully you have a safe hiding spot set up because it would take roughly 22 hours to complete. Oh, and you also shouldn\u2019t be more than 69 inches away.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Transmission speeds and error rates also depend greatly on the equipment used. Dr. Guri\u2019s team found their best results with a system consisting of an ASRock ATX motherboard, Intel Core i7 3.2Ghz CPU, 4GB of Crucial 2.4GHz DDR4 SRAM, and the Ubuntu OS.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s not the most practical means of attack, but pretty much anything is possible, especially as the stakes get higher and higher.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Guri wrote about the results,<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">We transmitted the data at a bit rate of 100 bps and maintained a bit error rate (BER) of 8.75 percent for a distance up to 180 cm from the transmitter. Note that due to the local ramifications and interference, the signal quality may vary with the distance and location of the receiver.<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s very likely that one could improve upon those numbers if they were able to test a wider range of components and configurations, however.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-protecting-your-air-gap\">Protecting Your Air Gap<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The research paper also suggests different countermeasures that can be used safeguard air-gapped systems from these sorts of unconventional attacks. Organizations can:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Deploy signal-jamming equipment in the physical proximity of air-gapped systems to prevent the use of wireless signals.<\/li>\n\n\n\n<li>Ban all network-connected phones, laptops, tablets, and other devices so they can\u2019t be used as a receiver.<\/li>\n\n\n\n<li>Use the zone separation measures <a href=\"https:\/\/www.sans.org\/reading-room\/whitepapers\/privacy\/introduction-tempest-981\">suggested by the U.S. and NATO telecommunication security standards<\/a> to reduce the risk of TEMPEST (Telecommunications Electronics Materials Protected from Emanating Spurious Transmissions) dangers.<\/li>\n\n\n\n<li>Employ runtime detection.<\/li>\n\n\n\n<li>Outfit machines with Faraday shielding to block electromagnetic waves.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Besides implementing these technical measures, organizations should also be sure to limit access to systems. No matter what type of data you\u2019re trying to protect, whether it\u2019s state secrets and air-gapped systems or simply the server you use for your website, it\u2019s critical to be comprehensive because you never know where a breach could originate. And in the meantime, researchers like Dr. Guri will keep trying to find new ways in.<\/p>\n\n\n<span style=\"--tl-form-height-m:966.781px;--tl-form-height-t:989px;--tl-form-height-d:989px;\" class=\"tl-placeholder-f-type-shortcode_12768 tl-preload-form\"><span><\/span><\/span>\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A New Type of Attack Uses Signals Generated by RAM to Steal Data From Systems Without Wi-Fi Cards Keeping secrets is easier said than done. The measures required to safeguard&#8230;<\/p>\n","protected":false},"author":37,"featured_media":13858,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[13107,130],"tags":[],"class_list":["post-13857","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-beyond-hashed-out","category-everything-encryption","post-without-tags"],"views":9447,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2021\/01\/ramwifi1.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/13857","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/37"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=13857"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/13857\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/13858"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=13857"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=13857"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=13857"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}