Platform-agnostic Low-intrusion Optical Data Exfiltration

Arthur Costa Lopes, Diego F. Aranha

2017

Abstract

Information leakage through covert channels is a growing and persistent threat, even for physical perimeters considered as highly secure. We study a new approach for data exfiltration using a malicious storage device which subtly transmits data through blinking infrared LEDs. This approach could be used by an attacker trying to leak sensitive data stored in the device, such as credentials, cryptographic keys or a small classified document. An ideal application for this approach is when an attacker is capable of sneaking a malicious device inside a protected perimeter and has remote control over a camera inside such perimeter. The device can then collect information and transmit directly to the attacker, without the need of recovering the device to obtain the captured information, erase evidence or prevent a forensic investigation. We discuss techniques for improving communication efficiency up to 15 bits per second per LED, and possible countermeasures for mitigation.

Download


Paper Citation


in Harvard Style

Costa Lopes A. and Aranha D. (2017). Platform-agnostic Low-intrusion Optical Data Exfiltration . In Proceedings of the 3rd International Conference on Information Systems Security and Privacy - Volume 1: ICISSP, ISBN 978-989-758-209-7, pages 474-480. DOI: 10.5220/0006211504740480

in Bibtex Style

@conference{icissp17,
author={Arthur Costa Lopes and Diego F. Aranha},
title={Platform-agnostic Low-intrusion Optical Data Exfiltration},
booktitle={Proceedings of the 3rd International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,},
year={2017},
pages={474-480},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0006211504740480},
isbn={978-989-758-209-7},
}


in EndNote Style

TY - CONF
JO - Proceedings of the 3rd International Conference on Information Systems Security and Privacy - Volume 1: ICISSP,
TI - Platform-agnostic Low-intrusion Optical Data Exfiltration
SN - 978-989-758-209-7
AU - Costa Lopes A.
AU - Aranha D.
PY - 2017
SP - 474
EP - 480
DO - 10.5220/0006211504740480