Papers
Topics
Authors
Recent
Search
2000 character limit reached

RAMBO: Leaking Secrets from Air-Gap Computers by Spelling Covert Radio Signals from Computer RAM

Published 3 Sep 2024 in cs.CR | (2409.02292v1)

Abstract: Air-gapped systems are physically separated from external networks, including the Internet. This isolation is achieved by keeping the air-gap computers disconnected from wired or wireless networks, preventing direct or remote communication with other devices or networks. Air-gap measures may be used in sensitive environments where security and isolation are critical to prevent private and confidential information leakage. In this paper, we present an attack allowing adversaries to leak information from air-gapped computers. We show that malware on a compromised computer can generate radio signals from memory buses (RAM). Using software-generated radio signals, malware can encode sensitive information such as files, images, keylogging, biometric information, and encryption keys. With software-defined radio (SDR) hardware, and a simple off-the-shelf antenna, an attacker can intercept transmitted raw radio signals from a distance. The signals can then be decoded and translated back into binary information. We discuss the design and implementation and present related work and evaluation results. This paper presents fast modification methods to leak data from air-gapped computers at 1000 bits per second. Finally, we propose countermeasures to mitigate this out-of-band air-gap threat.

Authors (1)
Citations (2)

Summary

  • The paper presents a novel exfiltration method that leverages RAM-generated EMR to leak data from air-gapped systems.
  • The paper uses modulation techniques like On-Off Keying and Manchester encoding to embed sensitive data in the emitted signals.
  • The paper evaluates the attack achieving up to 1000 bps over a 7-meter range, outlining practical implications and effective countermeasures.

RAMBO: Leaking Secrets from Air-Gap Computers by Spelling Covert Radio Signals from Computer RAM

The paper "RAMBO: Leaking Secrets from Air-Gap Computers by Spelling Covert Radio Signals from Computer RAM" presents a novel exfiltration technique capable of leaking information from air-gapped computers via electromagnetic radiation (EMR) emitted from RAM modules. The authors, led by Mordechai Guri from Ben-Gurion University of the Negev, provide an in-depth analysis and evaluation of this covert channel, emphasizing its implementation, practical feasibility, and possible countermeasures.

Air-gapped systems, disconnected from external networks, are widely considered highly secure against cyber-attacks. These systems are physically isolated to prevent unauthorized access to sensitive information. However, the RAMBO attack challenges this assumption by introducing a method that leverages EMR from RAM to covertly transmit data to an attacker.

Air-Gap Isolation and Breach Techniques

Typical air-gap security involves disabling network interfaces, disallowing USB connections, and ensuring no direct link to external networks. Despite these measures, prior incidents such as Stuxnet and Agent.BTZ have demonstrated vulnerabilities in air-gapped systems. The RAMBO attack is positioned within this context, proposing an advanced technique to breach these isolated environments.

RAMBO Attack Model

The RAMBO attack model is a multi-phase strategy. Initially, malware is introduced to the air-gapped system through physical media or supply chain compromises. Once the system is infected, the malware manipulates the RAM to generate EMR that encodes sensitive information. An attacker, positioned within a certain range, intercepts these signals using software-defined radio (SDR) hardware.

Implementation of RAMBO Attack

Signal Generation

The RAM bus generates EMR as a byproduct of high-frequency data transfers. The RAMBO attack exploits this by modulating memory access patterns, using techniques such as On-Off Keying (OOK) and Manchester encoding, to represent binary data within the EM emissions. This signal is then intercepted and decoded by an attacker.

Experimental Setup and Evaluation

The authors conducted extensive evaluations using multiple workstations equipped with different configurations of Intel i7 CPUs and DDR RAM. Signal interception was facilitated by Ettus B210 SDR hardware. Various bit rates and distances were tested to determine the reliability and efficacy of the RAMBO attack. Results demonstrated bit rates up to 1000 bits per second with sustainable bit error rates up to a distance of 700 cm.

Key Evaluation Metrics

  1. Signal-to-Noise Ratio (SNR): The SNR was measured at various distances, highlighting the relationship between bit rate and transmission reliability. Notably, lower bit times correlated with higher SNR values, resulting in more effective data transmission.
  2. Bit Rates and Error Rates: The study explored different transmission speeds from 10ms to 1ms per bit, demonstrating effective communication with acceptable BERs within specific distance thresholds.
  3. Data Exfiltration: Practical examples were provided, showing the time required to exfiltrate various types of data, such as encryption keys, biometric information, and keylogging data.

Countermeasures

To mitigate the threat posed by RAMBO, the paper discusses several defensive countermeasures:

  • Zone Restrictions and Red-Black Separation: Physically separating sensitive areas to limit the presence of radio receivers.
  • Host Intrusion Detection Systems (HIDS): Monitoring memory operations for suspicious patterns.
  • Hypervisor-Level Memory Access Monitoring: Utilizing hypervisors to detect anomalies in virtual memory operations.
  • External Electromagnetic Monitoring: Using spectrum analyzers to detect and mitigate unintended EM emissions.
  • Internal and External Jamming: Disrupting the covert channel through random memory operations or external RF interference.
  • Faraday Enclosures: Using Faraday cages to physically block EM emissions from the compromised systems.

Implications and Future Directions

While the RAMBO attack presents a sophisticated method of breaching air-gapped systems, it also underscores the need for enhanced countermeasures that address electromagnetic vulnerabilities. This attack vector may push for the development of new hardware-level protections and more advanced monitoring tools to secure highly isolated environments. Future work in this domain could involve optimizing detection algorithms for lower false positives and exploring alternative covert channels.

Conclusion

The RAMBO attack provides a comprehensive study of how EM emissions from RAM can be exploited to exfiltrate data from air-gapped systems. Through detailed evaluation and analysis, the authors demonstrate the feasibility of this covert channel, while also proposing effective countermeasures. This research contributes significantly to understanding the electromagnetic vulnerabilities of air-gapped computers and paves the way for more robust security measures in sensitive environments.

Paper to Video (Beta)

No one has generated a video about this paper yet.

Whiteboard

No one has generated a whiteboard explanation for this paper yet.

Open Problems

We found no open problems mentioned in this paper.

Tweets

Sign up for free to view the 24 tweets with 2258 likes about this paper.