【24h】

Xerox Day Vulnerability

机译:施乐日漏洞

获取原文
获取原文并翻译 | 示例
           

摘要

In the area of espionage between countries, an infiltration covert channel used to trigger a silent malware installed on a network of a critical organization (such as 911 services and missile launching facility) from the outside world is extremely dangerous to the target country's security. In order to prevent attackers from establishing such a channel, these organizations take various steps to secure their networks, to make the establishment of this type of covert channel very challenging and almost impractical to achieve; the current state of the art methods are very limited and ineffective. In this paper, we show that even a strong isolation technique, such as air-gapping the network, can be circumvented by using an organizational multifunction printer (MFP) to establish an infiltration covert channel in order to communicate with a malware installed on an isolated organization from the outside. We show how an attacker can leverage the light sensitivity of an MFP and use different light sources to infiltrate commands to the malware in the organization. We analyze the influence of light intensity, distance, transmission rate, ambient light, and wavelength on the covert channel. In addition we demonstrate the attack on a real organization using: 1) a laser attached to a tripod stand; 2) a laser carried by a drone; and 3) a hijacked smart bulb that is not even connected to the organization's network and is accessed and controlled by an attacker in a passing car. We prove that locating the scanner in an inner room inside an organization does not prevent an attacker from establishing the covert channel. We show how our covert channel can be established from a greater distance (900 m) and at a higher transmission rate of 200 bits/s than other methods used to infiltrate data to an organization, even using invisible light (covertly).
机译:在国家之间的间谍活动领域,用于触发来自外部世界的重要组织(例如911服务和导弹发射设施)网络上安装的静默恶意软件的渗透秘密通道对目标国家的安全极为危险。为了防止攻击者建立这样的渠道,这些组织采取了各种步骤来保护其网络,使这种隐蔽渠道的建立非常具有挑战性,几乎是不切实际的。当前技术水平非常有限且无效。在本文中,我们表明,甚至可以通过使用组织多功能打印机(MFP)建立渗透秘密通道来与安装在隔离的恶意软件之间进行通信,从而避免使用诸如隔离网络等强大的隔离技术。外部组织。我们展示了攻击者如何利用MFP的光敏性并使用不同的光源将命令渗透到组织中的恶意软件。我们分析了光强度,距离,传输速率,环境光和波长对隐蔽通道的影响。另外,我们使用以下方法论证了对真实组织的攻击:1)将激光束固定在三脚架上; 2)无人机携带的激光; 3)甚至没有连接到组织网络的被劫持的智能灯泡,攻击者可以在经过的汽车中对其进行访问和控制。我们证明,将扫描仪放置在组织内部的房间中不会阻止攻击者建立隐蔽通道。我们展示了与其他用于将数据渗透到组织的方法相比,即使使用可见光(隐式),也可以从更远的距离(900 m)和200位/秒的更高传输速率建立隐蔽通道。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号