Data Exfiltration from Air-Gapped Computers based on ARM CPU

Abstract

Air-gapped Network is a network isolated from public networks. Several techniques of data exfiltration from air-gapped networks have been recently proposed. Air-gap malware is a malware that breaks the isolation of an air-gapped computer using air-gap covert channels, which extract information from air-gapped computers running on air-gap networks. Guri et al. presented an air-gap malware “GSMem”, which can exfiltrate data from air-gapped computers over GSM frequencies, 850 MHz to 900MHz. GSMem makes it possible to send data using the radio waves leaked out from the system bus between CPU and RAM. It generates binary amplitude shift keying (B-ASK) modulated waves with x86 SIMD instruction. In order to efficiently emit electromagnetic waves from the system-bus, it is necessary to access the RAM without being affected by the CPU caches. GSMem adopts an instruction that writes data without accessing CPU cache in Intel CPU. This paper proposes an air-gap covert channel for computers based on ARM CPU, which includes a software algorithm that can effectively cause cache misses. It is also a technique to use NEON instructions and transmit B-ASK modulated data by radio waves radiated from ARM based computer (e.g. Raspberry Pi 3). The experiment shows that the proposed program sends binary data using radio waves (about 1000kHz ~ 1700kHz) leaked out from system-bus between ARM CPU and RAM. The program can also run on Android machines based on ARM CPU (e.g. ASUS Zenpad 3S 10 and OnePlus 3).

Authors and Affiliations

Kenta Yamamoto, Miyuki Hirose, Taiichi Saito

Keywords

Related Articles

A Hindi Speech Actuated Computer Interface for Web Search

Aiming at increasing system simplicity and flexibility, an audio evoked based system was developed by integrating simplified headphone and user-friendly software design. This paper describes a Hindi Speech Actuated Compu...

Spectral Efficiency of Massive MIMO Communication Systems with Zero Forcing and Maximum Ratio Beamforming

The massive multiple-input-multiple-output (MIMO) is a key enabling technology for the 5G cellular communication systems. In massive MIMO (M-MIMO) systems few hundred numbers of antennas are deployed at each base station...

Optimal Design of a Variable Coefficient Fractional Order PID Controller by using Heuristic Optimization Algorithms

This paper deals with an optimal design of a new type Variable coefficient Fractional Order PID (V-FOPID) controller by using heuristic optimization algorithms. Although many studies have mainly paid attention to correct...

Green ICT Readiness Model for Developing Economies: Case of Kenya

There has been growing concerns about the rising costs of doing business and environmental degradation world over. Green ICT has been proposed to provide solutions to the two issues yet it is not being implemented fully...

Detection of Violations in Credit Cards of Banks and Financial Institutions based on Artificial Neural Network and Metaheuristic Optimization Algorithm

Due to popularity of the World Wide Web and e-commerce, electronic communications between people and different organizations through virtual world of the Internet have provided a good basis for commercial and economic re...

Download PDF file
  • EP ID EP261527
  • DOI 10.14569/IJACSA.2018.090125
  • Views 65
  • Downloads 0

How To Cite

Kenta Yamamoto, Miyuki Hirose, Taiichi Saito (2018). Data Exfiltration from Air-Gapped Computers based on ARM CPU. International Journal of Advanced Computer Science & Applications, 9(1), 183-190. https://europub.co.uk/articles/-A-261527