RAMBO: Leaking Secrets from Air-Gap Computers by Spelling Covert Radio Signals from Computer RAM.

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

Abstract

Air-gapped systems are physically separated from external networks, including the Internet. This isolation is achieved by keeping the air-gap computers disconnected from wired or wireless networks, preventing direct or remote communication with other devices or networks. Air-gap measures may be used in sensitive environments where security and isolation are critical to prevent private and confidential information leakage. In this paper, we present an attack allowing adversaries to leak information from air-gapped computers. We show that malware on a compromised computer can generate radio signals from memory buses (RAM). Using software-generated radio signals, malware can encode sensitive information such as files, images, keylogging, biometric information, and encryption keys. With software-defined radio (SDR) hardware, and a simple off-the-shelf antenna, an attacker can intercept transmitted raw radio signals from a distance. The signals can then be decoded and translated back into binary information. We discuss the design and implementation and present related work and evaluation results. This paper presents fast modification methods to leak data from air-gapped computers at 1000 bits per second. Finally, we propose countermeasures to mitigate this out-of-band air-gap threat.
Original languageEnglish
Title of host publicationSecure IT systems
Subtitle of host publication28th Nordic Conference, NordSec 2023
EditorsLothar Fritsch, Ismail Hassan, Ebenezer Paintsil
PublisherSpringer Cham
Pages144-161
Number of pages18
ISBN (Electronic)9783031477485
ISBN (Print)9783031477478
DOIs
StatePublished - 8 Nov 2023
Event28th Nordic Conference, NordSec 2023 - Oslo
Duration: 16 Nov 202317 Nov 2023

Publication series

NameLecture Notes in Computer Science
Volume14324

Conference

Conference28th Nordic Conference, NordSec 2023
CityOslo
Period16/11/2317/11/23

Fingerprint

Dive into the research topics of 'RAMBO: Leaking Secrets from Air-Gap Computers by Spelling Covert Radio Signals from Computer RAM.'. Together they form a unique fingerprint.

Cite this