Ordinary HDMI cable and window antenna. To steal data from computers without the Internet learned scientists

Even a fully insulated computer can transmit data outward through a regular video cable. Specialists from Shandong University and the Quan Cheng laboratory described the TrojPix method, in which malware imperceptibly changes individual pixels on the screen and causes an HDMI cable to emit controlled electromagnetic signals. For the user, the image remains normal, but outside the room the signal can be received by the antenna and restore the transmitted data.

The work is devoted to attacks on isolated networks that are used in military centers, government agencies, financial organizations and critical infrastructure management systems. Such networks are physically separated from the Internet, prohibit wireless connections and limit external media, but even complete isolation does not eliminate side channels of leakage. TrojPix shows that such a channel may not be a memory, processor or drive, but a digital cable connecting a computer to a monitor.

The essence of the method is that the video signal is transmitted through the cable at a very high speed, and currents in the conductors inevitably create electromagnetic radiation. The authors showed that pixel data affect the nature of such radiation. If you slightly change the brightness or individual color components of pixels, the screen almost does not change for the human eye, but the external receiver fixes that the electromagnetic signal changes markedly.

In the preliminary experience, experts changed only the junior bit of the blue channel in the selected area of the image. Visually, the picture was almost no different from the original, but the oscilloscope recorded how the electromagnetic radiation changed. The authors then showed that through such oscillations it is possible to transmit binary data, distinguishing “0” and “1” in terms of signal intensity at the main frequency of 148.5 MHz and the second harmonica 297 MHz.


To attack the malware does not need administrator rights, access to equipment or the need to change the cable. According to the model of the authors, the malware works in user mode, finds confidential files, determines the screen resolution, forms a disguised image and begins to secretly transmit data. The attacker uses the usual radio receiving equipment and antenna outside the room or at a distance from the target.

TrojPix supports two modes. In the first, the malware shows a black screen or a picture similar to a turned off monitor. The user thinks the display is asleep, but the cable continues to transmit data. Once the user moves the mouse, the transmission immediately stops, and the screen returns to normal. In the second mode, the data is embedded in the current image: the program barely noticeably changes color and pixels while the person continues to work at the computer.

Tests have shown that the method is not tied to a single device. TrojPix was checked on Dell, AOC, Redmi, Philips, Lenovo, Samsung, LG, Huawei and TCL monitors, as well as on fifteen regular digital video cables of different manufacturers and length. On cables, it was possible to correctly restore an average of 99.20% bits, and after the correction of errors, the data was restored completely. On monitors, the average figure reached 99.13%, also with a full recovery after correction.

The resolution of the screen almost did not affect the result. The authors checked the modes from 800 × 600 to 1920×1080 at a frequency of 60 Hz, and the difference in accuracy was minimal. At a distance of 20 meters, TrojPix gave 99.19% of the correct bits, and at 120 meters the figure decreased to 91.02%. In the open space, specialists managed to accept a full data packet at a distance of 208 meters.

In a separate test, a signal passed through a concrete wall with a thickness of 30 cm was checked. The antenna was 10 meters from the target computer, and the average accuracy decreased from 99.96% to 99.14%. The authors conclude that the wall worsens the signal, but does not destroy the hidden channel.

The speed at which the data was transmitted depended on the frequency they were taken. At 5 MHz, the maximum speed was 1.8 Mbit / s, at 10 MHz - 3.8 Mbps, at 15 MHz - 5.9 Mbps, and at 20 MHz reached 8.1 Mbps. For a hidden channel through the side of the video cable, this is a very high indicator, especially given the range and imperceptibility of the image.

How impenetrable the method was tested on 50 volunteers. Participants were shown the image before and after TrojPix, and no one reported visible differences. When they transmitted files measuring 10 KB, 100 KB, 1 MB and 10 MB, the accuracy with which the characters could be restored reached 100%, and the file was 10 MB was transmitted in 41.6 seconds.

To protect against such an attack, measures are needed on a physical level. If the cable is additionally shielded, it worsens the operation of TrojPix, but does not block the channel completely: even with protective materials, the success remained above 91%. The authors offer to shield the cable, create interference in the desired range, change the procedure for transmitting the video signal randomly and smooth the changes in pixels. A more reliable option, experts call video connections without such electromagnetic leaks, including fiber-optic interfaces.
 
Top Bottom