We show that as a side effect of building code requirements, almost all commercial buildings today are vulnerable to a novel data exfiltration attack, even if they are air-gapped and secured against traditional attacks. The new attack uses vibrations from an inconspicuous transmitter to send data across the building's physical infrastructure to a receiver. Our analysis and experiments with several large real-world buildings show a single-frequency bit rate of 300Kbps, which is sufficient to transmit ordinary files, real-time MP3-quality audio, or periodic high-quality still photos. The attacker can use multiple channels to transmit, for example, real-time MP4-quality video. We discuss the difficulty of detecting the attack and the viability of various potential countermeasures.
翻译:我们显示,作为建筑法规要求的副作用,今天几乎所有商业建筑都容易受到新颖的数据过滤攻击,即使它们被空气封住,并能够抵御传统攻击。新的攻击使用一个不显眼的发射机的振动,将数据通过大楼的有形基础设施传送给接收器。我们对几个大型实际世界建筑的分析和实验显示,单频位位位数为300Kbps,这足以传输普通文件、实时MP3质量的音频或定期的高质量静止照片。攻击者可以使用多种渠道传输,例如实时MP4质量的视频。我们讨论了探测攻击的困难和各种潜在反措施的可行性。