TEMPEST and EMSEC: Can Electromagnetic Waves Be Used in Cyber Attacks?

TEMPEST and EMSEC: Can Electromagnetic Waves Be Used in Cyber Attacks?

Recently, Venezuela experienced a series of power outages, which left 11 states of the country without electricity. From the very beginning of this incident, Nicolás Maduro's government claimed that it was an act of sabotage, made possible by electromagnetic and cyber attacks on the national electric company Corpoelec and its power plants. In contrast, the self-proclaimed government of Juan Guaidó simply attributed this incident to the “inefficiency [and] failure of the regime».

. Without an impartial and thorough analysis of the situation, it is very difficult to determine whether these outages were a result of sabotage or due to a lack of maintenance. Nevertheless, the allegations of supposed sabotage raise a number of intriguing questions regarding information security. Many control systems at critical infrastructure facilities, such as power plants, are closed systems and therefore do not have external Internet connections. Thus, the question arises: could cybercriminals access closed IT systems without direct connections to their computers? The answer is yes. In such cases, electromagnetic waves could serve as a vector for the attack.

How to 'capture' electromagnetic emissions


All electronic devices emit radiation in the form of electromagnetic and acoustic signals. Depending on various factors, such as distance and the presence of obstacles, listening devices can 'capture' signals from these devices using special antennas or highly sensitive microphones (in the case of acoustic signals) and process them to extract useful information. Such devices include monitors and keyboards, and as such, they can also be used by cybercriminals.

Speaking of monitors, back in 1985, researcher Wim van Eck published the first unclassified document about the security risks posed by emissions from such devices. As you may remember, monitors used to rely on cathode ray tubes (CRT). His study demonstrated that radiation from the monitor could be 'read' from a distance and used to reconstruct images displayed on the monitor. This phenomenon is known as Van Eck phreaking, and it in fact represents one of the reasons, why several countries, including Brazil and Canada, find electronic voting systems too insecure for use in electoral processes.

TEMPEST and EMSEC: Can Electromagnetic Waves Be Used in Cyber Attacks?
Equipment used to access another laptop located in the next room. Source: Tel Aviv University

Although nowadays LCD monitors generate significantly less radiation than CRT monitors, nonetheless, a recent study showed that they are also vulnerable. Moreover, experts from Tel Aviv University (Israel) vividly demonstrated this. They managed to access encrypted content on a laptop located in the next room using relatively simple equipment costing about $3,000, which consisted of an antenna, an amplifier, and a laptop with specialized software for signal processing.

On the other hand, the keyboards themselves may also be sensitive to the interception of their emissions. This means there is a potential risk of cyber-attacks, where attackers can recover login credentials and passwords by analyzing which keys on the keyboard were pressed.

TEMPEST and EMSEC


The use of emissions to extract information was first employed during World War I and was related to telephone wires. These techniques were widely utilized throughout the Cold War with more sophisticated devices. For instance, a declassified NASA document from 1973 explains how in 1962 a U.S. embassy security officer in Japan discovered that a dipole placed in a nearby hospital was directed at the embassy building to intercept its signals.

However, the concept of TEMPEST as such began to emerge in the 1970s with the first security directives on emissions that emerged in the USA . This code name refers to research on unintentional (side) emissions from electronic devices that may contribute to the leakage of classified information. The TEMPEST standard was established by the National Security Agency (NSA) of the USA and led to the development of security standards that were also adopted by NATO.

This term is often used interchangeably with the term EMSEC (emission security), which is part of the standards COMSEC (communications security).

TEMPEST protection


TEMPEST and EMSEC: Can Electromagnetic Waves Be Used in Cyber Attacks?
Red/Black cryptographic architecture scheme for communication devices. Source: David Kleidermacher

Firstly, TEMPEST protection applies to a fundamental concept in cryptography known as Red/Black architecture. This concept separates systems into 'Red' equipment, which is used to process classified information, and 'Black' equipment, which transmits data without a classification label. One of the purposes of TEMPEST protection is this separation, which keeps all components apart by isolating 'Red' equipment from 'Black' using special filters.

Secondly, it is important to keep in mind that all devices emit a certain level of radiation. This means that the maximum possible level of protection would be total coverage of the entire space, including computers, systems, and components. However, this would be extremely costly and impractical for most organizations. For this reason, more targeted techniques are used:

Zoning assessment: is used to assess the level of TEMPEST security for spaces, installations, and computers. After conducting this assessment, resources can be directed to those components and computers that contain the most sensitive information or unencrypted data. Various official bodies regulating communication security, such as the NSA in the USA or CCN in Spain, certify such techniques.

Shielded areas: zoning assessment may show that certain areas housing computers do not fully meet all security requirements. In such cases, one option is to completely shield the area or use shielded cabinets for these computers. These cabinets are made from special materials that prevent the spread of emissions.

Computers with their own TEMPEST certifications: sometimes a computer may be in a secure location but lack an adequate level of security. To enhance the existing level of security, there are computers and communication systems that have their own TEMPEST certification, which verifies the security of their hardware and other components.

TEMPEST shows that, even if corporate systems have virtually secure physical environments or are not even connected to external communications, there are still no guarantees that they are completely safe. In any case, most vulnerabilities in critical infrastructures are likely related to common attacks (e.g., ransomware), as we recently reported. In these cases, it is relatively easy to avoid such attacks with appropriate measures and advanced cybersecurity solutions with advanced protection options. The combination of all these protective measures is the only way to ensure the security of systems critical to the future of the company or even the entire country.

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster