I-TEMPEST kunye ne-EMSEC: ngaba amaza ombane wombane angasetyenziswa kuhlaselo lwe-cyber?

I-TEMPEST kunye ne-EMSEC: ngaba amaza ombane wombane angasetyenziswa kuhlaselo lwe-cyber?

kutshanje eVenezuela uthotho lokumka kombane, nto leyo eyashiya amazwe ali-11 eli lizwe engenambane. Kwasekuqaleni kwesi siganeko, urhulumente kaNicolás Maduro wathi kunjalo isenzo sokonakalisa, eyenzeka ngenxa yokuhlaselwa kwe-electromagnetic kunye ne-cyber kwinkampani yelizwe yombane iCorpoelec kunye nezityalo zayo zamandla. Ngokuchaseneyo noko, urhulumente ozibiza ngokuba nguJuan Guaidó uvele wasibhala esi siganeko ngokuthi "ukungasebenzi [kunye] nokusilela kolawulo».

Ngaphandle kohlalutyo olungenamkhethe kunye nolunzulu lwemeko, kunzima kakhulu ukufumanisa ukuba oku kucinywa kube ngumphumo wokutshatyalaliswa okanye ukuba kubangelwa ukungabikho kokugcinwa. Nangona kunjalo, izityholo zokutyholwa ngokutshabalalisa ziphakamisa inani lemibuzo enomdla enxulumene nokhuseleko lolwazi. Iinkqubo ezininzi zokulawula kwiziseko ezingundoqo ezibalulekileyo, ezifana nezityalo zamandla, zivaliwe kwaye ngoko ke azikho uxhulumaniso lwangaphandle kwi-Intanethi. Ngoko umbuzo uvela: ngaba abahlaseli be-cyber banokufikelela kwiinkqubo ezivaliweyo ze-IT ngaphandle kokudibanisa ngokuthe ngqo kwiikhomputha zabo? Impendulo nguewe. Kule meko, amaza e-electromagnetic anokuba yi-vector yokuhlasela.

Indlela "yokubamba" imitha ye-electromagnetic


Zonke izixhobo zombane zivelisa i-radiation ngendlela ye-electromagnetic kunye ne-acoustic signals. Ngokuxhomekeke kwinani lezinto, ezinjengomgama kunye nobukho bemiqobo, izixhobo zokuphulaphula zinokuthi "zibambe" iimpawu ezivela kwezi zixhobo zisebenzisa i-eriyali ezikhethekileyo okanye ii-microphone ezinovakalelo kakhulu (kwimeko yemiqondiso ye-acoustic) kwaye ziqhubekise ukukhupha ulwazi oluluncedo. Ezo zixhobo ziquka iimonitha kunye nee-keyboards, kwaye ngenxa yoko zinokusetyenziswa ngabaphuli-mthetho be-cyber.

Ukuba sithetha ngabahloli, emva phayaa ngowe-1985 umphandi uWim van Eyck wapapasha uxwebhu lokuqala olungahlelwanga malunga nemingcipheko yokhuseleko eyenziwa yimitha evela kwizixhobo ezinjalo. Njengoko ukhumbula, ngelo xesha abahloli babesebenzisa iityhubhu ze-cathode ray (CRTs). Uphando lwakhe lubonise ukuba i-radiation evela kwimonitha "inokufundwa" kude kwaye isetyenziselwa ukwakha kwakhona imifanekiso eboniswe kwimonitha. Esi siganeko saziwa ngokuba yivan Eyck interception, kwaye enyanisweni kunjalo esinye sezizathu, kutheni amazwe amaninzi, kuquka iBrazil neKhanada, ecinga ukuba iinkqubo zokuvota ze-elektroniki azikhuselekanga ukuba zingasetyenziswa kwiinkqubo zonyulo.

I-TEMPEST kunye ne-EMSEC: ngaba amaza ombane wombane angasetyenziswa kuhlaselo lwe-cyber?
Isixhobo esisetyenziselwa ukufikelela kwenye ilaptop ekwigumbi elilandelayo. Umthombo: IYunivesithi yaseTel Aviv

Nangona iimonitha ze-LCD kule mihla zivelisa imitha ephantsi kakhulu kuneemonitha zeCRT, uphononongo lwakutsha nje babonise ukuba nabo basesichengeni. Ngaphezu koko, Iingcali zeYunivesithi yaseTel Aviv (kwaSirayeli) zibonise ngokucacileyo oku. Baye bakwazi ukufikelela kumxholo ofihliweyo kwilaptop ebekwe kwigumbi elilandelayo besebenzisa izixhobo ezilula ezixabisa malunga ne-US$3000, equka i-eriyali, iamplifier kunye nelaptop enesoftware ekhethekileyo yokwenziwa kwemiqondiso.

Kwelinye icala, ii-keyboards ngokwazo zinokuba njalo onovakalelo ukuthintela imitha yabo. Oku kuthetha ukuba kukho umngcipheko wohlaselo lwe-cyber apho abahlaseli banokuphinda bafumane iziqinisekiso zokungena kunye namagama ayimfihlo ngokuhlalutya ukuba zeziphi izitshixo ezicinezelwe kwikhibhodi.

I-TEMPEST kunye ne-EMSEC


Ukusetyenziswa kwemitha yokukhupha ulwazi kwakunesicelo sayo sokuqala ngexesha leMfazwe yokuQala yeHlabathi, kwaye yayinxulunyaniswa neengcingo zomnxeba. Obu buchule basetyenziswa kakhulu kuyo yonke iMfazwe Yomlomo ngezixhobo eziphambili. Umzekelo, uxwebhu lwe-NASA lwachithwa ngo-1973 ichaza indlela, kwi-1962, igosa lezokhuseleko kwi-Embassy yase-US eJapan yafumanisa ukuba i-dipole ebekwe kwisibhedlele esiseduze yayijoliswe kwisakhiwo se-ambassy ukuba ibambe iimpawu zayo.

Kodwa ingqikelelo ye-TEMPEST injalo iqala ukubonakala sele ikwi-70s neyokuqala imiyalelo yokhuseleko ngemitha evele e-USA . Eli gama lekhowudi libhekisa kuphando kwizinto ezikhutshwayo ezingenziwanga ngabom ezivela kwizixhobo zombane ezinokuvuza ulwazi olucaluliweyo. Umgangatho weTEMPEST wenziwa I-Arhente yeSizwe yoKhuseleko yase-US (NSA) kwaye kwakhokelela ekuveleni kwemigangatho yokhuseleko nayo yamkelwe kwi-NATO.

Eli gama lihlala lisetyenziswa ngokutshintshana kunye negama elithi EMSEC (ukhuseleko lokukhupha), oluyinxalenye yemigangatho I-COMSEC (ukhuseleko lonxibelelwano).

UKHUSELEKO LOKUFUMANA


I-TEMPEST kunye ne-EMSEC: ngaba amaza ombane wombane angasetyenziswa kuhlaselo lwe-cyber?
I-Red/Black cryptographic architecture diagram yesixhobo sonxibelelwano. Umthombo: UDavid Kleidermacher

Okokuqala, ukhuseleko lwe-TEMPEST lusebenza kwi-cryptographic concept esisiseko eyaziwa ngokuba yi-Red/Black architecture. Le ngcamango yahlula iisistim kwizixhobo "eziBomvu", ezisetyenziselwa ukucubungula ulwazi oluyimfihlo, kunye nezixhobo "eziMnyama", ezihambisa idatha ngaphandle kokuhlelwa kokhuseleko. Enye yeenjongo zokukhuselwa kwe-TEMPEST yile yahlula, eyahlula onke amacandelo, ukwahlula izixhobo "ezibomvu" ezivela "ezimnyama" ezineefilitha ezikhethekileyo.

Okwesibini, kubalulekile ukugcina engqondweni ukuba zonke izixhobo zikhupha inqanaba elithile lemitha. Oku kuthetha ukuba umgangatho ophezulu wokukhusela uya kukhuselwa ngokupheleleyo kwendawo yonke, kuquka iikhomputha, iinkqubo kunye namacandelo. Nangona kunjalo, oku kuya kubiza kakhulu kwaye kungenzeki kwimibutho emininzi. Ngenxa yesi sizathu, iindlela ezijoliswe ngakumbi zisetyenziswa:

Uvavanyo loCando: Isetyenziselwa ukujonga umgangatho wokhuseleko weTEMPEST wezithuba, ufakelo, kunye neekhompyutha. Emva kolu vavanyo, izibonelelo zinokubhekiswa kuloo macandelo kunye neekhompyuter eziqulathe olona lwazi lunovakalelo okanye idatha engafihlwayo. Amaqumrhu asemthethweni ahlukeneyo alawula ukhuseleko lonxibelelwano, afana ne-NSA e-USA okanye CCN eSpain, qinisekisa ubuchule obunjalo.

Iindawo ezikhuselekileyo: Uvavanyo lwezowuni lungabonisa ukuba izithuba ezithile ezineekhompyutha azifikeleli ngokupheleleyo zonke iimfuno zokhuseleko. Kwiimeko ezinjalo, enye inketho kukukhusela ngokupheleleyo indawo okanye ukusebenzisa iikhabhinethi ezikhuselekileyo kwiikhomputha ezinjalo. Ezi khabhinethi zenziwe ngezinto ezikhethekileyo ezithintela ukusasazeka kwemitha.

Iikhompyutha ezinezatifikethi zazo ze-TEMPEST: Maxa wambi ikhompyutha isenokuba kwindawo ekhuselekileyo kodwa ingabi nakhuseleko lwaneleyo. Ukuphucula umgangatho okhoyo wokhuseleko, kukho iikhomputha kunye neenkqubo zonxibelelwano ezinesatifikethi se-TEMPEST yazo, eziqinisekisa ukhuseleko lwe-hardware yazo kunye namanye amacandelo.

I-TEMPEST ibonisa ukuba nokuba iinkqubo zeshishini zineendawo ezibonakalayo ezikhuselekileyo okanye aziqhagamshelwanga kunxibelelwano lwangaphandle, akukabikho siqinisekiso sokuba zikhuselekile ngokupheleleyo. Ngayo nayiphi na imeko, ubuthathaka obuninzi kwiziseko ezingundoqo ezibalulekileyo budla ngokunxulumana nohlaselo oluqhelekileyo (umzekelo, iransomware), yile nto siyenzayo. kutshanje. Kwezi meko, kulula kakhulu ukunqanda uhlaselo olunjalo usebenzisa amanyathelo afanelekileyo kunye nezisombululo zokhuseleko lolwazi oluphambili kunye neendlela zokukhusela eziphezulu. Ukudibanisa onke la manyathelo okukhusela kuphela kwendlela yokuqinisekisa ukhuseleko lweenkqubo ezibalulekileyo kwikamva lenkampani okanye ilizwe lonke.

umthombo: www.habr.com

Yongeza izimvo