230
3 Hardware Trojans in Electronic Devices
As a result, the new touchscreen installed on the phone will help the intruder
provide phishing addresses to the user and trick the user into entering passwords into
fake login forms of social media and other resources. Tracking of user actions can
be performed in standard mode 24/7.
In order to send their own commands to the infected phone, the researches used
Arduino with ATmega328 module. They also used an STM32L432 microcontroller.
According to the authors of the research, other microcontrollers can also be easily
used. Of course, the test example of equipment turned out to be not so small; however,
it is possible to design the one that would fit into the case of any mobile phone. The
size can be very modest, so that the user wouldn’t even realize there is something
wrong with their phone.
Even though the developers experimented with an Android-based device, it
doesn’t mean that similar actions cannot be performed with iOS or any other mobile
operating system. The only way of protecting a mobile phone is through certification of device parts, even though it is extremely difficult to do. Implementation of
certification requires approval from multiple manufacturers of mobile devices from
different countries, designing certain standards and approval of these standards in
various countries. This is a very long process that also will not bring any financial benefits to its initiator. Therefore, it is unlikely that someone would decide to
implement something like this in the near future.
The worst part is that such attack method can already be used by organizations like
NSA; perhaps, we simply don’t know anything about it. Technicians in service centers
can be unaware of the fact that they are installing bugs embedded in components into
the phone. Proper miniaturization of equipment will prevent it from being noticed,
and such attacks can happen on a very large scale.
User devices are accessed by multiple repair services, the work of which is not
monitored by anyone. Therefore, the possibility of a hardware attack is fairly high;
moreover, it is virtually impossible to detect. According to certain data, the screens
of 20% of today’s smartphones ultimately break, and the user wants to replace the
screen as quickly and cheaply as possible.
However, not only component parts can be subjected to malicious attacks. Smartphones appeared quite a long time ago; it would be naive to think that no one has
found a way to watch and listen to the owners of such devices and their data. Since
then, many different ways have been presented to obtain information required by the
intruder.
For example, in 2014, scientists from Stanford developed the Gyrophone application [13], which can use gyroscope as a microphone. This application only works
with Android-based smartphones; iPhone gyroscopes fluctuate at a frequency of less
than 100 Hz.
Android devices, on the other hand, are equipped with gyroscopes, which are able
to perceive vibrations with a frequency of 80–250 Hz, that is, almost the entire range
of sound frequencies available to human ear. The most interesting part is that access
to gyroscope doesn’t require permission.
Moreover, tracking of devices (not only phones) can also be performed by means
of passive monitoring of wireless networks [14]. In this case, the system which
Précédent

- 250/839

Suivant