266
3 Hardware Trojans in Electronic Devices
emits unmasking radiation that can be used to acquire confidential information.
Many years passed since then; with development of technologies, both TEMPEST
intelligence methods and TEMPEST protection were improved.
In late 1980s–early 1990s, a quality leap occurred in the sphere of TEMPEST technologies. First of all, it was associated with wide introduction of cryptography, development of electronic data storage technologies, and emergence of reliable encryption
algorithms that often don’t even leave the intruder a chance to decode the intercepted
data. TEMPEST is the only reliable method of data acquisition, since it helps perform
interception even before the information is encrypted.
As early as in 1985, at the exhibition Securecom-85, equipment for interception of
monitor radiation was demonstrated. Experiments demonstrated that such interception is possible even with the help of a slightly modified regular TV set. Even though
it was a huge step in the sphere of data interception for that time, this method was not
deprived of flaws. In order to obtain the desired result, it was necessary to wait for
the user to display the required information on the screen; this process can take a lot
of time. Today, this task is solved quite easily: the target computer is infected with
an implant through any of the known means, e.g., via a CD with a game or drivers
or via the network.
This program finds the information required by the intruder on the hard drive
and causes generation of spurious radio emissions by addressing computer devices.
For example, it can organize a communication channel through the composite signal
of the monitor; in this case, the user, while playing his or her favorite game, will
be completely unaware that confidential information ready to be transmitted is
embedded in character images. These interception methods are known among hackers
as computer steganography; they are constantly refined and widely used in practice
by special services of different countries.
The feature of this information stealing method lies in that the detection of the very
fact of unauthorized transmission is difficult. While there are various hardware and
software means to protect the data transmitted via the Internet or a local network,
no user tools are available for detection of a TEMPEST transmission (as far as
we know, at least); it is nearly impossible to identify radiation in the broadband
spectrum without knowledge of parameters of the useful signal. The viral program
doesn’t manifest itself in the operating system; it doesn’t establish a connection
with the Internet, doesn’t affect operation of programs, and doesn’t damage data or
affect operation of the compute. Modern antiviruses are almost useless against such
programs; such viruses can remain in the system for years without being detected.
Monitor is not the only computer device capable of transmitting information
through the TEMPEST channel. For example, system unit LEDs also can serve as
such transmitter: they have low inertia and allow modulating a signal at a frequency
of up to hundreds of megahertz. This feature can be used for data transmission,
especially considering the fact that high frequency oscillations are invisible to a
human eye and can only be detected using special equipment.
One of the main tasks of any intruder is to obtain access to password-protected
information. Of course, the monitor cannot just give out the password, as such information is always covered with asterisks or dots on the screen; keyboard, on the other
3 Hardware Trojans in Electronic Devices
emits unmasking radiation that can be used to acquire confidential information.
Many years passed since then; with development of technologies, both TEMPEST
intelligence methods and TEMPEST protection were improved.
In late 1980s–early 1990s, a quality leap occurred in the sphere of TEMPEST technologies. First of all, it was associated with wide introduction of cryptography, development of electronic data storage technologies, and emergence of reliable encryption
algorithms that often don’t even leave the intruder a chance to decode the intercepted
data. TEMPEST is the only reliable method of data acquisition, since it helps perform
interception even before the information is encrypted.
As early as in 1985, at the exhibition Securecom-85, equipment for interception of
monitor radiation was demonstrated. Experiments demonstrated that such interception is possible even with the help of a slightly modified regular TV set. Even though
it was a huge step in the sphere of data interception for that time, this method was not
deprived of flaws. In order to obtain the desired result, it was necessary to wait for
the user to display the required information on the screen; this process can take a lot
of time. Today, this task is solved quite easily: the target computer is infected with
an implant through any of the known means, e.g., via a CD with a game or drivers
or via the network.
This program finds the information required by the intruder on the hard drive
and causes generation of spurious radio emissions by addressing computer devices.
For example, it can organize a communication channel through the composite signal
of the monitor; in this case, the user, while playing his or her favorite game, will
be completely unaware that confidential information ready to be transmitted is
embedded in character images. These interception methods are known among hackers
as computer steganography; they are constantly refined and widely used in practice
by special services of different countries.
The feature of this information stealing method lies in that the detection of the very
fact of unauthorized transmission is difficult. While there are various hardware and
software means to protect the data transmitted via the Internet or a local network,
no user tools are available for detection of a TEMPEST transmission (as far as
we know, at least); it is nearly impossible to identify radiation in the broadband
spectrum without knowledge of parameters of the useful signal. The viral program
doesn’t manifest itself in the operating system; it doesn’t establish a connection
with the Internet, doesn’t affect operation of programs, and doesn’t damage data or
affect operation of the compute. Modern antiviruses are almost useless against such
programs; such viruses can remain in the system for years without being detected.
Monitor is not the only computer device capable of transmitting information
through the TEMPEST channel. For example, system unit LEDs also can serve as
such transmitter: they have low inertia and allow modulating a signal at a frequency
of up to hundreds of megahertz. This feature can be used for data transmission,
especially considering the fact that high frequency oscillations are invisible to a
human eye and can only be detected using special equipment.
One of the main tasks of any intruder is to obtain access to password-protected
information. Of course, the monitor cannot just give out the password, as such information is always covered with asterisks or dots on the screen; keyboard, on the other
