5.1 Brief Review of Basic Techniques for Detection …
455
A trigger activates a charge under certain conditions, for example, in case of a
rare event (occurrence of a set of bits 0 × 3745 in the data line), after a certain time
interval (for example, 10,000 s) or at a certain state of the environment (for example,
if the temperature is 65 °C). The most important requirement for the trigger start-up
condition is that it is not detected (failed) during functional tests, which are the most
important elements of the microcircuit production process. Otherwise, the trigger
can activate the Trojan during final testing, making it easy to detect.
The useful load mechanism performs the actual target function of the Trojan.
Such a function, for example, may consist in a complete shutdown of the hardware
system, interception of sensitive data (for example, a cryptographic key), or remote
control of the hardware system (which corresponds to the creation of a workaround
in the operation of the hardware).
As will be clear from the following overview, this problem is extremely
multifaceted and illustrates a wide range of possible attack vectors.
The expert studies considered multiple threats in relation to basic components of
a modern infrastructure. For example, Jean and Macris claim that there is a potential
for the leakage of a cryptographic key of a wireless device via a wireless channel
[23]. Depending on each key bit, the wireless signal varies within tolerance levels.
In this case, it is enough for an intruder to be within the range of the wireless device,
record the signal, and perform statistical analysis to obtain the key. Subsequently, the
intruder will be able to use this key for authorization and use the device as a regular
user, which will allow him to undermine the operation of the entire system to which
the device belongs.
Lin et al. also demonstrate the possibility of data leakage via a specifically created
secret channel [32]. It has been shown that by modulating the signal from the device
power supply, an imperceptible leakage of any data can be organized. In this case,
it is extremely difficult to detect this hidden data transmission, since the transmitted
signal is modulated by means of digital transmission with code division, i.e., using the
so-called distributed spectrum technology. Therefore, without knowing the correct
code, such hidden signal is nearly impossible to detect, since it is indistinguishable from noise (interference). In order to obtain confidential data (for example, a
cryptographic key), the intruder has to de-energize the device being attacked and
demodulate it by combining it with the necessary code.
King et al. experimentally proved it by developing their own malicious processor
with implemented special software allowing the intruder to perform mass attacks
at the software level [27]. The Illinois malicious processor describes, known to the
specialists, the mechanisms that allow illegally logging into the operating system
as an administrative user even without using a password. That way, the attacker can
gain broad access to any infrastructure component. The introduction of such infected
processor, for example, into a router, will lead to the modification of the infrastructure
itself, which will later serve as the basis for attacks at the network level.
Below we present a brief history of evolution of Trojans as well as measures to
counter them. This chapter describes the developments known since 2005, when
the US Ministry of Defense published the first report on supplies of counterfeit
semiconductors [19] and until the moment of publication of this book.
455
A trigger activates a charge under certain conditions, for example, in case of a
rare event (occurrence of a set of bits 0 × 3745 in the data line), after a certain time
interval (for example, 10,000 s) or at a certain state of the environment (for example,
if the temperature is 65 °C). The most important requirement for the trigger start-up
condition is that it is not detected (failed) during functional tests, which are the most
important elements of the microcircuit production process. Otherwise, the trigger
can activate the Trojan during final testing, making it easy to detect.
The useful load mechanism performs the actual target function of the Trojan.
Such a function, for example, may consist in a complete shutdown of the hardware
system, interception of sensitive data (for example, a cryptographic key), or remote
control of the hardware system (which corresponds to the creation of a workaround
in the operation of the hardware).
As will be clear from the following overview, this problem is extremely
multifaceted and illustrates a wide range of possible attack vectors.
The expert studies considered multiple threats in relation to basic components of
a modern infrastructure. For example, Jean and Macris claim that there is a potential
for the leakage of a cryptographic key of a wireless device via a wireless channel
[23]. Depending on each key bit, the wireless signal varies within tolerance levels.
In this case, it is enough for an intruder to be within the range of the wireless device,
record the signal, and perform statistical analysis to obtain the key. Subsequently, the
intruder will be able to use this key for authorization and use the device as a regular
user, which will allow him to undermine the operation of the entire system to which
the device belongs.
Lin et al. also demonstrate the possibility of data leakage via a specifically created
secret channel [32]. It has been shown that by modulating the signal from the device
power supply, an imperceptible leakage of any data can be organized. In this case,
it is extremely difficult to detect this hidden data transmission, since the transmitted
signal is modulated by means of digital transmission with code division, i.e., using the
so-called distributed spectrum technology. Therefore, without knowing the correct
code, such hidden signal is nearly impossible to detect, since it is indistinguishable from noise (interference). In order to obtain confidential data (for example, a
cryptographic key), the intruder has to de-energize the device being attacked and
demodulate it by combining it with the necessary code.
King et al. experimentally proved it by developing their own malicious processor
with implemented special software allowing the intruder to perform mass attacks
at the software level [27]. The Illinois malicious processor describes, known to the
specialists, the mechanisms that allow illegally logging into the operating system
as an administrative user even without using a password. That way, the attacker can
gain broad access to any infrastructure component. The introduction of such infected
processor, for example, into a router, will lead to the modification of the infrastructure
itself, which will later serve as the basis for attacks at the network level.
Below we present a brief history of evolution of Trojans as well as measures to
counter them. This chapter describes the developments known since 2005, when
the US Ministry of Defense published the first report on supplies of counterfeit
semiconductors [19] and until the moment of publication of this book.
