1.5 Technical Channels of Information Leakage
55
Fig. 1.24 Structure of a technical channel of information leakage created by hardware Trojans
introduced in CE
primarily for intercepting user passwords and text documents that are printed using
a PC. The intercepted information can either be transmitted over the air or recorded
on a flash drive.
Hidden Trojan keylogger transmitting information over the air consists of an
interception module, transmitting or storage units, and a control unit. The keylogger
is powered from the keyboard interface.
The interception module intercepts signals transmitted from the keyboard to the
system unit as soon as a key is pressed. Intercepted signals in digital form are aired
to the receiving point, where they are restored in real time and displayed on the
computer screen in the form of characters typed on the keyboard.
The remote control unit is designed to receive signals of remote switching of the
embedded device and setting the parameters of the transmitting device.
The reception complex consists of a radio receiver, a special modem module
(modem), a laptop, and a special software.
As a rule, UHF is used to transmit information. For instance, KS-1 hardware
keylogger [1] operates at a frequency of 434,0005 MHz, and BE24 T keylogger
operates in the frequency range from 300 to 306 MHz [28]. Fast frequency shift
keying (FFSK) is used to transmit information. Transmitter power can range from
1–20 mW to 50–100 mW, which ensures the transmission of information at a distance
of 50 to 500 m or more.
Hardware keyloggers are small and weigh a few grams. For instance, BE24 T
keylogger has the dimensions of 48 × 16 × 4 mm [29].
Figure 1.25 is an image of a hardware keylogger transmitting the intercepted
information via a radio channel and a special receiver; Fig. 1.26—its application
diagram [29].
Some hardware keyloggers use a Bluetooth channel to transmit information. One
of them is represented in Fig. 1.27 [30].
Précédent

- 77/839

Suivant