1.5 Technical Channels of Information Leakage
59
The embedded device is powered from the 220 V mains via the power supply.
The reception complex consists of a radio receiver, a modem, a laptop, and a
special software.
Thus, the information processed by computer technology is intercepted as follows:
• Interception of stray electromagnetic radiation resulting from CE operation;
• Interception of pickup of informative signals from the AES connecting lines and
external conductors;
• Interception of pickup of informative signals from CE power and ground lines;
• CE “high-frequency irradiation,” introduction of embedded devices in CE.
1.5.4 Methods for Sensitive Information Retrieval Based
on the Analysis of Acoustic and Electromagnetic
Radiation
Catching electromagnetic radiation of a keyboard at a distance is very problematic
(although theoretically possible). However, catching acoustic noise is much easier.
Sometimes even during a phone conversation one can clearly hear how the interlocutor enters information from the keyboard. Studies of specialists in the field of
information security show that each key, when pressed, produces a specific sound that
makes it possible to identify the exact keys pressed. The most famous work in this
direction was carried out by scientists at the University of California at Berkeley
(for more details, see http://zdnet.ru/?ID=498415), who came to the conclusion
that 60–96% of the entered characters can be recognized on a conventional sound
recording.
No specialized software is required to identify the number of characters typed in
the password or the presence of duplicate characters.
Method of counteraction: the main means of protection against information
leakage by analyzing acoustic signals is a constant and systematic personnel training.
There is one universal and reliable method of bypassing hardware keylogger—the
use of on-screen keyboard and other ways to enter information without a keyboard.
It should be noted that the majority of modern anti-keyloggers contain their own
built-in on-screen keyboard for this very purpose.
The search for hardware keyloggers should certainly be part of the duties of all
information security personnel. At the same time, one should bear in mind that the
probability of installing a hardware keylogger is directly proportional to the value
of the information entered at the workplace.
59
The embedded device is powered from the 220 V mains via the power supply.
The reception complex consists of a radio receiver, a modem, a laptop, and a
special software.
Thus, the information processed by computer technology is intercepted as follows:
• Interception of stray electromagnetic radiation resulting from CE operation;
• Interception of pickup of informative signals from the AES connecting lines and
external conductors;
• Interception of pickup of informative signals from CE power and ground lines;
• CE “high-frequency irradiation,” introduction of embedded devices in CE.
1.5.4 Methods for Sensitive Information Retrieval Based
on the Analysis of Acoustic and Electromagnetic
Radiation
Catching electromagnetic radiation of a keyboard at a distance is very problematic
(although theoretically possible). However, catching acoustic noise is much easier.
Sometimes even during a phone conversation one can clearly hear how the interlocutor enters information from the keyboard. Studies of specialists in the field of
information security show that each key, when pressed, produces a specific sound that
makes it possible to identify the exact keys pressed. The most famous work in this
direction was carried out by scientists at the University of California at Berkeley
(for more details, see http://zdnet.ru/?ID=498415), who came to the conclusion
that 60–96% of the entered characters can be recognized on a conventional sound
recording.
No specialized software is required to identify the number of characters typed in
the password or the presence of duplicate characters.
Method of counteraction: the main means of protection against information
leakage by analyzing acoustic signals is a constant and systematic personnel training.
There is one universal and reliable method of bypassing hardware keylogger—the
use of on-screen keyboard and other ways to enter information without a keyboard.
It should be noted that the majority of modern anti-keyloggers contain their own
built-in on-screen keyboard for this very purpose.
The search for hardware keyloggers should certainly be part of the duties of all
information security personnel. At the same time, one should bear in mind that the
probability of installing a hardware keylogger is directly proportional to the value
of the information entered at the workplace.
