Authors explore security threat of covert acoustical mesh networks in air

December 3, 2013 by Nancy Owano weblog
Scenario for a multi-hop acoustical keylogger. Credit: Michael Hanspach and Michael Goetz

(Phys.org) —"If we want to exploit a rigorously hardened and tested type of computing system or networks of this type of computing system, we have to break new ground. Covert channels are communication channels utilizing means for communications that have not been designed for communication at all." So begins a bracing paper published last month in the Journal of Communications. Titled "On Covert Acoustical Mesh Networks in Air," the paper discusses devices that can support stealthy communication preventing immediate detection of the covert channels. The authors, Michael Hanspach and Michael Goetz, are research associates at the Fraunhofer Institute for Communication, Information Processing and Ergonomy (FKIE), in Wachtberg, Germany.

The authors warned that "Acoustical networking as a covert technology is a considerable threat to computer security and might even break the security goals of high assurance based on formally verified micro kernels that did not consider acoustical networking in their security concept."

Researchers in the past have described acoustic wave propagation used in underwater setups but the authors in their research did something different.

"The underlying network stack is based on a communication system that was originally designed for robust underwater communication. We adapt the communication system to implement covert and stealthy communications by utilizing the near ultrasonic frequency range. We further demonstrate how the scenario of covert acoustical communication over the air medium can be extended to multi-hop communications and even to wireless mesh networks."

The authors showed that establishing covert acoustical mesh networks in air is feasible in setups with commonly available business laptops. (The authors noted that a covert acoustical mesh network can be conceived as a botnet or malnet that is accessible via nearfield audio communications.) For their experimental setup, they used five laptops as the mesh network participants. They installed Debian 7.1 on each laptop.

Commenting on their work, Dan Goodin of Ars Technica said the new research shows that "high-frequency networking is easily within the grasp of today's malware." In an email, Hanspach said that commonly available laptops can communicate over their internal speakers and microphones, and form a covert acoustical . Over that network, "information can travel over multiple hops of infected nodes, connecting completely isolated computing systems and networks (e.g., the internet) to each other."

The authors, in their paper, also discussed countermeasures against covert acoustical mesh networks. These include the use of lowpass filtering in computing systems and a host-based intrusion detection system for analyzing audio input and output to detect irregularities.

Explore further: Research finds new channels to trigger mobile malware

More information: Research paper: On Covert Acoustical Mesh Networks in Air, www.jocm.us/index.php?a=show&catid=124&id=600

Related Stories

Research finds new channels to trigger mobile malware

May 16, 2013

(Phys.org) —Researchers at the University of Alabama at Birmingham (UAB) have uncovered new hard-to-detect methods that criminals may use to trigger mobile device malware that could eventually lead to targeted attacks launched ...

Toward harmonised aircraft communication

August 2, 2013

A key requirement for aircraft security is an efficient and modern communication network. The procedure carried out before each take-off requires input by multiple individuals at each stage. A fail in communication may lead ...

Reliable communication, unreliable networks

August 5, 2013

Now that the Internet's basic protocols are more than 30 years old, network scientists are increasingly turning their attention to ad hoc networks—communications networks set up, on the fly, by wireless devices—where ...

OpenFlow experimental facility to boost future ICT research

August 28, 2013

The explosion of high-tech devices such as laptops, tablets and smartphones into the market and the subsequent rise in demand for greater bandwidth has resulted in a drive towards sophisticated network communications systems. ...

Recommended for you

Microsoft describes hard-to-mimic authentication gesture

August 1, 2015

Photos. Messages. Bank account codes. And so much more—sit on a person's mobile device, and the question is, how to secure them without having to depend on lengthy password codes of letters and numbers. Vendors promoting ...

Power grid forecasting tool reduces costly errors

July 30, 2015

Accurately forecasting future electricity needs is tricky, with sudden weather changes and other variables impacting projections minute by minute. Errors can have grave repercussions, from blackouts to high market costs. ...

Netherlands bank customers can get vocal on payments

August 1, 2015

Are some people fed up with remembering and using passwords and PINs to make it though the day? Those who have had enough would prefer to do without them. For mobile tasks that involve banking, though, it is obvious that ...

1 comment

Adjust slider to filter visible comments by rank

Display comments: newest first

alfie_null
not rated yet Dec 04, 2013
Aside from using ultrasonic frequencies, it might also be possible to have transducers emit noise that sounds like something normal - cooling fans, or disk drive rumbles - and then impose some sort of modulation. I wouldn't rely on low pass filtering as a remediation.

Please sign in to add a comment. Registration is free, and takes less than a minute. Read more

Click here to reset your password.
Sign in to get notified via email when new comments are made.