Israeli team uses heat to beat computer security
Researchers demonstrate method of breaking into secure systems that doesn’t require any physical connection
Stuart Winer is a breaking news editor at The Times of Israel.
Israeli researchers have demonstrated a method that can be used to breach high-security computer systems without gaining physical or electronic access and instead using heat as a means of communication.
The Cyber Security Labs at Beersheba’s Ben-Gurion University of the Negev featured the concept, dubbed Bitwhispher, in a video published Monday on its website by researcher Mordechai Guri, who worked on the project under the guidance of Professor Yuval Elovici.
“BitWhisper is a demonstration for a covert bi-directional communication channel between two close by air-gapped computers communicating via heat,” the researchers wrote.
In the short clip, two computers can be seen communicating with each other by fluctuating their temperatures, allowing one machine to instruct the other to alter the position of a connected toy missile-launcher.
The technology could be used against secure air-gapped systems — computers that are not connected to the internet either directly or even via other machines in order to secure their data. High-security systems that need to protect sensitive data, such as classified military computers or credit card systems, use the air-gap method as a way of isolating the machines to put them out of reach of hackers.
Previously, it was thought that hacking into such a system required physical access, such as plugging in a USB drive or connecting a communications cable. However, the Ben-Gurion team showed that the computers could be compromised merely by controlling the temperature of the air around them.
The method works by taking advantage of the built-in thermal sensors with which computers control their internal fans to prevent sensitive components from overheating. By carefully increasing and decreasing temperature, the computers can be made to communicate in a manner similar to Morse code, with rises and drops in temperature instead of the dots and dashes. As one computer processor is instructed to work hard and overheat, the neighboring computer’s senor detects the change in temperature in what amounts to a crude form of communication.
Both computers also need to have been infected with a special malware program that sits undetected in the system and instructs the computers to use the heat transfer communication. Once installed, the method could enable hackers to siphon data from the computers or send malicious commands at any time.
Currently, the rate of transfer of information is only about eight bits an hour, enough to read a password or send simple commands, but not fast enough to download large amounts of data.
While the technology requires the computers to be within about 40 centimeters of each other, the researchers noted that in a work environment computers are often stacked close to one another, putting supposedly secure air-gapped machines in close proximity to others that are connected to the internet.
The team now intends to research the possibility of using the same method via computer-controlled air-conditioning systems or even a fax machine, according to the Wired technology website.
Last year, the Ben-Gurion researchers demonstrated a concept called “AirHopper,” which uses mobile phones to pick up faint radio wave signals from computers as a method of obtaining data.
The Times of Israel Community.







