2018/04/10 by Mordechai Guri, Boris Zadov, Guri, Mordechai +5 · 3 voices
Computer Science · Engineering · #Advanced Malware Detection Techniques #Cryptographic Implementations and Security #Electrostatic Discharge in Electronics #cs.CR
paper · pdf · doi:10.48550/arxiv.1804.04014
openalex publication_date 2018/04/10 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
In this paper we provide an implementation, evaluation, and analysis of\nPowerHammer, a malware (bridgeware [1]) that uses power lines to exfiltrate\ndata from air-gapped computers. In this case, a malicious code running on a\ncompromised computer can control the power consumption of the system by\nintentionally regulating the CPU utilization. Data is modulated, encoded, and\ntransmitted on top of the current flow fluctuations, and then it is conducted\nand propagated through the power lines. This phenomena is known as a 'conducted\nemission'. We present two versions of the attack. Line level powerhammering: In\nthis attack, the attacker taps the in-home power lines1 that are directly\nattached to the electrical outlet. Phase level power-hammering: In this attack,\nthe attacker taps the power lines at the phase level, in the main electrical\nservice panel. In both versions of the attack, the attacker measures the\nemission conducted and then decodes the exfiltrated data. We describe the\nadversarial attack model and present modulations and encoding schemes along\nwith a transmission protocol. We evaluate the covert channel in different\nscenarios and discuss signal-to-noise (SNR), signal processing, and forms of\ninterference. We also present a set of defensive countermeasures. Our results\nshow that binary data can be covertly exfiltrated from air-gapped computers\nthrough the power lines at bit rates of 1000 bit/sec for the line level\npower-hammering attack and 10 bit/sec for the phase level power-hammering\nattack.\n