The Air-Gap Jumpers

Black Hat USA 2018

Presented by: Mordechai Guri
Date: Wednesday August 08, 2018
Time: 17:05 - 17:30
Location: South Pacific F

The term 'air-gap' in cyber security refers to a situation in which a sensitive computer, classified network, or critical infrastructure is intentionally physically isolated from public networks such as the Internet. Air-gap isolation is mainly used to maintain trade secrets, protect confidential documents, and prevent personal information from being leaked out, accidently or intentionally.

In this talk, we focus on 'Bridgeware', a type of malware which allows attackers to overcome ('bridge') air-gap isolation in order to leak data. We talk about various covert channels proposed over the years, including electromagnetic, magnetic, acoustic, thermal, electrical and optical methods (and introduce new air-jumping technique from our recent research). We examine their characteristics and limitations, including bandwidth and effective distance. We also discuss the relevance of these threats and the likelihood of related cyber-attacks in the modern IT environment. Finally, we present different types of countermeasures to cope with this type of threat. We will include demo videos.

Mordechai Guri

Mordecai Guri, PhD, is the head of R&D; at Ben-Gurion University of the Negev's Cyber-Security Research Center. He earned his B.Sc. and M.Sc, from the Computer Science Department at Hebrew University and received his PhD from BGU. He was awarded the prestigious IBM PhD International Fellowship in 2015. Mordechai manages academic research in various aspects of cyber security for the commercial and governmental sectors. He has led a number of breakthrough research projects in cyber security, focusing primarily on state of the art challenges in the fields of cyber attack and cyber defense. Mordechai examines current paradigms and develops new methods for improved mitigation of security problems in the modern cyber environment. His research topics include OS security, advanced malware, moving target defense (MTD), mobile security, and embedded systems.


KhanFu - Mobile schedules for INFOSEC conferences.
Mobile interface | Alternate Formats