论文标题

关于使用商品智能设备的声学攻击的可行性

On the Feasibility of Acoustic Attacks Using Commodity Smart Devices

论文作者

Wixey, Matt, Johnson, Shane, De Cristofaro, Emiliano

论文摘要

在某些情况下,人类听力的范围可能会对个体造成不利的生理和心理影响。在本文中,我们研究了网络攻击的可行性,这些网络攻击可能会使智能消费者设备在高(17-21kHz)和低(60-100Hz)频率上产生可能无法察觉的声音,以最大的可用体积设置,并有可能将其转变为声学网络武器。为此,我们部署针对不同智能设备的攻击,并在无声室内进行声音测量。为了进行比较,我们还测试了对传统设备的可能攻击。 总体而言,我们发现许多测试的设备能够在高范围和低范围内复制频率,其水平超过了已发布准则中建议的频率。一般而言,这种攻击通常很容易发展,并且在许多情况下可以添加到现有的恶意软件有效载荷中,因为它们可能对具有特定动机或目标的对手有吸引力。最后,我们建议一些对策,包括平台特定和通用的对策。

Sound at frequencies above (ultrasonic) or below (infrasonic) the range of human hearing can, in some settings, cause adverse physiological and psychological effects to individuals. In this paper, we investigate the feasibility of cyber-attacks that could make smart consumer devices produce possibly imperceptible sound at both high (17-21kHz) and low (60-100Hz) frequencies, at the maximum available volume setting, potentially turning them into acoustic cyber-weapons. To do so, we deploy attacks targeting different smart devices and take sound measurements in an anechoic chamber. For comparison, we also test possible attacks on traditional devices. Overall, we find that many of the devices tested are capable of reproducing frequencies within both high and low ranges, at levels exceeding those recommended in published guidelines. Generally speaking, such attacks are often trivial to develop and in many cases could be added to existing malware payloads, as they may be attractive to adversaries with specific motivations or targets. Finally, we suggest a number of countermeasures, both platform-specific and generic ones.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源