xLED: Covert Data Exfiltration from Air-Gapped Networks via Router LEDs
Mordechai Guri, Boris Zadov, Andrey Daidakulov, Yuval Elovici

TL;DR
This paper demonstrates a novel method for covert data exfiltration from air-gapped networks by controlling router LEDs to transmit encoded information detectable by remote cameras and sensors.
Contribution
It introduces the first study of using router status LEDs as covert channels for data exfiltration, including implementation, modulation schemes, and evaluation.
Findings
Data can be leaked at rates up to 1Kbit/sec per LED.
Remote cameras and sensors can detect the LED signals effectively.
Countermeasures can be implemented to prevent such covert channels.
Abstract
In this paper we show how attackers can covertly leak data (e.g., encryption keys, passwords and files) from highly secure or air-gapped networks via the row of status LEDs that exists in networking equipment such as LAN switches and routers. Although it is known that some network equipment emanates optical signals correlated with the information being processed by the device ('side-channel'), intentionally controlling the status LEDs to carry any type of data ('covert-channel') has never studied before. A malicious code is executed on the LAN switch or router, allowing full control of the status LEDs. Sensitive data can be encoded and modulated over the blinking of the LEDs. The generated signals can then be recorded by various types of remote cameras and optical sensors. We provide the technical background on the internal architecture of switches and routers (at both the hardware and…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Steganography and Watermarking Techniques · Advanced Malware Detection Techniques · Chaos-based Image/Signal Encryption
