aIR-Jumper: Covert Air-Gap Exfiltration/Infiltration via Security Cameras & Infrared (IR)
Mordechai Guri, Dima Bykhovsky, Yuval Elovici

TL;DR
This paper demonstrates how security cameras and infrared light can be exploited to establish covert, bidirectional air-gap communication channels for data exfiltration and infiltration, revealing new security vulnerabilities.
Contribution
It introduces novel methods for covert data transfer using IR-enabled surveillance cameras, including implementation details and evaluation of data rates and distances.
Findings
Data exfiltration at 20 bits/sec over tens of meters
Data infiltration at over 100 bits/sec over hundreds of meters
Bidirectional covert communication possible via IR signals
Abstract
Infrared (IR) light is invisible to humans, but cameras are optically sensitive to this type of light. In this paper, we show how attackers can use surveillance cameras and infrared light to establish bi-directional covert communication between the internal networks of organizations and remote attackers. We present two scenarios: exfiltration (leaking data out of the network) and infiltration (sending data into the network). Exfiltration. Surveillance and security cameras are equipped with IR LEDs, which are used for night vision. In the exfiltration scenario, malware within the organization access the surveillance cameras across the local network and controls the IR illumination. Sensitive data such as PIN codes, passwords, and encryption keys are then modulated, encoded, and transmitted over the IR signals. Infiltration. In an infiltration scenario, an attacker standing in a public…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · Internet Traffic Analysis and Secure E-voting · Cybercrime and Law Enforcement Studies
