Pith. sign in

REVIEW

Don't Look Up: Ubiquitous Data Exfiltration Pathways in Commercial Spaces

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2206.12944 v1 pith:ZSWM3PTO submitted 2022-06-26 cs.CR

classification cs.CR
keywords attackdatabuildingbuildingscommercialexfiltrationreal-timetransmit
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

We show that as a side effect of building code requirements, almost all commercial buildings today are vulnerable to a novel data exfiltration attack, even if they are air-gapped and secured against traditional attacks. The new attack uses vibrations from an inconspicuous transmitter to send data across the building's physical infrastructure to a receiver. Our analysis and experiments with several large real-world buildings show a single-frequency bit rate of 300Kbps, which is sufficient to transmit ordinary files, real-time MP3-quality audio, or periodic high-quality still photos. The attacker can use multiple channels to transmit, for example, real-time MP4-quality video. We discuss the difficulty of detecting the attack and the viability of various potential countermeasures.

Discussion (0). Continue with ORCID to comment.

Pith tools