Securing air-gapped systems-review of covert techniques for data ex-filtration and a new clause proposal for ISO 27001
摘要
Air-gapped networks are created to isolate a computer or a network of computers in order to avoid any external connection. Suck systems are required for completely rendering any wired or wireless connection with other networks , systems or devices. Usually these infrastructures are used for maintaining the enhanced security of critical systems that involves highly confidential information. Mostly military setups, financial sectors,industrial organizations and nuclear plants requires air-gapped systems for ensuring the privacy,security, integrity and confidentiality of the extremely sensitive data. These systems are completely disconnected from internet which makes it extremely challenging and difficult to penetrate into such systems. Despite ensuring extreme security measures and complete isolation from any kind of network, security threats are always there and risks still exist for air-gapped systems. Various software and hardware vulnerabilities in critical systems can lead to security breaches which can have devastating effect at a wider level. Professional hackers keep on inventing novel ways and malwares for infiltrating highly secure air-gapped systems and extracting sensitive information. Hence, to ensure confidentiality, integrity and availability of such critical systems, it is required to standardize controls and policies are required to be implemented. This research paper focuses on the latest emerging threats to air-gapped systems using covert channels for data exfiltration. Countermeasures for the covert channels have been analysed in our research. ISO27001 ,the internationally established security standard has been discussed in context of securing air-gapped systems. In the light of existing covert channels, respective countermeasures and ISO 27001 applicability to air-gapped systems, we have proposed a new clause for securing air-gapped systems.