Leaking Through the Physics: Covert Cyber-Physical Data Exfiltration Through Unobserved Physics
摘要
From magnetic fields to differential power analysis, side-channel attacks have emerged as a significant threat to cyber-physical systems (CPS). Attackers often exploit out-of-band channels through signal-injection attacks to perform data exfiltration. These attacks primarily target unmonitored channels and open-loop cyber-physical systems. However, attacks through physical channels are relatively unexplored because state estimation methods are conventionally believed to be sufficient for detecting malicious physical actuation. In this paper, we propose a novel method for out-of-band data exfiltration from a cyber-physical system based on unobserved physics. We present that, despite the presence of state estimation-based intrusion detection techniques, our data exfiltration method can exploit the limitations of physical state observability to circumvent these protections. It allows for the stealthy exfiltration of sensitive data from the network using existing cyber-physical models and the infrastructure of individual devices. We evaluate the efficacy of our data exfiltration technique in the context of two real-world testbed scenarios: an industrial robotic arm controller and an autonomous surveillance drone. We discuss potential defenses against this type of attack and their limitations.