If you haven’t spent much time around computers and cyber, it might surprise you to learn that pattern detection plays a huge role in both human and machine activity. Signature detection allows antivirus systems to work, while human analysts become skilled at observing patterns within the data to help prevent attacks and enhance their knowledge regarding active threats.
In a lot of situations, this works great. The problems start when we get systems that operate outside the traditional pattern-based activities. RF systems are one of these things that often don’t easily fit into many pattern-based systems at all.
Radio isn’t new. These days, it isn’t even glamorous, but it is consistently overlooked, which is the entire reason that this publication exists. And as more systems evolve to leverage wireless features, the RF layer becomes a bigger part of the overall attack surface.
Today, we’re going to look at this in much more detail.
The spectrum is embedded in the technology we use everyday. Now, that matters. Source: Wikipedia
What the RF Attack Surface Actually Is
At its fundamental level, the RF attack surface is made up of any system that transmits or receives radio signals. That includes the obvious things like Wi-Fi and Bluetooth, but it also extends well beyond traditional IT as well.
In the modern world, we can also look at and consider:
- Cellular communications
- GNSS (GPS and related systems)
- RFID and NFC
- Sub-GHz IoT devices (433 MHz, 868/915 MHz)
- Remote controls, key fobs, and garage doors
- Smart meters and industrial sensors, and
- Aviation and satellite systems
This might be a reasonably broad list in comparison to what most expect, but the reality is that a lot of modern, RF-based systems sit outside the traditional security scope.
They are often isolated or unmanaged, many rarely have logs, and they are more often than not deployed with little thought given to the security or integrity of such systems. Today, though, if a device transmits or communicates over the air, it can often be considered part of the attack surface.
Whether it was designed with that in mind or not is usually a secondary consideration.
With no encryption and no authentication, ADS-B is easily spoofable. Source: Wikipedia
RF Changes (Some Of) The Rules
Standard defensive controls work pretty well after decades of evolution, and it’s trivially easy to set up a pipeline to adapt the best of these controls to your own application.
But one of the biggest problems is that, for the most part, RF is inherently broadcast. It will transmit as part of its normal operation, and it’s these transmissions that can often open up an attack vector.
Secondary to this, in a lot of cheap devices, the physical layer will provide little in the way of security. Authentication and encryption will often sit on top of the RF layer, and that assumes that they even exist at all. Sometimes, they don’t.
Lastly, while specialised tools do exist for logging and monitoring, often the fact that they are specialised means that they are the last to be introduced. The reasons for this are varied, but often factors can include cost or simply limited access to the right people. The fact that the spectrum is so busy these days creates an additional problem in that, in busy areas, it can often be tricky to get a baseline understanding of what’s happening around you.
All in all, it comes together to create an environment that is consistently interesting from a research perspective.
RF Attack Types: Passive
The spectrum can often be a confusing place to hang out, but once we start looking at things from an attack perspective, things get much more consistent and easier to understand. More often than not, attacks can be classified as active or passive, and beyond this, they’ll typically come in a few different types.
Passive attacks are where things start, and while this has no need for transmitting, you can still gain plenty of information if you’re patient and know where to look. Passive attacks will include:
- Eavesdropping on unencrypted signals
- Capturing and analysing transmissions
- Observing traffic patterns for activity analysis
Passive attacks are particularly interesting because little more than capture is required to start gathering information. While they aren’t as rapid or noisy as an active attack, they can still be a legitimate threat for enumeration and building up a picture discreetly.
No longer the sole domain of the military, cheap electronics have enabled jamming and replay technology to hit the mainstream. Source: Wikipedia.
Active Attacks
Less commonly observed in everyday environments, active attacks are where the adversary will interact with the system, much like we would see in a traditional cyberattack. These attacks can include:
- Replay attacks (capturing and retransmitting signals)
- Signal injection
- Spoofing legitimate devices
Radio is also unique in that active attacks also include those whose sole purpose is denial or disruption. Here, this can include jamming specific frequencies, causing interference to large chunks of spectrum or simply preventing legitimate communications by other means.
This can be critical in some industrial environments, however, like an online Denial of Service (DoS) attack, these are very noisy and very visible to anyone who might be looking at a spectrum display during an active event.
Note: It’s worth pointing out that active attacks may still affect your environment, with little you can do in the way of stopping them. For instance, after the Russian invasion of Ukraine, GPS became a contested environment that would spill into the civilian sector. While they are rarer, this doesn’t mean that they don’t occur.
Real-World RF Applications
Some of these attacks stay rare. Others are already common, backed up by both historical precedent and cases that are still unfolding.
GPS denial is still a problem that affects Europe to this day, while worldwide, thousands of commercial and private IoT sensors will regularly send data in the clear.
The ability to deauth specific devices or worse, jam Wi-Fi networks is well documented, and to prove the threats aren’t just active, we’ve had plenty to say about device fingerprinting and Bluetooth tracking in previous articles.
Let’s be clear. The traditional attack surface that we see can be much more detailed than the one we might see in wireless devices. But as technology evolves over time, this statement will hold less weight.
Our reliance on IoT has forced us to reconsider just what is being broadcast, while a secondary reliance on convenience over security is partly why some of these problems exist.
Note: Physics plays a key role in helping to reduce the wireless attack surface. While computers can be accessed from the other side of the world, for many RF systems, proximity is key. We’ll look at this more in future articles.
Devices like the cellphone-snooping Stingray help to highlight how proximity and physics often play a key role in wireless attacks. Source: Wikipedia.
It’s Not All Bad
You might be reading this article and wondering why on earth we use wireless devices at all. But the reality is that in the real world, security isn’t the only consideration when a system is built. In fact, for some systems, security isn’t even a consideration at all.
The wireless spectrum has made it much more convenient for us to live our modern lives. Tools like Wi-Fi have demonstrably changed the way we consume media, work remotely and connect to the internet.
The spectrum can be a confusing place. But in a lot of instances, it’s simply because little is known or understood about what is being broadcast, and more importantly, what that actually means. This means understanding that with RF devices, the attack surface is defined by visibility, not complexity.
While the attack surface is constantly expanding, so is the knowledge base and the motivation to provide more secure wireless systems.
As always, the scales move back and forth as the advantage moves from the attacker to the defender.
Investigator515 explores the RF spectrum, cybersecurity, and the hidden tech behind modern espionage.
Follow for new content weekly
You might also like,
- OSINT Investigators Guide to Self Care & Resilience