Data Exfiltration through Electromagnetic Covert Channel of Wired Industrial Control Systems

Sachintha, Shakthi; Le-Khac, Nhien-An; Scanlon, Mark; Sayakkara, Asanka P.

Publication Date:  October 2022

Publication Name:  Applied Sciences, Volume 13,, Number 5,, Pages 2928,

Abstract:   Industrial control systems (ICS) often contain sensitive information related to the corresponding equipment being controlled and their configurations. Protecting such information is important to both the manufacturers and users of such ICSs. This work demonstrates an attack vector on industrial control systems where information can be exfiltrated through a electromagnetic (EM) radiation covert channel from the wired Ethernet connections commonly used by these devices. The attack leverages compromised firmware for the controller—capable of encoding sensitive/critical information into the wired network as packet transmission patterns. The EM radiation from the wired network’s communication is captured without direct physical interaction using a portable software-defined radio, and subsequently demodulated on the attacker’s computer. This covert channel facilitates the exfiltration of data from a distance of up to two metres with a data rate of 10 bps without any significant data loss. The nature of this covert channel demonstrates that having strong firewalls and network security.

Download Paper:

Download Paper as PDF

BibTeX Entry:


      @article{sachintha2023DataExfiltrationEMSCA,
author={Sachintha, Shakthi and Le-Khac, Nhien-An and Scanlon, Mark and Sayakkara, Asanka P.},
title="{Data Exfiltration through Electromagnetic Covert Channel of Wired Industrial Control Systems}",
journal="{Applied Sciences}",
year=2022,
month=10,
volume=13,
number=5,
pages=2928,
doi={10.3390/app13052928},
abstract={Industrial control systems (ICS) often contain sensitive information related to the corresponding equipment being controlled and their configurations. Protecting such information is important to both the manufacturers and users of such ICSs. This work demonstrates an attack vector on industrial control systems where information can be exfiltrated through a electromagnetic (EM) radiation covert channel from the wired Ethernet connections commonly used by these devices. The attack leverages compromised firmware for the controller—capable of encoding sensitive/critical information into the wired network as packet transmission patterns. The EM radiation from the wired network’s communication is captured without direct physical interaction using a portable software-defined radio, and subsequently demodulated on the attacker’s computer. This covert channel facilitates the exfiltration of data from a distance of up to two metres with a data rate of 10 bps without any significant data loss. The nature of this covert channel demonstrates that having strong firewalls and network security.}
}