Researchers in Hong Kong have developed a method of intercepting signals processed by the analog components of headphones, wired phones and smart devices – a technique that involves actively executing external electromagnetic carrier signals.
Image source: injecteave.github.io
This method is called Inject into eavesand this is not just monitoring low-frequency analog signals, but using electromagnetic signals to conduct side-channel attacks. This method does not involve passive interception, but rather a mechanism that actively affects signals in the 0 to 9 MHz range and uses nearby devices to intercept the signal. This attack targets the nonlinear components of computer systems: amplifiers, analog-to-digital converters, power converters, and MOSFET transistors. These components modulate the signal fed to them in such a way that a hypothetical attacker can recover the audio signal transmitted along the analog path.
To implement the InjectEave mechanism, a kit is required that includes a USRP B210 software-defined radio (SDR), antennas to receive and transmit signals, a Siglent SSA3075X Plus spectrum analyzer, a laptop to manage the SDR, and (if necessary) an RF amplifier to increase the attack range. The researchers tested the method on 11 commercially available devices. The most obvious use of this technology is espionage by listening in on conversations via headphones or landlines. This approach also allows you to track occupant activity in rooms equipped with smart fans and lights by monitoring and analyzing control signals and energy consumption metrics.
During testing, the attack range ranged from 1 meter to 6 meters; in some cases, when an RF amplifier was connected, the sound emitted by the headphones could be intercepted from a distance of up to 30 meters. Researchers described eavesdropping through hotel room walls using devices hidden in suitcases or office furniture.
Defending against this attack is not easy: a variety of devices containing nonlinear analog nodes used for signal conversion may be vulnerable to InjectEave attacks. The researchers stress that encryption, blocking or signal randomization will not help in this case because the leak occurs through an analog path. Mechanisms such as shielding or filtering can reduce the energy embedded in the carrier signal – they increase the level of protection, but still do not guarantee complete invulnerability.
If you find an error, select it with your mouse and press CTRL+ENTER.










