SiteMap
close
Research
Research News
A prestigious global university that fosters Sejong-type talent who challenges creative thinking and communicates with the world.
--
|
Collapse of Impenetrable Security: Realization and Advancement of Acoustic Signal-Based Air-Gap Attacks 2026.03.24 1104 |
|||||
|---|---|---|---|---|---|
|
1. Introduction The international security environment recently changed into an invisible and asymmetrical aspect. More specifically, as shown in the Russia-Ukraine War demonstrates, It was more specifically confirmed that the aspect of war was not only limited to traditional physical conflicts, which the Russia-Ukraine war illustrates. War in cyberspace preemptively took place. In other words, the past wars evolved around forces, weapons, and terrain, but the acquisition and control of enemy intelligence in modern times determines the aspect of war. National secrets and military operational information are in particular considered to contain sensitive data, and they are separately managed by laws and regulations. If this type of information is preemptively stolen and used for disruption, a strategic advantage over the opposing nation may be obtained. This does not mean that there are no countermeasures in situations like this. Infrastructure that is directly related to national security and operations is designated to be critical information and communications infrastructure, which is managed separately in Korea, and air-gap technology has been adopted as a last line of security strategy in order to physically or logically block access to external networks in regards to infrastructure that contains control systems. The air-gap environment has long been considered to be flawless, because it fundamentally blocks internal systems from external networks. However, a series of research and actual attack cases, which are recently developed studies, are increasingly revealing that the air-gap security model is not a flawless defense mechanism. Attackers are becoming more intelligent and sophisticated, and new attack methods that bypass air-gap mechanisms as opposed to simply penetrating networks have been proposed and developed. There are various attack techniques, but the most popular attack techniques are the covert channel-based attacks using non-conventional media, such as acoustic signals, electromagnetic waves, and heat signals. Acoustic signal-based attacks, which are unlike other attack techniques, do not require expensive equipment and leave no traces, which restricts response, identification, and detection. The importance of offensive security research, which moves beyond analyzing the existing attacks from the defender's perspective and instead analyzes threats from the attacker's perspective, is therefore increasingly emphasized. It is required through this to proactively understand attack techniques and analyze how attacks can be conducted in order to identify blind spots in the existing security systems and establish effective response strategies. This paper, which is based on research on offensive security from the attacker's perspective, therefore aims to systematically analyze what security threats may be caused by air-gap attacks using acoustic signals. Furthermore, security strategies that should be developed in order to ensure national security and infrastructure security is discussed in addition to clarifying the limitations of the existing network separation technologies. 2. Air-Gap Technology and Its Limitations: Collapse of Impenetrable Security “Air-gap refers to an interface between two systems that are not physically connected and what logical connection is not automated [1]. This means that the air-gap environment refers to the environment that is completely isolated from all external connections, which includes networks, computers, and the public internet. The air-gap environment has long been perceived as being "not hackable because they are not connected to the internet" and have been used as essential security measures for systems that store sensitive information or control large-scale important infrastructure due to this characteristic. Intelligence agencies and military agencies in particular have built the air-gap environment in order to protect national confidential information and defense systems, whereas critical infrastructure, such as power, water resources, and manufacturing facilities are also applying the air-gap technology for the security of industrial control systems and operational data. Air-gap technologies have emerged as a core security strategy across various organizations and industries that put the protection of sensitive information as a top priority. However, the security accidents that target important infrastructure has been continuously increased recently despite this strong security awareness, and the cases of damage are also steadily increasing. This is representative evidence that shows that air gap technology is no longer a flawless security technique. There are in fact various routes in order to attack the air gap environment, which are classified below. 1. Malware infection via physical media: Malware infiltrates the air-gap environment via removable storage devices, such as USBs and CDs. 2. Insider threat: An individual with legitimate credentials within an organization intentionally or unknowingly causes malware to run on internal network systems. 3. Supply chain attack: Malware is inserted into reliable software or hardware supply chains and ultimately infiltrate the air-gap internal systems. If an attacker gains control of internal systems through these routes, PCs within the air-gap internal network are no longer considered to be safe destinations. They become a medium for leaking sensitive data to outside sources. However, the attacker cannot externally transmit data via traditional TCP/IP-based network channels at this stage, which is what we commonly understand. This is because the physical and logical network separation is still maintained, which is a core characteristic of air-gap technology. Attackers should leak sensitive data accordingly from the internal network to the outside world using abnormal communication methods as opposed to normal network routes. The most commonly used intermediaries include electromagnetic waves, acoustic signals, and optical signals, which have the characteristic of being able to transmit information even in environments where network connectivity is completely blocked. Abnormal channel-based attacks that utilize various intermediaries are consequently emerging as a new threats that are capable of exfiltrating internal network data despite efforts to protect sensitive data in critical infrastructure through air-gap environments. An attack that leaks sensitive data from the internal network to the external network using electromagnetic waves, acoustic signals, or optical signals in an air gap environment that is built on the premise of complete separation of the network is defined as an air-gap attack. The conceptual structure of the air gap attack is illustrated in Figure 1.
* Internal Network / * External Network Figure 1. Air-gap Attack Concept Diagram: Internal Network Data Exfiltration Structure via Non-Conventional Intermediaries 3. Structural Limitations of Acoustic Signal-Based Air-gap Attacks It was previously confirmed that air-gap attack techniques may steal sensitive data from internal networks to external networks using various intermediaries, which include electromagnetic waves, acoustic signals, and optical signals. This study was conducted by focusing on air-gap attack techniques using acoustic signals among these intermediaries. Attackers should maintain high levels of stealth when they steal accurate data in regards to air-gap attacks, which aim to steal data in network-separated environments. However, there is a limit to stably collecting and analyzing the signals that are used in the attack due to the large amount of interference that is caused by electromagnetic waves that are generated in the daily environment, which raises the problem that it is difficult to steal high-accuracy sensitive data, in regards to electromagnetic wave-based air gap attacks. Optical signal-based air gap attack technology also has structural limitations in regards to securing stealth, because visual elements, such as LED blinking and screen brightness changes are inevitably exposed. Acoustic signal-based air-gap attacks in contrast have stealth advantages, because they use inaudible frequency bands, which are difficult for humans to perceive, and relatively high-accuracy data transmission is achieved by applying advanced signal processing techniques at the same time. This study focuses on data exfiltration techniques using acoustic signals, exploring more advanced air-gap attack techniques, and raising awareness of the potential threat and impact of these techniques for this reason. It is necessary to first understand the characteristics of the acoustic signals themselves, which is the basis of the attack, in order to analyze acoustic signal-based air-gap attack techniques. Acoustic signals are essentially waves, so information can be transmitted by adjusting physical elements, such as amplitude, frequency, and wavelength. In other words, acoustic signal-based air-gap attacks transmit sensitive data from the internal network to the external network through the process that is illustrated in Figure 2. First, sensitive data is acquired from a malware-infected internal network device through the previously mentioned attack path, and it is then converted into a packet-structured bit string. The amplitude, frequency, or wavelength is modulated based on the bit string in order to generate an audio signal, which is then emitted into the external space through an output device, such as a speaker or computer buzzer. An attacker located on the external network receives the audio signal using a device, such as a microphone and recovers the original sensitive data through a signal analysis.
Many acoustic signal-based air-gap attack techniques proposed to date adopted the Frequency Shift Keying (FSK) for digital data transmission. FSK has been widely used in various communication systems due to its simple structure and relatively strength to noise [2]. Modulation in FSK is performed by allocating different frequencies f1 and f2 to bits 0 and 1, and the receiver extracts bit data by analyzing frequency components in each bit section after collecting the sound signals. However, various interference factors, such as electromagnetic noise from surrounding electronic devices, sound emitted from the computing device itself, and environmental noise are likely to distort the transmitted sound signal in the process of reaching the receiver in an environment where an actual air-gap attack is performed. This phenomenon can be confirmed through the frequency spectrum, which is illustrated in Figure 3.
Figure 3 shows an example where an air-gap attack receiver transmitted an audio signal at a frequency modulation of 18,500 Hz for the 0 bit and 19,500 Hz for the 1 bit. However, the receiver observed frequency components different from the intended transmission. This means that the signal spectrum is diffused or distorted due to interference in an actual environment. A sophisticated signal analysis technique that considers acoustic signal distortion due to ambient interference is therefore essential in order to accurately steal sensitive data from the internal network in an actual air gap environment. In addition, precise time synchronization between the transmitter and receiver is required for accurate data demodulation in the FSK-based signal processing method. However, it is actually impossible to exchange real-time synchronization information between transceivers due to the physical and logical separation of the network. This is due to the nature of the air gap environment, which makes it difficult for external network receivers to accurately determine when the internal network device reproduces the sound signal and what section of the received signal contains the actual sensitive data. As a result, the receiver receives the sound signal from a certain point in time, which causes a bit alignment error during the FSK demodulation process, and it greatly reduces the accuracy and reliability of the demodulation. Furthermore, external attackers cannot know the full length or the end point of sensitive data stored on the internal network in advance, so it is difficult to determine whether data restoration is complete. This issue acts as a major factor that prevents the success rate of attacks in the real-world environment. The previously mentioned constraints, such as signal distortion, time asynchronous, and data length uncertainty should consequently be considered in order to research and develop advanced acoustic signal-based air-gap attack technologies that can be applied in a real-world environment. However, several of the previous studies to date have not sufficiently reflected these realistic constraints, and there is a limitation. As a result, the attack efficiency in a long-distance communication environment is limited, which can be seen in Table 1. Table 1. Performance by air gap attack technique based on the preceding sound signal 4. Acoustic Signal Air-Gap Attack Using Optimal Frequency Range Search This study proposed and implemented an acoustic signal air-gap attack technique using an optimal frequency range search technique in order to alleviate the structural limitations of the previously mentioned acoustic signal-based air-gap attack and develop a more advanced acoustic signal-based air-gap attacker. The attacker consists of an air-gap attack transmitter that is located in the internal network and an air-gap attack receiver that is located in the external network due to the nature of air-gap attacks. The transceiver that is implemented in this study was developed using the speakers and microphones of the devices, which are listed in Table 2. Table 2. Transmitter and receiver device information in the proposed acoustic signal-based air-gap attack First, the proposed acoustic signal-based air-gap attacker uses inaudible frequency bands in order to ensure stealth during attack. This makes it difficult for internal network users to detect the attack, and it significantly strengthen the stealth of the air-gap attack. Furthermore, the use of these inaudible frequency bands offers the additional benefit of effectively reducing signal interference that is caused by external noise by minimizing the impact of audible noise in the daily environment. The proposed acoustic signal-based attacker, which is illustrated in Figure 3, was designed in order to address the problem that acoustic signals generated from the transmitter becoming distorted in the transmission to the receiver. An extended demodulation strategy is applied that also considers the surrounding frequency bands in order to mitigate this, which is unlike the conventional method that performs demodulation solely based on 2 modulation frequencies f1 and f2 used in the attack. This means that the proposed method searches for the frequency with the maximum amplitude within the frequency spectrum of the received acoustic signal, which includes the adjacent frequency band of each f1and f2, and determines the bit value based on the result. The key issue at this time is how far to consider the surrounding frequency band. If the range that is being considered is too narrow, the data demodulation accuracy may deteriorate, because the frequency distortion that occurs in the actual environment is not sufficiently covered. If the range of consideration is too wide, the calculation complexity conversely increases, because the unnecessary frequency domain is included in the analysis target. Also, the possibility of overlapping between frequency ranges that correspond to f1and f2, increases at that time. This may lead to a decrease in the attack efficiency and an increase in the risk of mis-demodulation. The optimal frequency range that is accordingly considered in this study for advanced acoustic signal-based air gap attacks is defined as the range that satisfies the following conditions. 1. The distorted frequency range of f1 and f2 used in the attack should be included within each frequency band range. 2. No overlap between two frequency ranges should occur. 3. It should be the minimum value of the frequency band range that satisfies both considerations above. Figure 4 shows the process of searching for the optimal frequency range that satisfies these conditions. The proposed acoustic signal-based air-gap attacker searches for the optimal frequency range that satisfies the conditions for each bit interval, and it then performs demodulation only within that range. This enables effective detection of distorted frequency components, which consequently improves both the accuracy and attack efficiency of the data reconstruction.
* Optimal Frequency Range Figure 4. Optimal Frequency Range Search Technique Furthermore, this study adopted additional design elements in order to mitigate the lack of time synchronization between the transmitter and receiver and the inability to know the full size of the target sensitive data in advance. The proposed attacker allows the air gap attack receiver to identify the start point of the valid payload within the received sound signal without prior synchronization as well as to accurately restore the order of the demodulated data by using a packet structure, which includes a preamble and a sequence number. In addition, the receiver analyzes the sound signal at a single point in time, and it also accumulates and analyzes the demodulation results based on a plurality of sound signals that are collected over a long period of time. The valid sequence range is identified by analyzing the distribution and continuity of the observed sequence number in this process, and the size of the entire payload is estimated through the maximum value of the observed sequence number. The receiver can determine the completeness of the restored data through this as well as by verifying whether the data is missing and restoring more reliable sensitive data. The overall structure of the advanced acoustic signal air gap attack based on optimal frequency range search with this type of a function can be confirmed using Figure 5.
5. Experiment and Verification This study performed an actual acoustic signal-based air-gap attack and measured the bit error rate (BER) according to the distance between the transmitter and the receiver in order to verify the effectiveness of the advanced acoustic signal air-gap attack, which was based on the search for the optimal frequency range that is introduced above. All BER measurements were performed through 10 independent repetitive experiments under the same experimental conditions. The results of independent experiments generally use the average value as a performance indicator, but this study aimed to evaluate the effectiveness of the attack by considering the worst performance degradation situation that can occur in an actual attack environment as opposed to using the average performance. The maximum value of the BER among the results of 10 repetitive experiments performed under each distance condition was accordingly adopted as a representative performance indicator. The experiment was conducted in an indoor environment where the HVAC system continuously operates based on the device, which is presented in Table 1. The experimental space has a long corridor shape with a width of about 1.9 meters, and the transmitter and receiver were placed at the same height. In addition, the straight path was maintained under the condition that there were no physical obstacles that could directly affect the sound propagation on the transmission/reception path. This study conducted experiments in 2 noise environments, which are illustrated below, in order to consider realistic environmental conditions. 1. A daily environment with an average noise level of about 40 dB. 2. An environment where music is played at an average of about 70 dB. The experimental results for each distance in each environment are presented in Figure 6. It was confirmed through the experimental results that the acoustic signal-based air-gap attack technique proposed in this study can steal sensitive data from the internal network even at a distance of up to 40 meters. This is a result that shows that attacks are possible at the higher accuracy over a much longer distance compared to the existing acoustic signal-based air-gap attack technique, which is presented in Table 1.
The results that are presented in Figure 6 show 2 key characteristics. First, a certain degree of variability is observed in the BER values of the repeated experiments between 2 noise environments, which include a 40 dB everyday environment and a 70 dB music playback environment, under the same distance conditions. The maximum BER values observed at each distance remain generally similar in both environments despite this variability. This means that the impact of increased environmental noise levels on the BER performance of the proposed acoustic signal-based air-gap attack technique is limited, which implies that performance degradation due to changes in the noise environment is minimal. The reason why this trend occurs is more clearly defined in Figure 7.
Frequency spectrum (A), which is shown in Figure 7, shows the frequency spectrum of the acoustic signal that is received by the receiver 3 meters away from the transmitter in the average 40 dB noise environment, and frequency spectrum (B) shows the frequency spectrum of the acoustic signal that is received under the same conditions in the average 70 dB noise environment. It was previously mentioned that the proposed air gap attacker uses the inaudible frequency band in order to ensure stealth, and it was confirmed to receive little direct interference from general environmental noise, which includes music. Second, it can be confirmed through the results of the proposed study that the attack was successfully conducted at a distance of 40 meters, which is much longer than the attack distance that was reported by the previous studies, and the BER remained at a low level at that distance. The reason why this result is derived is confirmed by Figure 8.
The frequency spectrum (A), which is provided in Figure 8, shows the frequency spectrum of the acoustic signal that is received by the receiver 36 meters away from the transmitter in an environment where music is played at an average of 70 dB, and the frequency spectrum (B) is the result of only expanding the optimum frequency range around the frequency f1and f2, which were used when the attack was performed in (A). The frequency component with the maximum amplitude in this spectrum exists within the optimum frequency range based on f1, so out of the frequency set during the attack, which is illustrated in Figure 8, shows that the 0 bit is correctly demodulated. In other words, even if the signal strength is weakened due to the effect of noise or attenuation that occurs during the propagation of the acoustic signal, the proposed optimal frequency range search-based demodulation technique proves that the bit string can be accurately extracted by selectively analyzing only a specific frequency band. It was confirmed through this that the sensitive data of the internal network can be reliably stolen even in the real-world environment. The research team won the Institute of Electronics and Information Engineers (IEIE) President’s Award at the Side Channel Information Analysis Competition that was held in July 2024 and July 2025 based on these study results, which is shown in Figure 9.
6. Extending the Acoustic Signal-Based Air-Gap Attack Threat Model by Considering Real-World Environmental Constraints The studies on advanced air-gap attack techniques are continuously being conducted in addition to the proposed study that is described above in order to emphasize that air-gap environments are no longer a perfect security measure as well as raise awareness of this issue. Considering more sophisticated air-gap attack techniques and the types of attack models that can be used in actual battlefields or critical infrastructure environments is an essential step in regards to defining new constraints that future acoustic signal-based air-gap attack techniques should address, such as the process of deriving various constraints in the studies that are proposed above. Air-gap attacks use non-conventional intermediaries in order to steal data, so their applicability in real-world environments is one of the most important evaluation criteria. Whether an attack is possible in environments where there are physical obstacles and the high background noise coexists is in particular a key factor in regards to determining the practical threat that is posed by air-gap attacks. However, most of the existing studies have been limited to either conducted attacks in ideal environments with relatively little noise, or they failed to adequately account for situations where physical obstacles, such as walls, doors, and structures are present. This does not sufficiently reflect the environment where the actual air-gap attack can be performed, which acts as a factor that limits the practical applicability of the attack technique. On the other hand, threat models that do account for realistic constraints are no longer sufficient at a time when the battlefield environment and the cyber attack technologies are also rapidly advancing with the rapid development of AI technology. It is necessary to recognize that acoustic signal-based air-gap attacks are no longer threats that are limited to a controlled experimental environment. They can be extended to an attack model that can be established even under realistic environmental constraints. The future studies on sound signal-based airgap attacks should start with the critical mind that even in an infrastructure environment that is actually important, so sound signal-based data exfiltration is no longer a theoretically possible scenario. Important infrastructure is in fact composed of an environment where continuous background noise is generated and various physical obstacles, such as walls, doors, and other structures interfere with the propagation of sound signals. Nevertheless, if an air-gap attack is possible even in these types of environments, the ripple effect of the attack may significantly exceed the previously evaluated level. For example, it is a very important study task to analyze whether an acoustic signal-based air-gap attack is possible in large public places, such as crowded Seoul Station, which is shown in Figure 10, a high-noise environment, such as inside a method of transportation that is moving, which is illustrated in Figure 11, or a space where a number of physical obstacles exist, which is depicted in Figure 12. If an attack is actually possible in these types of environments, the attacker will overcome additional constraints, and it is necessary to proactively review what technological advances are required for this. It is consequently necessary to expand the attack scenario that includes a real environment where high noise and physical obstacles coexist, which is beyond the existing ideal experimental environment to a threat model in order to effectively respond to the rapidly developing sound signal-based air gap attack technology. In addition, it is time to discuss response strategies and defense systems from a security perspective as well as technical feasibilities by focusing on whether an attack is possible even under these conditions.
7. Conclusion Air gap technology, which has long been recognized as an absolute defense through the physical and logical separation of the network, can no longer be said to be a flawless security measure. Important infrastructure that seeks to protect sensitive data by adopting air gap technologies has become a high-value target for attackers who are continuously advancing air gap attacks using various intermediaries, such as electromagnetic waves, acoustic signals, and optical signals in order to steal internal network data. We need to accordingly identify blind spots with the existing security system and establish effective response strategies by understanding the air-gap attack technology from a preemptive perspective as opposed to a follow-up response and analyzing how an attack can be actually performed. This study systematically analyzed the major constraints that cause performance degradation when performing an actual air-gap attack, and the derived requirements in order to mitigate them by using a critical point of view. Furthermore, an advanced acoustic signal air-gap attack technology based on searching for the optimal frequency range by reflecting the requirements was designed and implemented. The proposed technique has been experimentally proven to ensure high concealment by using the inaudible frequency band, maintaining low error rates even in distorted signal environments, and achieving high data exfiltration accuracy at distances of up to 40m. These study findings clearly show that the air-gap attack technology is no longer a threat that remains in a theoretical possibility or limited experimental environment. In other words, it implies that the air-gap attack is evolving into an attack model that can be sufficiently established even under realistic environmental constraints, which is beyond the existing perception that it is difficult to use on actual battlefields or important infrastructure environments due to performance limitations. This may be a result of warning that blind trust in the air gap environment can act as a serious security vulnerability. It is therefore time to boldly abandon the premise that air gap is safe and establish a security response strategy that considers various non-conventional attack scenarios, which include sound signal-based air-gap attacks, in the future. It is hoped that the analysis and experimental results presented in this study will be a reference point for realistic threat recognition and preemptive response strategies in regards to designing next-generation critical infrastructure security systems. 8. References [1] National Institute of Standards and Technology (NIST), “Air gap”, NIST Computer Security Resource Center Glossary. [Online]. Available: https://csrc.nist.gov/glossary/term/air_gap. Accessed: Feb. 4, 2026. [2] J. Sanchez, “FSK Demodulation and Bit String Extraction: A Python-Centric Approach in SDR Systems”, arXiv preprint arXiv:2402.17777, 2024. [3] M. Guri, “PIXHELL Attack: Leaking Sensitive Information from Air-Gap Computers via ‘Singing Pixels’”, in Proc. 2024 IEEE 48th Annual Computers, Software, and Applications Conference (COMPSAC), pp. 976-987, 2024. [4] M. Guri, “Gpu-fan: Leaking sensitive data from air-gapped machines via covert noise from gpu fans”, in Proc. Nordic Conference on Secure IT Systems, Springer International Publishing, pp. 194-211, 2022. [5] M. Guri, “EL-GRILLO: Leaking Data Ultrasonically from Air-Gapped PCs via the Tiny Motherboard Buzzer”, in Proc. 2023 20th Annual International Conference on Privacy, Security and Trust (PST), pp. 1-11, 2023. [6] J. de Gortari Briseno et al., “Inkfiltration: Using inkjet printers for acoustic data exfiltration from air-gapped networks”. in Proc. ACM Trans. Privacy Secur., vol. 25, no. 2, pp. 1-26, 2022. [7] M. Guri, “Power-supplay: Leaking sensitive data from air-gapped, audio-gapped systems by turning the power supplies into speakers”, in Proc.IEEE Trans. Depend. Secure Comput., vol. 20, no. 1, pp. 313-330, 2021. [8] M. Guri et al., “Mosquito: Covert ultrasonic transmissions between two air-gapped computers using speaker-to-speaker communication”, in Proc. 2018 IEEE Conference on Dependable and Secure Computing (DSC), pp. 1-8, 2018. [9] M. Guri et al., “Fansmitter: Acoustic data exfiltration from (speakerless) air-gapped computers”, arXiv preprint arXiv:1606.05915, 2016. [10] M. Hanspach and M. Goetz, “On covert acoustical mesh networks in air”, arXiv preprint arXiv:1406.1213, 2014. |
|||||
| Next | Sejong University researchers claim breakthrough in faster-charging battery tech | ||||
| Previous | General 3D method to accurately measure gravity in wide binary stars is developed and demonstrated by a pilot study | ||||