🤖 AI Summary
Conventional wisdom holds that high-speed Ethernet standards such as 100BASE-TX are inherently resistant to electromagnetic eavesdropping due to their weak emanations. This work proposes a novel hardware Trojan attack based on passive radio-frequency retroreflection, successfully extending such attacks to high-speed Ethernet for the first time. By constructing a miniature retroreflector from discrete components and integrating it with an MLT-3 signal recovery and interference-resilient demodulation-decoding pipeline, the method enables remote and covert data exfiltration from 100BASE-TX links. Experimental results demonstrate that the approach effectively reconstructs Fast Ethernet communication content, overcoming the prior limitation of retroreflection-based attacks to low-speed or video interfaces and establishing their practical feasibility in high-speed networking environments.
📝 Abstract
Electromagnetic eavesdropping is a well-established attack vector for remotely monitoring a target activity, most notably displays, over considerable ranges. Other targets have been considered resistant to such attacks or do not exhibit sufficient electromagnetic leakage for practical exploitation. Radio-frequency retroreflector attacks (RFRA) were developed to enable covert, active monitoring of a target by implanting a minimal hardware Trojan. These implants, typically implemented using discrete components such as transistors or diodes, do not betray their presence by emitting signals themselves; rather, they modulate the electromagnetic reflectivity of the target depending on the probed signal line data. Prior RFRA work has demonstrated their viability against video links and low-speed peripheral interfaces. In this work, we extend the applicability of RFRA to high-speed targets by presenting a successful attack on the 100BASE-TX Ethernet standard. We describe the design and realization of a compact implant capable of recovering the MLT-3 encoded signaling used in Fast Ethernet, as well as a dedicated demodulation and interpretation pipeline that mitigates errors introduced by the radio channel and maximizes the amount of recovered information. Experimental results validate the feasibility of covertly monitoring Fast Ethernet traffic using RF retroreflection and highlight the viability of such attacks for high-speed links.