File:A Wolf in Sheep’s Clothing - Spreading Deadly Pathogens Under the Disguise of Popular Music.pdf

From Wikimedia Commons, the free media repository
Jump to navigation Jump to search
Go to page
next page →
next page →
next page →

Original file(1,275 × 1,650 pixels, file size: 2.17 MB, MIME type: application/pdf, 15 pages)

Captions

Captions

A Wolf in Sheep's Clothing: Spreading Deadly Pathogens Under the Disguise of Popular Music

Summary[edit]

Description
English: A Negative Pressure Room (NPR) is an essential requirement by the Bio-Safety Levels (BSLs) in biolabs or infectious-control hospitals to prevent deadly pathogens from being leaked from the facility. An NPR maintains a negative pressure inside with respect to the outside reference space so that microbes are contained inside of an NPR. Nowadays, differential pressure sensors (DPSs) are utilized by the Building Management Systems (BMSs) to control and monitor the negative pressure in an NPR. This paper demonstrates a non-invasive and stealthy attack on NPRs by spoofing a DPS at its resonant frequency. Our contributions are: (1) We show that DPSs used in NPRs typically have resonant frequencies in the audible range. (2) We use this finding to design malicious music to create resonance in DPSs, resulting in an overshooting in the DPS's normal pressure readings. (3) We show how the resonance in DPSs can fool the BMSs so that the NPR turns its negative pressure to a positive one, causing a potential leak of deadly microbes from NPRs. We do experiments on 8 DPSs from 5 different manufacturers to evaluate their resonant frequencies considering the sampling tube length and find resonance in 6 DPSs. We can achieve a 2.5 Pa change in negative pressure from a ~7 cm distance when a sampling tube is not present and from a ~2.5 cm distance for a 1 m sampling tube length. We also introduce an interval-time variation approach for an adversarial control over the negative pressure and show that the forged pressure can be varied within 12 - 33 Pa. Our attack is also capable of attacking multiple NPRs simultaneously. Moreover, we demonstrate our attack at a real-world NPR located in an anonymous bioresearch facility, which is FDA approved and follows CDC guidelines. We also provide countermeasures to prevent the attack.
Date
Source https://dl.acm.org/doi/10.1145/3548606.3560643
Author Anomadarshi Barua, Yonatan Gizachew Achamyeleh, and Mohammad Abdullah Al Faruque

doi:10.1145/3548606.3560643

Licensing[edit]

w:en:Creative Commons
attribution
This file is licensed under the Creative Commons Attribution 4.0 International license.
You are free:
  • to share – to copy, distribute and transmit the work
  • to remix – to adapt the work
Under the following conditions:
  • attribution – You must give appropriate credit, provide a link to the license, and indicate if changes were made. You may do so in any reasonable manner, but not in any way that suggests the licensor endorses you or your use.

File history

Click on a date/time to view the file as it appeared at that time.

Date/TimeThumbnailDimensionsUserComment
current16:22, 25 November 2022Thumbnail for version as of 16:22, 25 November 20221,275 × 1,650, 15 pages (2.17 MB)Koavf (talk | contribs)Uploaded a work by Anomadarshi Barua, Yonatan Gizachew Achamyeleh, and Mohammad Abdullah Al Faruque from https://dl.acm.org/doi/10.1145/3548606.3560643 with UploadWizard

The following page uses this file:

Metadata