Top Banner
SPREAD SPECTRUM SATCOM HACKING ATTACKING THE GLOBALSTAR SIMPLEX DATA SERVICE Colby Moore @colbymoore - [email protected]
89

Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

Aug 18, 2015

Download

Technology

Synack
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

SPREAD SPECTRUM SATCOM HACKING

ATTACKING THE GLOBALSTAR SIMPLEX DATA SERVICE

Colby Moore@colbymoore - [email protected]

Page 2: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

WHO AM I?

Colby MooreSynack R&D

KD7SCT

Page 3: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service
Page 4: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

INTRODUCTION

Page 5: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

MOTIVATION

• Try something new

• Satellite hacking often too theoretical

• Unexplored frontier

• Systems are hopelessly broken

• Inspire and collaborate

Page 6: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

WHAT ARE WE GOING TO LEARN?

• RF signals and modulation

• What is spread spectrum?

• Selecting a target and reverse engineering

• Exploiting the target

Page 7: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

PREREQUISITES

• High school mathematical knowledge

• Lets keep things relatively “understandable”

• Will provide resources (see github)

Page 8: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

TARGETING

Page 9: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

SELECTING A TARGETG

over

nmen

tC

omm

erci

al

Page 10: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

• SPOT - Consumer grade satellite tracking

• Aging satellite network: voice, data, messaging

• But wait… this tech is used everywhere. Jackpot.

Page 11: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

WHERE IS IT USED?Military / Classified

Trailers / Containers Air Quality Monitoring

Personnel Tracking Fire Detection and Prevention

Water Quality Monitoring Tank Level Gauging

Perimeter / Border monitoringAsset / Vehicle Tracking

Remote Meters Buoys

Ship Movement Fishing vessel monitoring Power line monitoring

Dispersed sensorsand many more…

Page 12: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

SIMPLEX DATA NETWORK

“Simplex works where infrequent, small packets of data are to be collected”

GPS Satellite

Asset

Globalstar Satellite

Globalstar Ground StationThe Internet

Globalstar Infrastructure

User Infrastructure

Page 13: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

BENT PIPE

“A bent pipe satellite does not demodulate or decode the signal. A gateway station on the ground is

necessary to control the satellite and route traffic to and from the satellite and to the internet.”

Page 14: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

REDUNDANCY• Yes, the network only talks in one direction (simplex)

• How is this reliable?

Page 15: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

GROUND STATIONS AND COMMAND CENTERS

Hundreds of ground stations Two Operations Centers

Page 16: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

COVERAGE

48 satellites - 5850 km diameter footprint - 1410 km orbit - In service since 2000

Page 17: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

SECURITY POSTURE

Page 18: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

“Error 100: Database query failed - retrieving login information You have an error in your

SQL Syntax;…”

NOT SO MUCH…

Page 19: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

–Globalstar

“The received data is then forwarded to a user defined network interface that may be in the form of an FTP

host or HTTP host where the user will interpret the data for further processing.”

Page 20: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

INTELLIGENCE GATHERING

Page 21: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

WHERE TO LOOK

Page 22: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

PRIOR RESEARCH

Travis Goodspeedhttps://github.com/travisgoodspeed/pyspot

Natrium42https://web.archive.org/web/20120202211125/

http://natrium42.com/projects/spot/

Page 23: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

STX-3“Worlds’ smallest and lowest power consuming industrial-

use satellite transmitter”

DSSS? BPSK? What the &^#% is that?…

Page 24: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

FREQUENCIES

Globalstar L-Band Frequencies

Globalstar Simplex Data Frequencies

Page 25: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

THE BREAKTHROUGH

Clues!

Page 26: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

REVIEW OF WAVES AND MODULATION

Page 27: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

WAVES

Amplitude - APhase - φ (radians)

Time (t)

Wavelength

Page 28: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

TIME DOMAIN VS. FREQUENCY DOMAIN

Frequency DomainTime Domain

Am

plit

ude

Time

Frequency

Page 29: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

ANALOG MODULATION

• Amplitude Modulation (AM)

• Frequency Modulation (FM)

Page 30: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

AMPLITUDE MODULATION

Carrier

Modulating Signal (Data)

Modulated Signal

Page 31: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

FREQUENCY MODULATION

Carrier

Modulating Signal (Data)

Modulated Signal

Page 32: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

DIGITAL MODULATION

• Amplitude Shift Keying (ASK / OOK)

• Frequency Shift Keying (FSK)

• Phase Shift Keying (PSK)

Page 33: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

PHASE SHIFT KEYING (PSK)

Modulated Signal

Modulating Signal (Data)

0 0 1 1 0 1 1 1

0˚ 180˚ 0˚ 180˚

BPSK - Two phases (0 and 180 degrees) are used to represent 1 and 0

Page 34: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

SPREAD SPECTRUM

Page 35: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

SPREAD SPECTRUM MODULATION

• Why is Spread Spectrum special?

• WiFi, Bluetooth, GPS, and basically all modern RF communications

• Processing Gain

• Jam Resistant

• CDMA

Page 36: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

SPREAD SPECTRUM MODULATION

• Frequency Hopping Spread Spectrum (FHSS)

• Direct Sequence Spread Spectrum (DSSS)

Page 37: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

DIRECT SEQUENCE SPREAD SPECTRUM (DSSS)

• Mixes a slow signal with fast pseudo-random signal

• Signal still contains original information but occupies much more bandwidth.

BPSK SignalOccupies ~100Hz

Spread BPSK SignalOccupies ~1.25Mhz

Page 38: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

DSSS CONTD.Data Signal

Pseudo Random

Result

000000000000 111111111111

110001111001 010000101000

110001000110 010000010111⊕

Page 39: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

DSSS CONTD.

Data Signal

Pseudo RandomResult

000000000000 111111111111

110001111001 010000101000110001000110 010000010111

Page 40: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

M-SEQUENCES AS PN CODES

• Periodic binary codes that have strong autocorrelation properties

• Commonly generated with LFSRs

Page 41: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

M-SEQUENCES AND CORRELATION

0001 0001

0001 0010

0001 0100

0001 1000

4 0 0 0

M-Sequence:

Shifted:

Correlation:

This makes looking for the m-sequence in a signal easy!

Page 42: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

DECODING THEORY

• Simple in practice. More difficult in theory

• Mix incoming signal with PN sequence and the original BPSK signal will emerge.

• Compensate for frequency differential between local and remote oscillators

• Signal needs to be phase aligned with PN code

Page 43: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

HARDWARE

Page 44: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

TOOLS AND HARDWARE

USRP B200$675

GSP-1620 LHCP Antenna$65

Page 45: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

MORE HARDWARE

Dimension Engineering AnyVolt 3$55

12v AC/DC Adapter$5SMA Cables

$20

MiniCircuits ZX60-1614LN-SLow Noise Amplifier

$150

Page 46: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

ASSEMBLED CAPABILITY

Page 47: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

SAMPLINGNyquist: Sample at least twice as fast as the signal’s

fastest frequency.

The human ear can’t hear frequencies higher than 20Khz.CD audio is sampled at 44.1Khz (twice the human range).

Page 48: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

IQ MODULATION• Makes generation of signals easy in software!

https://www.youtube.com/watch?v=h_7d-m1ehoYBasics of IQ Signals and IQ modulation & demodulation - A tutorial

Page 49: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

PN RECOVERY

Page 50: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

WHAT TO EXPECT

• Pseudo random sequence (1s and 0s)

• Repeating

• 255 bits long

• 1.25 million “chips” per second

Much like Bart in detention, the PN will repeat over and over and over…

Page 51: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

PN RECOVERY• In order to decode the signal, we need to know the PN sequence

• DSSS BPSK == BPSK

BPSK DSSS

BPSK

Low

Fre

quen

cyH

igh

Freq

uenc

y

Page 52: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

SAMPLING REQUIREMENTS 32 Mhz ———— = 4 Mhz (> 1.25 x 2) 8 Mhz > 2x faster than 1.25 Mhz (Nyquist)

Even multiple of 32 Mhz (USRP)

4 Mhz 3.2 samples—————— = —————— (not even) 1.25 Mcps 1 symbol

4 Mhz 5 4 samples—————— x —— = —————

1.25 Mcps 4 symbol

Even samples / symbol (Implementation Specific)

*We can resample the signal from 4 to 5 Mhz.

*

Page 53: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

PN RECOVERY• PN Sequence is much shorter than bit length

• PN repeats 49 times for each bit

• PN ⊕ Data == PN (within a bit boundary)

1,250,000 chips 1 second 1 PN seq. 49 PN seq.———————— x —————— x ————— = ————— 1 second 100.04 bits 255 chips 1 bit

Page 54: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

PN RECOVERY

Page 55: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

PN RECOVERY111111110010110101101110101010111001001101101001100110100011101101100010001001111010010010000111100010100111000111110101111001110100001010110010100010110000011001000110000110111111011100001000001001010100101111100000011100110001101010000000101110111101100

Page 56: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

DESPREADING

Page 57: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

WHAT TO EXPECT

• Mix original signal with PN

• Narrow band signal will emerge

• Shown as sharp spike on FFT

Page 58: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

REALTIME IS HARD• Unfortunately doing this is very computational intensive

• Lots of room for optimizations

• Record now, process later

sh-­‐3.2#  time  python  sync.py  

real   0m58.326s  user   0m48.754s  sys        0m0.909s

1.4 second capture (one packet)

4M samp/sec * 2 floats/samp * 4 bytes/float = 30.5 MB/sec

Page 59: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

CORRELATIONC

orre

lati

on

Time

Slide PN against data and correlate at each step.

Page 60: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

CODE TRACKING

Time (samples)

Cor

rela

tion

Correlation Peak

If we don’t compensate for misalignment, we will drift and lose correlation over time.

Search for peaks, and track

themStrong Correlation (PN aligned)

No Correlation (PN unaligned)

Early

Late

Aligned

Page 61: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

CODE TRACKING

Time (samples)

Cor

rela

tion

Early or late detection lets us keep track.

Positive and negative correlations indicate bits!

Consistent Correlation (PN aligned)

Page 62: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

DESPREAD SIGNAL

It works!

Mix the PN against the signal. Original signal appears.

Page 63: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

DECODING

Page 64: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

EXTRACTING DATA

Low Pass Filter

Rational Resampler

PSK Demodulator

Decoder

Signal

Time Domain

Frequency Domain

10100 0 0111 ……

Page 65: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

PACKET FORMAT000000101100101001101100011110100000010100000000010011110000000100000010000010000000000000000100000000000000000000000000000011001000001010010011

001 01001101100011110100000Manufacturer ID Unit ID

Page 66: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

LOCATION DECODINGLatitude: bits 8:32Longitude: bits 32:56 + -

Latitude Northern Hemisphere

Southern Hemisphere

Longitude Eastern Hemisphere

Western Hemisphere

Convert to decimal(signed int MSB to LSB)

Multiply by degrees per count

1.

2.

3.

Page 67: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

CHECKSUM

Packet (without preamble and CRC)110 bits

CRC

(Code Provided)Compare

If we known how to reproduce the checksum, we can create our own packets… no signing, no encryption, lets spoof!

000000101100101001101100011110100000010100000000010011110000000100000010000010000000000000000100000000000000000000000000000011001000001010010011

24 bits

Page 68: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

INTERCEPTING ON DOWNLINK

• Bigger antennas and better equipment

• RF downconversion

• Doppler Shift

• Multipath

Worst Case Doppler Shift

Page 69: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

TRANSMITTING

Page 70: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

DISCLAIMER

Transmitting on Globalstar’s frequencies may be illegal where you live and could interfere with critical communications.

Do no

t do

this! Seriously, don’t.

No one likes late night visits from the FCC.

Page 71: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

TRANSMITTING

MGA-2000 0.5W RF Amplifier$190.00

But if you like late night visits from the FCC…

• This is actually the easy part.

• ~.2 Watts power

• Simply mix data, PN, and carrier and correct rates

Page 72: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

BUT WAIT… ITS EASIER

Spot Device Updater SPOT3FirmwareTool.jar

Currently $49.99

Page 73: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

DOES IT WORK?

Spot Trace1 Spot Trace 2

Clone

Page 74: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

IMPACT

Page 75: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

EMERGENCY RESPONSE

Real Emergency

Fake Emergency

Overwhelm emergency response center anonymously?

Page 76: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

WHERE ELSE?

Page 77: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

BUT WAIT, THERE’S MORE

Lockheed Martin Flight Service (LMFS) Integration

Page 78: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

CAPABILITY

Page 79: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

Uplink Interception

RF Beam

GlobalstarAttacker

Attacker intercepts andplots pattern of life

Page 80: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

SPOOFING LOCATION

Planned Route

Hijack Route

Attacker hijacks truck, disables tracker, transmits location as if delivery is on

track.

False

Loca

tion D

ata

Page 81: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

TESTING THE CAPABILITY

Reception Window

Page 82: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

DEMO

Video demo time. It’s better to not tempt the demo gods. ;)

Page 83: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

CONCLUSIONS

Page 84: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

"Like all companies and industries in the 21st century, including those that Wired reported on this week to expose hacking vulnerabilities like Chrysler, GM, Brinks

and others, Globalstar monitors the technical landscape and its systems to protect our customers. Our engineers would know quickly if any person or entity was

hacking our system in a material way, and this type of situation has never been an issue to date. We are in the business of saving lives daily and will continue to

optimize our offerings for security concerns and immediately address any illegal actions taken against our Company."

DISCLOSURE & RESPONSE• ~180 days ago

• Friendly and concerned for user privacy, but no further communication

Page 85: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

NEXT STEPS

• Collaboration

• Code optimization - realtime

• Downlink interception

• Data aggregation

Page 86: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

CONCLUSIONS

• Long lifecycle

• Unpatchable

• Security going forward

• DSSS != security

• Assume Insecure

• Act accordingly

• Higher standards

Page 87: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

SPECIAL THANKS

Alex K., Chris W., Cyberspectrum Meetup, David C., Michael Ossmann, Mom and Dad, Paul David, Tom Rondeau

The Interns

and

Page 88: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

QUESTIONS / COMMENTS?

https://github.com/synack/globalstar

https://syn.ac/bh15satcom

@colbymoore

[email protected]

code

slides

twitter

email

Page 89: Black Hat '15: Spread Spectrum Satcom Hacking: Attacking The GlobalStar Simplex Data Service

IMAGE CREDITS

• http://images.google.com