Hardware security specialists with cyber security provider F-Secure have published a report detailing their investigation into a pair of counterfeit network switches.
The investigation, which concluded that the counterfeits were designed to bypass processes that authenticate system components, illustrates the security challenges posed by counterfeit hardware.
F-Secure Consulting’s hardware security team investigated two different counterfeit versions of Cisco Catalyst 2960-X series switches. The counterfeits were discovered by an IT company after a software update stopped them from working, which is a common reaction of forged/modified hardware to new software.
At the company’s request, F-Secure Consulting performed a thorough analysis of the counterfeits to determine the security implications.
The investigators found that while the counterfeits did not have any backdoor-like functionality, they did employ various measures to fool security controls. For example, one of the units exploited what the research team believes to be a previously undiscovered software vulnerability to undermine secure boot processes that provide protection against firmware tampering.
“We found that the counterfeits were built to bypass authentication measures, but we didn’t find evidence suggesting the units posed any other risks,” says Dmitry Janushkevich, a senior consultant with F-Secure Consulting’s hardware security team, and lead author of the report. “The counterfeiters’ motives were likely limited to making money by selling the devices. But we see motivated attackers use the same kind of approach to stealthily backdoor companies, which is why it’s important to thoroughly check any modified hardware.”
The counterfeits were physically and operationally similar to an authentic Cisco switch. One of the unit’s engineering suggests that the counterfeiters either invested heavily in replicating Cisco’s original design or had access to proprietary engineering documentation to help them create a convincing copy.
According to F-Secure Consulting’s Head of Hardware Security Andrea Barisani, organisations face considerable security challenges in trying to mitigate the security implications of sophisticated counterfeits such as the those analysed in the report.
“Security departments can’t afford to ignore hardware that’s been tampered with or modified, which is why they need to investigate any counterfeits that they’ve been tricked into using,” explains Barisani. “Without tearing down the hardware and examining it from the ground up, organizations can’t know if a modified device had a larger security impact.
“And, depending on the case, the impact can be major enough to completely undermine security measures intended to protect an organization’s security, processes, infrastructure, etc.”
F-Secure advises organisations to prevent themselves from using counterfeit devices, and offers these tips:
* Source devices from authorised resellers;
* Have clear internal processes and policies that governing procurement processes;
* Ensure all devices run the latest available software provided by vendors; and
* Make note of even physical differences between different units of the same product, no matter how subtle they may be.