Emerging Tech: Security — The Need for Wireless Airspace Cybersecurity
Download now▶Dr. Bob Baxley, Chief Scientist at Bastille Networks discusses "FCC Device Data"
Every device sold in the United States that transmits wirelessly carries an FCC ID, and behind that ID sits a public file of certification test reports. Those reports exist to prove the device stays within legal emission limits — but they also document, in detail, exactly how the device uses the spectrum: which frequencies, which protocols, which packet formats, and how it behaves under test.
In this talk, Bastille Chief Engineer Dr. Bob Baxley walks through the FCC device database as a research resource: what’s in it, how security researchers have used it to reverse-engineer wireless protocols, and what emerges when the entire dataset is scraped, parsed, and plotted by frequency and equipment class.
The point is not that this data is secret — it is public domain, and anyone can read it. The point is that it dramatically lowers the effort required to understand and attack a wireless protocol, and it is equally valuable to the defenders building sensors that need to recognize those protocols in the field.
Open up almost any wireless device and you’ll find an FCC ID printed on the case or inside the battery compartment. To obtain that ID, the manufacturer had to submit the device to a certification lab. The certification confirms two things: that the device operates within the legal limits of wireless emissions — it doesn’t transmit too much power — and that it only transmits in permitted, unlicensed spectrum.
The test reports generated during that certification process are sent to the FCC, which logs them in a public database. Anyone can search it, view the filings, and use them.
An iPhone has its FCC ID printed clearly on the back. Type that ID into the database and you get a full record of the device’s radio behavior:
For an IT security person, a researcher, or an attacker, the value is straightforward: those documents describe how the device uses the wireless spectrum. What protocols it speaks, what the packets look like, what the formats are. That is normally the hardest and slowest part of attacking a proprietary wireless system, and here it is handed over in a certification filing.
The same kind of information also turns up in patent filings, which are likewise public domain. Between the two sources, a proprietary protocol is often far less opaque than its vendor assumes.
Bastille security researcher Logan Lamb used exactly this approach against home security systems, which rely on wireless door sensors and other wireless components. By reading the FCC documentation, he was able to understand precisely how the protocol worked, which made it far easier to demonstrate its vulnerabilities.
The result was demonstrated on Good Morning America: using a software defined radio to spoof the wireless protocol, he transmitted a signal telling the alarm panel the door was still closed even as the door was opened. In practice, that means walking into a building without the alarm ever going off.
That’s one example of what the FCC dataset makes possible — and a reminder that “proprietary” is not a security property when the protocol is documented in a public filing.
Individual lookups are useful, but the database becomes something else entirely when you take all of it. Bastille scraped the full set of FCC device data, categorized it, and parsed it by frequency and by usage, then built a portal for slicing through it.
In that tool, the x-axis is frequency and the y-axis is the device equipment class as classified by the FCC. Supporting panels show device metadata as described by the FCC, the manufacturer, and related details. Highlight a frequency range and the tool filters to the device types that live there.
Highlight 900 MHz and the expected devices appear — 900 MHz cordless phones, in several varieties. Less expected: paging receivers and satellite equipment also occupy that space. This is the kind of context that helps interpret what a sensor is actually seeing in the field.
A visible cluster of devices with similar equipment classes sits between roughly 300 and 500 MHz. Highlight that region and it resolves into remote control transmitters: RC cars, key fobs, and automotive security system transmitters. The manufacturers are exactly who you’d expect — companies like Honeywell and Chamberlain.
Highlight 2.4 GHz and everything else filters out, leaving Wi-Fi and Bluetooth devices: computers, tablets, phones, Bluetooth headsets, Bluetooth speakers. Zoom in on manufacturers and Apple and Samsung dominate — again, exactly what you’d expect.
The interesting findings come from spending more time in the data. Digging into particular equipment classes at particular frequencies starts surfacing counterintuitive devices — things you wouldn’t expect to be transmitting where they are.
For a wireless security team, the FCC dataset serves two purposes. It provides the protocol detail needed to build and validate detection for device families that ship no public specification — an essential input when a sensor has to recognize a proprietary protocol from the physical layer up. And it provides a map of the spectrum by device class, which helps interpret what a sensor observes: given an emitter at this frequency with this behavior, what class of device is it likely to be?
It is also a reminder about threat modeling. Any attacker targeting a wireless device in your environment starts with the same public filings. Obscurity buys nothing; visibility into what is actually transmitting in your facility is what matters.
Hi, welcome to this talk on FCC device data. My name’s Bob Baxley and I’m the Chief Engineer at Bastille, where I lead the radio and data science teams. In this talk I want to give you a feeling for the kinds of data behind the FCC ID, and how that data can be used to do all kinds of things.
I’ve got a screenshot of the FCC’s website that lets you search for FCC device data. What you’re actually searching for — I’ll just use this wireless device as an example — is the FCC ID printed on the device. When I open up the back, there’s an FCC ID printed there.
For the manufacturer to get that FCC ID for this device, they had to have it certified by a lab. The certification says the device operates within the legal limits of wireless emissions — so it doesn’t transmit too much power, and it only transmits in unlicensed spectrum. The test reports from that certification process get sent to the FCC, and the FCC logs them in this database, where it’s public domain data. So you can view them; anyone can use them.
Here’s a picture of an iPhone, and the FCC ID is printed clearly on the back of the iPhone. If you type that FCC ID into the database, you get an interface that looks like this. In the screenshot on the left you can see all the frequencies that iPhone operates in, since the iPhone talks on several different cellular carrier frequencies, plus Bluetooth, Wi-Fi, NFC — there are lots of radio standards that it utilizes. And then you also see these really cool test pictures. That’s an iPhone held up in the operating position, and they’re assessing the emission pattern from the iPhone. So it’s super cool data. There are literally dozens and dozens of independent PDFs that you can get for almost any device that transmits wirelessly.
One reason that’s interesting, if you’re an IT security person — or a hacker, or a researcher — is that in those documents it’s documented how this device uses the wireless spectrum. What protocols it uses, the packets, the formats, all those things. That kind of information can also be found in patent filings, which are also public domain.
We’ve got a picture of Logan Lamb, one of our security researchers. He was able to use the FCC documentation for home security systems, which have wireless door sensors and wireless components. He was able to look at the documents and understand exactly how the protocol worked, which made it much easier to demonstrate some of the vulnerabilities in this protocol.
There’s another screenshot of him on Good Morning America, where he demonstrated the ability to take a radio that was spoofing the wireless protocol of the wireless home security system and basically transmit the signal that says the door’s still closed, even as the door was open. What that means is he would be able to walk into the building without the alarm going off. So, super cool — and that’s just one example of the sorts of things that you can do with the FCC data.
Another example: I want to show you a demo where we’ve scraped all this FCC data and categorized it, parsed it by frequency and by usage. We’ve got this really neat portal where we can slice and dice it. So let me show you that demo right now.
Again, we’ve scraped all the FCC device data. In the plot here, the x-axis is frequency and the y-axis is the device equipment class as classified by the FCC. In the lower left I have metadata about the devices as described by the FCC, the middle is the manufacturer, and the bottom right has additional detail.
What we can do with this tool is highlight certain frequency ranges and see what types of devices are in those ranges. So we highlight the 900 megahertz band here. What do we see? Well, we’d expect to see things like 900 megahertz cordless phones, and of course that’s what we see — on the lower left you can see several different types of cordless phones. What’s also interesting is to see paging receivers and satellites. This is the sort of tool that helps us understand what we’re seeing with our sensors.
When I click away from that and reset it, the next thing I’m going to highlight is this little cluster of devices. As you can see, they have similar equipment classes, and they’re from about 300 to 500 megahertz. If I highlight that region right there, we see remote control transmitters. This is where RC car remote controls live. This is where key fobs live, and automotive security system transmitters. All those sorts of things live in this little block of frequencies and classes, and you can see companies like Honeywell and Chamberlain make these sorts of devices — which is what you would expect.
For the last example, I’m going to highlight the 2.4 band. There we would expect to see devices that have Wi-Fi and Bluetooth, so those devices will be things like computers, and tablets, and phones. I’m going to highlight it, it’s going to filter everything out, and of course we see that — we see Bluetooth headsets, Bluetooth speakers, tablet PCs. If you zoom in on the manufacturers, you can see companies like Apple and Samsung make these devices. So exactly the sorts of things you would expect.
But if you spend a little bit more time with this, digging into the particular classes at particular frequencies, you start seeing kind of counterintuitive things — things you wouldn’t expect. So it’s a really, really neat tool. Thanks for listening. My name’s Bob Baxley and I’m with Bastille.
Learn how Bastille can help you prepare you for today’s ever-growing wireless threat landscape, and schedule a demo and we’ll be in touch shortly.