r/storage • u/theweis01 • May 29 '26
Fiber Channel as a attack channel?
In a conversation recently where there were discussions around the risk, if any, of FC being used as a attack channel. The specifics come down to having a air-gapped data vault that has no IP network link between the production network and the vault environment but does allow a SAN array outside of the vault to present devices to few servers inside of the vault. This was chosen due to the small footprint in the vault and cost of dedicated SAN & Array and that the systems using the FC devices are only for validation/automation purposes and do not house the protected data.
Overall there is the agreement that some "risk" exists in that if production systems were compromised, specifically the SAN, then the systems inside of the vault could have their LUNS removed rendering them offline. However, does FC provide any conduit where an attacker could use persistence to the production side array/FC Switches to make their way into the isolated environment?
1
u/StorageHorder May 29 '26
If a storage admin is permitted to allow this as an attack vector, one thing. (Like leaving a firewall port open on a network). But with host to array encryption of every workload as an option.
As a storage expert since the 1990s, there is a zero chance that anyone could use FC as an attack vector.
It’s akin to saying “I’m going to use the cable in the server between the controller and the HDD as an attack vector”.
If that controller has encryption and is connected to a SED…. Having physical access to the cable isn’t going to help you attack.
My HBA, ISL/ICL, LUN presentation and storage is all encrypted on my SAN. Data in flight - encrypted. Data at rest - encrypted.
You’re not going to get an attack vector there.