USBIPS Framework: Protecting Hosts from Malicious USB Peripherals
Chun-Yi Wang, Fu-Hau Hsu

TL;DR
This paper introduces USBIPS, a comprehensive security framework for Windows OS that combines allowlisting, behavior detection, and cross-layer methods to protect against malicious USB peripherals and intrusions.
Contribution
It presents the first generic security framework integrating multiple detection strategies to defend against USB-based attacks in Windows OS.
Findings
Effective detection of malicious USB behavior
Persistent protection against USB intrusions
Enhanced security with minimal performance impact
Abstract
Universal Serial Bus (USB)-based attacks have increased in complexity in recent years. Modern attacks incorporate a wide range of attack vectors, from social engineering to signal injection. The security community is addressing these challenges using a growing set of fragmented defenses. Regardless of the vector of a USB-based attack, the most important risks concerning most people and enterprises are service crashes and data loss. The host OS manages USB peripherals, and malicious USB peripherals, such as those infected with BadUSB, can crash a service or steal data from the OS. Although USB firewalls have been proposed to thwart malicious USB peripherals, such as USBFilter and USBGuard, their effect is limited for preventing real-world intrusions. This paper focuses on building a security framework called USBIPS within Windows OSs to defend against malicious USB peripherals. This…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAdvanced Malware Detection Techniques · User Authentication and Security Systems · Digital and Cyber Forensics
