USB-Sentinel: A Generalized AIO Software-Assisted Insider Threat Detection Framework
摘要
The research paper titled “USB-Sentinel: A Generalized AIO Software-Assisted Insider Threat Detection Framework” offers a solution to safeguard computers against hardware hacking attacks involving USB devices. One such device, the USB rubber ducky, resembles a regular USB flash drive but possesses sophisticated capabilities to execute a “man-in-the-middle (MITM)” attack. By injecting keystrokes rapidly, the attacker can remotely gain control over the system and potentially pilfer sensitive information. While the prevailing method of preventing USB rubber ducky attacks involves configuring the operating system to block unknown USB devices, the USB-Sentinel framework adopts a comprehensive approach. This cross-platform application utilizes its own sophisticated AI algorithm to counter USB-based attacks by identifying and blocking keystroke injection speed, User Account Control (UAC) prompts, and USB storage access. The algorithm is initially trained based on user behavior to enhance computer protection against USB attacks. Effective prevention also entails physical security measures such as computer locking and restricted access, along with technological measures like disabling auto run and implementing strong passwords. Educating users about USB device risks and device verification before usage is crucial. Regular security audits and penetration testing contribute to vulnerability identification and attack prevention. By implementing these multifaceted measures and maintaining vigilance, organizations can significantly reduce the risk of successful USB rubber ducky attacks.