Users Really Do Plug in USB Drives They Find
Matthew Tischer, Zakir Durumeric, Sam Foster, Sunny Duan, Alec Mori, Elie Bursztein, Michael D. Bailey
Abstract
We investigate the anecdotal belief that end users will pick up and plug in USB flash drives they find by completing a controlled experiment in which we drop 297 flash drives on a large university campus. We find that the attack is effective with an estimated success rate of 45-98% and expeditious with the first drive connected in less than six minutes. We analyze the types of drives users connected and survey those users to understand their motivation and security profile. We find that a drive's appearance does not increase attack success. Instead, users connect the drive with the altruistic intention of finding the owner. These individuals are not technically incompetent, but are rather typical community members who appear to take more recreational risks than their peers. We conclude with lessons learned and discussion on how social engineering attacks -while less technical -continue to be an effective attack vector that our community has yet to successfully address.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 3e8a85d1-d2a4-4a9f-bd7e-53a503a202a0Cited by top-tier papers11
- An Experimental Security Analysis of an Industrial Robot ControllerDavide Quarta, Marcello Pogliani, Mario Polino, Federico Maggi et al.S&P 2017 · 169 citations
- FirmUSB: Vetting USB Device Firmware using Domain Informed Symbolic ExecutionGrant Hernandez, Farhaan Fowze, Dave (Jing) Tian, Tuba Yavuz et al.CCS 2017 · 98 citations
- Making USB Great Again with USBFILTERDave (Jing) Tian, Nolen Scaife, Adam Bates, Kevin R. B. Butler et al.USENIX Security 2016 · 56 citations
- Users Really Do Answer Telephone ScamsHuahong Tu, Adam Doupé, Ziming Zhao, Gail-Joon AhnUSENIX Security 2019 · 53 citations
- SoK: "Plug & Pray" Today - Understanding USB Insecurity in Versions 1 Through CJing (Dave) Tian, Nolen Scaife, Deepak Kumar, Michael D. Bailey et al.S&P 2018 · 52 citations
Related papers
- Towards Measuring and Mitigating Social Engineering Software Download AttacksTerry Nelms, Roberto Perdisci, Manos Antonakakis, Mustaque AhamadUSENIX Security 2016 · 70 citations
- The Kids Are All Right: Investigating the Susceptibility of Teens and Adults to YouTube Giveaway ScamsElijah Robert Bouma-Sims, Lily Klucinec, Mandy Lanyon, Julie Downs et al.NDSS 2025
- Dial One for Scam: A Large-Scale Analysis of Technical Support ScamsNajmeh Miramirkhani, Oleksii Starov, Nick NikiforakisNDSS 2017 · 116 citations
- Empirical Understanding of Deletion Privacy: Experiences, Expectations, and MeasuresMohsen Minaei, Mainack Mondal, Aniket KateUSENIX Security 2022
- USB Snooping Made Easy: Crosstalk Leakage Attacks on USB HubsYang Su, Daniel Genkin, Damith Chinthana Ranasinghe, Yuval YaromUSENIX Security 2017 · 41 citations
