USENIX Security2017Top-tier venue
USB Snooping Made Easy: Crosstalk Leakage Attacks on USB Hubs
Yang Su, Daniel Genkin, Damith Chinthana Ranasinghe, Yuval Yarom
Abstract
The Universal Serial Bus (USB) is the most prominent interface for connecting peripheral devices to computers. USB-connected input devices, such as keyboards, cardswipers and fingerprint readers, often send sensitive information to the computer. As such information is only sent along the communication path from the device to the computer, it was hitherto thought to be protected from potentially compromised devices outside this path. We have tested over 50 different computers and external hubs and found that over 90% of them suffer from a crosstalk leakage effect that allows malicious peripheral devices located off the communication path to capture and observe sensitive USB traffic. We also show that in many cases this crosstalk leakage can be observed on the USB power lines, thus defeating a common USB isolation countermeasure of using a charge-only USB cable which physically disconnects the USB data lines. Demonstrating the attack's low costs and ease of concealment, we modify a novelty USB lamp to implement an off-path attack which captures and exfiltrates USB traffic when connected to a vulnerable internal or a external USB hub.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 6452612d-88fd-45c4-b841-506fe0bbaf97Cited by top-tier papers16
- Synesthesia: Detecting Screen Content via Remote Acoustic Side ChannelsDaniel Genkin, Mihir Pattani, Roei Schuster, Eran TromerS&P 2019 · 63 citations
- Charger-Surfing: Exploiting a Power Line Side-Channel for Smartphone Information LeakagePatrick Cronin, Xing Gao, Chengmo Yang, Haining WangUSENIX Security 2021 · 62 citations
- SoK: Keylogging Side ChannelsJohn V. MonacoS&P 2018 · 56 citations
- SoK: "Plug & Pray" Today - Understanding USB Insecurity in Versions 1 Through CJing (Dave) Tian, Nolen Scaife, Deepak Kumar, Michael D. Bailey et al.S&P 2018 · 52 citations
- BadBluetooth: Breaking Android Security Mechanisms via Malicious Bluetooth PeripheralsFenghao Xu, Wenrui Diao, Zhou Li, Jiongyi Chen et al.NDSS 2019 · 51 citations
Builds on3
- ECDSA Key Extraction from Mobile Devices via Nonintrusive Physical Side ChannelsDaniel Genkin, Lev Pachmanov, Itamar Pipman, Eran Tromer et al.CCS 2016 · 196 citations
- Making USB Great Again with USBFILTERDave (Jing) Tian, Nolen Scaife, Adam Bates, Kevin R. B. Butler et al.USENIX Security 2016 · 56 citations
- Defending against Malicious Peripherals with CinchSebastian Angel, Riad S. Wahby, Max Howald, Joshua B. Leners et al.USENIX Security 2016 · 44 citations
Related papers
- The Impostor Among US(B): Off-Path Injection Attacks on USB CommunicationsRobert Dumitru, Daniel Genkin, Andrew Wabnitz, Yuval YaromUSENIX Security 2023
- HubBub: Contention-Based Side-Channel Attacks on USB HubsJunpeng Wan, Yanxiang Bi, Han Gao, Dave (Jing) TianUSENIX Security 2025
- Plug and Power: Fingerprinting USB Powered Peripherals via Power Side-channelRiccardo Spolaor, Hao Liu, Federico Turrin, Mauro Conti et al.INFOCOM 2023 · 14 citations
- Time-Print: Authenticating USB Flash Drives with Novel Timing FingerprintsPatrick Cronin, Xing Gao, Haining Wang, Chase CottonS&P 2022 · 16 citations
- FuzzUSB: Hybrid Stateful Fuzzing of USB Gadget StacksKyungtae Kim, Taegyu Kim, Ertza Warraich, Byoungyoung Lee et al.S&P 2022 · 32 citations
