The Impostor Among US(B): Off-Path Injection Attacks on USB Communications
Robert Dumitru, Daniel Genkin, Andrew Wabnitz, Yuval Yarom
摘要
USB is the most prevalent peripheral interface in modern computer systems and its inherent insecurities make it an appealing attack vector. A well-known limitation of USB is that traffic is not encrypted. This allows on-path adversaries to trivially perform man-in-the-middle attacks. Off-path attacks that compromise the confidentiality of communications have also been shown to be possible. However, so far no off-path attacks that breach USB communications integrity have been demonstrated. In this work we show that the integrity of USB communications is not guaranteed even against off-path attackers.Specifically, we design and build malicious devices that, even when placed outside of the path between a victim device and the host, can inject data to that path. Using our developed injectors we can falsify the provenance of data input as interpreted by a host computer system. By injecting on behalf of trusted victim devices we can circumvent any software-based authorisation policy defences that computer systems employ against common USB attacks. We demonstrate two concrete attacks. The first injects keystrokes allowing an attacker to execute commands. The second demonstrates file-contents replacement including during system install from a USB disk. We test the attacks on 29 USB 2.0 and USB 3.x hubs and find 14 of them to be vulnerable.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- ChoiceJacking: Compromising Mobile Devices through Malicious Chargers like a Decade agoFlorian Draschbacher, Lukas Maar, Mathias Oberhuber, Stefan MangardUSENIX Security 2025
- DNAFuzz: Descriptor-Aware Fuzzing for USB DriversZhengshu Wang, Peng He, Fuchen Ma, Yuanliang Chen 等ASE 2025
- From Hardware Fingerprint to Access Token: Enhancing the Authentication on IoT DevicesYue Xiao, Yi He, Xiaoli Zhang, Qian Wang 等NDSS 2024
- HubBub: Contention-Based Side-Channel Attacks on USB HubsJunpeng Wan, Yanxiang Bi, Han Gao, Dave (Jing) TianUSENIX Security 2025
它引用的顶会 Paper6
- Users Really Do Plug in USB Drives They FindMatthew Tischer, Zakir Durumeric, Sam Foster, Sunny Duan 等S&P 2016 · 被引用 97 次
- Making USB Great Again with USBFILTERDave (Jing) Tian, Nolen Scaife, Adam Bates, Kevin R. B. Butler 等USENIX Security 2016 · 被引用 56 次
- SoK: "Plug & Pray" Today - Understanding USB Insecurity in Versions 1 Through CJing (Dave) Tian, Nolen Scaife, Deepak Kumar, Michael D. Bailey 等S&P 2018 · 被引用 52 次
- Defending against Malicious Peripherals with CinchSebastian Angel, Riad S. Wahby, Max Howald, Joshua B. Leners 等USENIX Security 2016 · 被引用 44 次
- USB Snooping Made Easy: Crosstalk Leakage Attacks on USB HubsYang Su, Daniel Genkin, Damith Chinthana Ranasinghe, Yuval YaromUSENIX Security 2017 · 被引用 41 次
相关 Paper
- Saturn: Host-Gadget Synergistic USB Driver FuzzingYiru Xu, Hao Sun, Jianzhong Liu, Yuheng Shen 等S&P 2024 · 被引用 13 次
- USBFuzz: A Framework for Fuzzing USB Drivers by Device EmulationHui Peng, Mathias PayerUSENIX Security 2020
- Time-Print: Authenticating USB Flash Drives with Novel Timing FingerprintsPatrick Cronin, Xing Gao, Haining Wang, Chase CottonS&P 2022 · 被引用 16 次
- Plug and Power: Fingerprinting USB Powered Peripherals via Power Side-channelRiccardo Spolaor, Hao Liu, Federico Turrin, Mauro Conti 等INFOCOM 2023 · 被引用 14 次
- ProvUSB: Block-level Provenance-Based Data Protection for USB Storage DevicesDave (Jing) Tian, Adam Bates, Kevin R. B. Butler, Raju RangaswamiCCS 2016 · 被引用 31 次
