USENIX Security2025
HubBub: Contention-Based Side-Channel Attacks on USB Hubs
Junpeng Wan, Yanxiang Bi, Han Gao, Dave (Jing) Tian
摘要
Universal Serial Bus (USB) hubs enhance connectivity in modern computers by allowing multiple peripheral devices to share a single upstream port. Common peripherals include external storage devices, network interface cards, cameras, and keyboards. However, when several devices operate simultaneously, bus contention within the USB hub becomes unavoidable. Such contention causes timing variations that can be exploited to leak sensitive information. We identify three types of USB bus contention and design multiple side-channel attacks to infer user activities based on these contentions. These attacks can be launched from a virtual machine, a remote website, or a USB peripheral, as demonstrated in three distinct attack scenarios. By collecting I/O interval data using our probers, we can recover information such as web browsing history, camera-captured activities, and keystrokes with accuracies ranging from 85% to 99%. We evaluated 15 leading USB 3.x external hubs on the market, a USB 2.0 hub, and an internal hub, most of which are vulnerable to HubBub attacks. We have reported our findings to the relevant stakeholders.
