Time-Print: Authenticating USB Flash Drives with Novel Timing Fingerprints
Patrick Cronin, Xing Gao, Haining Wang, Chase Cotton
摘要
Universal Serial Bus (USB) ports are a ubiquitous feature in computer systems and offer a cheap and efficient way to provide power and data connectivity between a host and peripheral devices. Even with the rise of cloud and off-site computing, USB has played a major role in enabling data transfer between devices. Its usage is especially prevalent in high-security environments where systems are ‘air-gapped’ and not connected to the Internet. However, recent research has demonstrated that USB is not nearly as secure as once thought, with different attacks showing that modified firmware on USB mass storage devices can compromise a host system. While many defenses have been proposed, they require user interaction, advanced hardware support (incompatible with legacy devices), or utilize device identifiers that can be subverted by an attacker. In this paper, we present Time-Print, a novel timing-based fingerprinting method, for identifying USB mass storage devices. We create a fingerprint by timing a series of read operations from different locations on a drive, as the timing variations are unique enough to identify individual USB devices. Time-Print is low overhead, completely software-based, and does not require any extra or specialized hardware. To validate the efficacy of Time-Print, we examine more than 40 USB flash drives and conduct experiments in multiple authentication scenarios. The experimental results show that Time-Print can (1) identify known/unknown brand/model USB devices with greater than 99.5% accuracy, (2) identify seen/unseen devices of the same brand/model with 95% accuracy, and (3) classify USB devices from the same brand/model with an average accuracy of 98.7%.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了最后一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper6
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- Plug and Power: Fingerprinting USB Powered Peripherals via Power Side-channelRiccardo Spolaor, Hao Liu, Federico Turrin, Mauro Conti 等INFOCOM 2023 · 被引用 14 次
- DualStrike: Accurate, Real-time Eavesdropping and Injection of Keystrokes on Commodity KeyboardsXiaomeng Chen, Jike Wang, Zhenyu Chen, Qi Alfred Chen 等NDSS 2026 · 被引用 1 次
- The Impostor Among US(B): Off-Path Injection Attacks on USB CommunicationsRobert Dumitru, Daniel Genkin, Andrew Wabnitz, Yuval YaromUSENIX Security 2023
- From Hardware Fingerprint to Access Token: Enhancing the Authentication on IoT DevicesYue Xiao, Yi He, Xiaoli Zhang, Qian Wang 等NDSS 2024
它引用的顶会 Paper7
- FirmUSB: Vetting USB Device Firmware using Domain Informed Symbolic ExecutionGrant Hernandez, Farhaan Fowze, Dave (Jing) Tian, Tuba Yavuz 等CCS 2017 · 被引用 98 次
- Users Really Do Plug in USB Drives They FindMatthew Tischer, Zakir Durumeric, Sam Foster, Sunny Duan 等S&P 2016 · 被引用 97 次
- DeMiCPU: Device Fingerprinting with Magnetic Signals Radiated by CPUYushi Cheng, Xiaoyu Ji, Juchuan Zhang, Wenyuan Xu 等CCS 2019 · 被引用 73 次
- SensorID: Sensor Calibration Fingerprinting for SmartphonesJiexin Zhang, Alastair R. Beresford, Ian SheretS&P 2019 · 被引用 68 次
- Making USB Great Again with USBFILTERDave (Jing) Tian, Nolen Scaife, Adam Bates, Kevin R. B. Butler 等USENIX Security 2016 · 被引用 56 次
相关 Paper
- ProvUSB: Block-level Provenance-Based Data Protection for USB Storage DevicesDave (Jing) Tian, Adam Bates, Kevin R. B. Butler, Raju RangaswamiCCS 2016 · 被引用 31 次
- MagPrint: Deep Learning Based User Fingerprinting Using Electromagnetic SignalsLanqing Yang, Yi-Chao Chen, Hao Pan, Dian Ding 等INFOCOM 2020 · 被引用 16 次
- SoK: "Plug & Pray" Today - Understanding USB Insecurity in Versions 1 Through CJing (Dave) Tian, Nolen Scaife, Deepak Kumar, Michael D. Bailey 等S&P 2018 · 被引用 52 次
- HubBub: Contention-Based Side-Channel Attacks on USB HubsJunpeng Wan, Yanxiang Bi, Han Gao, Dave (Jing) TianUSENIX Security 2025
- USB Snooping Made Easy: Crosstalk Leakage Attacks on USB HubsYang Su, Daniel Genkin, Damith Chinthana Ranasinghe, Yuval YaromUSENIX Security 2017 · 被引用 41 次
