USB-based network security attack and defense demonstration system, method and device and storage medium

By integrating multiple USB attack units and defense strategies, the cybersecurity attack and defense demonstration system solves the problems of limited scenarios and low automation in existing systems, and realizes multi-dimensional attack simulation and efficient attack and defense assessment.

CN121923879APending Publication Date: 2026-04-24CHONGQING COLLEGE OF HUMANITIES SCI & TEHNOLOGY
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CHONGQING COLLEGE OF HUMANITIES SCI & TEHNOLOGY
Filing Date
2025-12-31
Publication Date
2026-04-24

AI Technical Summary

Technical Problem

Existing cybersecurity attack and defense demonstration systems do not fully cover all attack scenarios, have cumbersome operation procedures and low automation, lack integrated demonstrations of multiple attack types, have incomplete data monitoring, and are difficult to accurately assess the effectiveness of attack and defense.

Method used

A USB-based cybersecurity attack and defense demonstration system was designed, which includes an attack demonstration module, a defense configuration module, and a data monitoring module. It integrates multiple USB attack units and defense strategies, supports automated attack operations and visualized data display, and simulates scenarios of different complexity through a comprehensive exercise module.

Benefits of technology

It achieves complete coverage of multi-dimensional USB security risk scenarios, reduces operational errors, improves demonstration efficiency, supports custom configuration and one-click deployment of defense strategies, provides intuitive attack and defense process data display, and accurately evaluates the effect.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121923879A_ABST
    Figure CN121923879A_ABST
Patent Text Reader

Abstract

The invention discloses a USB-based network security attack and defense demonstration system. The system comprises an attack demonstration module, a defense configuration module and a data monitoring module, the attack demonstration module comprises a plurality of USB attack units, and each USB attack unit is configured with a corresponding attack execution component; the attack execution assembly comprises a hardware driving module, an instruction analysis module and a behavior execution module, the hardware driving module is adaptive to hardware interfaces of different USB attack units, the instruction analysis module decodes and converts a preset attack instruction, and the behavior execution module drives hardware to complete attack operation; the defense configuration module is used for performing USB security defense strategy configuration on target equipment; the data monitoring module is used for capturing and recording data interaction information in the attack and defense process. Complex manual intervention is not needed, the operation error is reduced, the demonstration efficiency is improved, scenes with different complexities are simulated, and the demonstration effect is close to an actual application scene.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a USB-based cybersecurity attack and defense demonstration, and more specifically, to a USB-based cybersecurity attack and defense demonstration system, method, apparatus, and storage medium. Background Technology

[0002] In the digital age, USB devices have become the core of device interaction due to their convenience, but they have also become a major carrier of cyberattacks. Frequent USB-related security incidents seriously threaten personal privacy, corporate data, and national information security. Therefore, conducting cybersecurity attack and defense demonstrations has become a crucial means to raise security awareness and verify the effectiveness of defense systems. Existing cybersecurity attack and defense demonstrations mostly rely on simulating single attack scenarios. The operational procedures often involve manually setting up simple experimental environments, manually configuring attack scripts and defense rules, capturing limited attack and defense data using scattered tools, and then manually organizing and analyzing the results. For example, a single demonstration focusing on malicious USB flash drive attacks requires manually deploying the attack program, enabling monitoring tools, and manually exporting data for post-attack analysis. However, existing demonstrations suffer from several drawbacks. First, they lack comprehensive attack scenario coverage, lacking integrated demonstrations of various attack methods such as wireless keyboard eavesdropping, mobile phone Trojan implantation, and WiFi data interception. Second, the operational procedures are cumbersome and lack automation, relying heavily on manual intervention and prone to errors. Third, attack and defense strategies cannot dynamically adapt to different scenarios, resulting in insufficient flexibility in drills. Fourth, data monitoring is incomplete, lacking systematic recording and intuitive visualization of key indicators during the attack and defense process, making it difficult to accurately assess the effectiveness of attacks and defenses. Summary of the Invention

[0003] To achieve the above objectives, the present invention provides a USB-based cybersecurity attack and defense demonstration system, the system comprising an attack demonstration module, a defense configuration module, and a data monitoring module; The attack demonstration module includes multiple USB attack units, each of which is configured with a corresponding attack execution component. The attack execution component includes a hardware driver module, an instruction parsing module, and a behavior execution module. The hardware driver module is adapted to the hardware interface of different USB attack units, the instruction parsing module decodes and converts preset attack instructions, and the behavior execution module drives the hardware to complete the attack operation. The defense configuration module is used to configure USB security defense policies for the target device; The data monitoring module is used to capture and record data interaction information during the attack and defense process.

[0004] Furthermore, the USB attack unit includes a malicious USB flash drive attack unit, an optical disc tampering theft unit, a wireless keyboard theft unit, a mobile phone Trojan theft unit, a WiFi email interception unit, a WiFi Web data interception unit, a classified storage medium data recovery unit, a USB Rubber Ducky attack unit, a firmware tampering attack unit, a WHID attack unit, a USB sniffing attack unit, a USB device cross-theft unit, and a USB mouse tampering unit.

[0005] Furthermore, the malicious USB flash drive attack unit includes a customized USB flash drive component. The customized USB flash drive component has a built-in Trojan program that can disguise itself as an ordinary storage device. After being connected to the target device, it can automatically steal files containing sensitive keywords in a specified directory. The sensitive keywords can be preset through a configuration file and support multiple keyword combinations. The USB Rubber Ducky attack unit includes a simulated keyboard execution component. The simulated keyboard execution component pre-stores attack command sequences and automatically simulates keyboard input behavior after being connected to the target device, quickly executing preset attack operations. The firmware tampering attack unit includes a firmware read / write component and a USB device modification component. The firmware read / write component is used to read, modify, and rewrite the USB device firmware. The USB device modification component includes an Arduino Leonardo development board, an ESP32S3 development board, and a USB housing kit. The WHID attack unit includes a wireless communication component with a communication distance of not less than 20 meters. It can be integrated into a human-machine interface device, which includes a keyboard and a mouse. It sends attack commands and transmits stolen data to the target device via a wireless link. The USB sniffing attack unit includes a data capture component and an analysis component; The data capture component is used to capture control transmissions and batch transmissions of various communication data between the USB device and the target device. The analysis component is used to parse sensitive information in the captured data and generate an attack analysis report.

[0006] Furthermore, the defense configuration module supports defense strategies including: USB port access permission control, disabling unauthorized USB devices, USB device firmware integrity verification, real-time scanning of malicious programs, and encrypted transmission of USB communication data; the defense strategy configuration also includes a real-time attack behavior interception module, which blocks the operation and triggers an alarm when an operation matching the attack characteristics is detected; the defense strategy can be customized and deployed with one click through a visual interface.

[0007] Furthermore, the data monitoring module records data including attack trigger time, attack operation steps, data transmission traffic, target device response status, defense strategy execution logs, attack success rate, and defense interception rate. The data can be exported to standardized format files and can be displayed intuitively in the form of line charts, bar charts, and pie charts to show key indicators of the attack and defense process.

[0008] Furthermore, the USB device cross-data theft unit is used for covert data theft between multiple target devices via USB devices; The USB mouse transfer unit integrates a storage module, which automatically copies confidential files from the target device during normal mouse use; The system also includes a comprehensive exercise module, which includes an exercise scenario parameter configuration unit that supports customizing parameters such as the number of target devices, system environment, attack intensity, and defense level to simulate attack and defense scenarios of varying complexity. The attack demonstration module and the defense configuration module work together to dynamically adjust attack and defense strategies and evaluate the exercise effect.

[0009] Furthermore, the customized USB flash drive component of the malicious USB flash drive attack unit includes an intelligent file fragmentation theft and breakpoint resume module; The intelligent file fragmentation theft and breakpoint resume module includes a dynamic fragmentation adaptation subunit, a breakpoint encrypted storage subunit, and a disguised transmission subunit. The dynamic fragmentation adaptation subunit first detects the target device's storage input and output rates, background process usage, and security software monitoring frequency. The dynamic fragmentation adaptation subunit detects the target device's status every 1-3 seconds and dynamically adjusts the fragment size based on the real-time detection results to ensure the theft process matches the target device's operating status. It automatically splits sensitive files into dynamic intervals of 512KB-10MB; specifically, it splits into small fragments of 512KB-2MB under high load scenarios and large fragments of 5-10MB under low load scenarios. Furthermore, during fragmentation, random byte padding is applied to the file header and footer. The system employs several techniques to encrypt and store breakpoint records. The encrypted storage subunit uses the AES-256 algorithm to encrypt breakpoint records, hiding the storage location within the unallocated sectors of the USB flash drive. This encryption can only be read using a dedicated decryption command specific to the customized USB flash drive component. This dedicated decryption command includes a hardware identifier and a dynamic key. The hardware identifier is the unique chip serial number of the customized USB flash drive, and the dynamic key is generated and transmitted in real-time by the control terminal. During fragmented transmission, the spoofing transmission subunit, in addition to using random 8-16 character combinations of uppercase and lowercase letters and numbers in the filename, also simulates the header structure of commonly used file formats on the target device. Simultaneously, it intersperses the transmission of 10-20KB of meaningless padding data blocks, with the transmission interval of these padding data blocks matching the normal file read / write interval of the target device.

[0010] A USB-based network security attack and defense demonstration method includes the following steps: S1) By pre-setting sensitive keywords, attack command sequences, and fragment size threshold parameters in the configuration file, the communication pairing between the attack unit and the control terminal is completed; The S2 system launches a comprehensive attack through multiple attack units, including a malicious USB flash drive attack unit, a USB Rubber Ducky attack unit, and a firmware tampering attack unit, integrated into the attack demonstration module. The malicious USB flash drive disguises itself as a regular storage device and, upon connection to the target device, dynamically splits and steals files based on preset sensitive keywords using an intelligent file segmentation and breakpoint resume module. The USB Rubber Ducky simulates a keyboard to quickly execute preset attack command sequences. The firmware tampering attack unit modifies devices using Arduino Leonardo and ESP32S3 development boards and rewrites firmware to implant malicious code. The WHID attack unit remotely sends attack commands via 2.4G wireless communication. The USB sniffing attack unit captures and parses USB communication data. The USB device cross-stealing unit and the USB mouse transfer unit respectively achieve covert multi-device stealing and file copying during normal use. S3) While the attack is being carried out, the defense configuration module can customize and configure defense strategies such as USB port access permission control, unauthorized device disabling, and firmware integrity verification for the target device through a visual interface and deploy them with one click to defend against various attack behaviors in real time. S4) The data monitoring module captures the attack trigger time, operation steps, data traffic, target device response status and defense strategy execution logs throughout the attack and defense process. It supports exporting data to standardized format files or displaying key indicators intuitively through charts. S5) The comprehensive exercise module imports real USB security incident cases, simulates actual attack scenarios, coordinates the attack demonstration module and the defense configuration module to dynamically adjust the attack and defense strategies, and conducts an effectiveness evaluation after the exercise is completed. S6) Based on the information recorded by the data monitoring module, generate an attack and defense review report to identify attack vulnerabilities and defense optimization directions.

[0011] A USB-based cybersecurity attack and defense demonstration device includes an attack demonstration component, a defense configuration component, a data monitoring component, a comprehensive exercise component, and auxiliary components. The attack demonstration component is located in the attack module area of ​​the device and is equipped with an independent USB interface panel. The attack demonstration component is physically connected to the target device through the USB interface panel and is also connected to the main control board of the device through an internal data cable. The defense configuration component includes a visual configuration terminal and a defense strategy processing module. The visual configuration terminal is located in the front-end operation area of ​​the device, and the defense strategy processing module is built into the device and connected to the visual configuration terminal via a ribbon cable. The defense configuration component establishes a communication connection with the target device through the main control board. The data monitoring component includes a data acquisition module, a storage module, and a visualization module. The data acquisition module and the storage module are integrated into the main control board inside the device. The visualization module is embedded in the front end of the device. The data acquisition module is connected to the attack demonstration component and the defense configuration component through an internal bus. The storage module and the visualization module are directly connected through a ribbon cable. The storage module is connected to an external device through a USB interface to support data export. The integrated training component includes a case import interface and a training control unit. The case import interface is located on the side of the device, and the training control unit is integrated with the main control board. The case import interface is connected to the main control board via a data cable, and the training control unit is connected to the attack demonstration component and the defense configuration component via an internal bus. The auxiliary components include a power supply module, an interface adapter module, and a data transmission module. The power supply module is installed at the bottom of the device and is connected to each functional component for power supply via a power cord. The interface adapter module is integrated at the rear of the USB interface panel and is bidirectionally connected to the USB interface panel and the main control board. The data transmission module is embedded in the main control board.

[0012] A USB-based network security attack and defense demonstration storage medium is a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the USB-based network security attack and defense demonstration method as described in claim 8.

[0013] This invention offers the following advantages: Firstly, it integrates USB-related attack units for malicious USB flash drive attacks, CD-ROM data theft, and wireless keyboard data theft, covering multiple attack methods such as device implantation, wireless interception, and data recovery. It fully recreates various USB security risk scenarios, filling the gap in existing demonstration scenarios. Secondly, each attack unit is equipped with a dedicated execution component, supporting automatic execution of attack operations with preset parameters. Defense strategies can be customized and deployed with a single click through a visual interface, eliminating the need for complex manual intervention, reducing operational errors, and improving demonstration efficiency. Thirdly, the comprehensive training module supports customizable parameters such as the number of target devices and attack intensity to simulate scenarios of varying complexity. Simultaneously, the data monitoring module comprehensively records key data such as attack trigger time and defense execution logs, supporting standardized format export and visualization through line charts, bar charts, and other visual displays. Furthermore, the intelligent fragmentation and breakpoint resumption module of the malicious USB flash drive attack unit evades security monitoring through dynamic adaptation to target device status and encrypted storage of breakpoint records. All attack units are compatible with mainstream hardware and system environments, and the demonstration effects closely resemble real-world application scenarios. Attached Figure Description

[0014] Figure 1 This is a schematic diagram of Trojan horse implantation into a USB flash drive in this invention; Figure 2 This is a schematic diagram of the appearance of the attacking and controlled computers in a demonstration of a special Trojan horse. Figure 3 This is a schematic diagram of the appearance of the customized USB flash drive component corresponding to the data theft function of the disk ferry; Figure 4 This is a screenshot of the settings interface for not showing hidden files, folders, or drives in the folder options of the attacked computer. Figure 5 This is a screenshot of the settings interface for not showing hidden files, folders, or drives in the computer's folder options. Figure 6 This is a schematic diagram of the file sensitive word configuration interface; Figure 7 This is a diagram illustrating the process of creating a file containing sensitive words on the attacked computer and inserting a custom USB drive. Figure 8 This is a diagram illustrating the theft of files hidden on a USB drive on a computer. Figure 9 A schematic diagram of the interface for launching the CD-ROM trojan on the target computer. Figure 10 A diagram illustrating the process of burning files from a target computer to a CD. Figure 11 A diagram illustrating the process of using the CDRecovery.bat file on a computer to recover files. Figure 12 A schematic diagram of the appearance of the wireless keyboard listener and its matching keyboard; Figure 13 A schematic diagram of the initial interface of the KEYBoardSPY.exe program on the computer for monitoring; Figure 14 A schematic diagram of the interface for successfully connecting to the listener and locating the wireless keyboard; Figure 15 A diagram illustrating the operation of synchronously displaying input content on the target computer on the monitoring computer. Figure 16 A schematic diagram of the product appearance of a mobile phone Trojan stealing unit; Figure 17 A screenshot of the interface for monitoring the startup of a mobile phone Trojan control terminal (.bat) program on a computer; Figure 18 A schematic diagram of the interface for the control terminal to obtain basic information from the mobile phone; Figure 19 A schematic diagram of the interface for the control terminal to access the phone's contacts; Figure 20 A schematic diagram of the interface for the control terminal to obtain SMS messages from the mobile phone; Figure 21 A schematic diagram of the configuration interface for the control terminal to obtain audio from the mobile phone; Figure 22 This is a schematic diagram of the interface for the control terminal to take photos using the phone's camera. Figure 23 A schematic diagram of the interface for the control terminal to obtain the real-time location of the mobile phone; Figure 24 A schematic diagram of the product appearance of the WiFi email interception unit; Figure 25 This is an illustration of a WiFi phishing attack homepage; Figure 26 A schematic diagram of the web data interception function page; Figure 27 This is a schematic diagram of the online customer list interface; Figure 28 This is a schematic diagram of the web browsing log interface; Figure 29This is a diagram illustrating the interface for intercepting and parsing emails. Figure 30 This is a diagram illustrating the parsed email content. Figure 31 This is a schematic diagram of the email attachment display and download interface. Figure 32 A schematic diagram of the WiFi Web data interception unit; Figure 33 This is an illustration of a WiFi phishing attack homepage; Figure 34 A schematic diagram of the web data interception function page; Figure 35 This is a schematic diagram of the online customer list interface; Figure 36 This is a schematic diagram of the web browsing log interface; Figure 37 A diagram illustrating the content of a webpage viewed by a user; Figure 38 This is an example of a screenshot of a webpage. Figure 39 A diagram showing a list of screenshots of all web pages; Figure 40 This is a diagram illustrating the images captured from a webpage. Figure 41 This is a separate illustration of a single captured image. Figure 42 A schematic diagram of the product appearance of a data recovery unit for classified storage media; Figure 43 This is a screenshot of the console window after the usb_jpg.bat program starts; Figure 44 A schematic diagram of the interface for the program to automatically recover files; Figure 45 A screenshot showing the confirmation screen for terminating the USB drive scan; Figure 46 This is a schematic diagram showing the interface for displaying the recovered files after the scan is complete. Figure 47 This is a block diagram of the attack and defense demonstration system of the present invention. Detailed Implementation

[0015] The present invention will be further described below with reference to the accompanying drawings and embodiments: In the description of this invention, it should be noted that the terms "up," "down," "left," "right," "vertical," "horizontal," "inner," and "outer," etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. They are used only for the convenience of describing the invention and for simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the invention. Furthermore, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance.

[0016] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms installation, setting, and connection should be interpreted broadly. For example, they can refer to fixed connections, detachable connections, or integral connections; they can refer to mechanical connections or electrical connections; they can refer to direct connections or indirect connections through an intermediate medium; and they can refer to the internal communication between two components. Those skilled in the art can understand the specific meaning of the above terms in this invention based on the specific circumstances.

[0017] like Figures 1 to 47 As shown, a USB-based cybersecurity attack and defense demonstration system is characterized by: the system comprising an attack demonstration module, a defense configuration module, and a data monitoring module; the attack demonstration module includes multiple USB attack units, each configured with a corresponding attack execution component; the attack execution component includes a hardware driver module, an instruction parsing module, and a behavior execution module, the hardware driver module adapting to the hardware interfaces of different USB attack units, the instruction parsing module decoding and converting preset attack instructions, and the behavior execution module driving the hardware to complete the attack operation; the defense configuration module is used to configure USB security defense strategies for the target device; and the data monitoring module is used to capture and record data interaction information during the attack and defense process. The USB attack units include a malicious USB flash drive attack unit, a CD-ROM data interception unit, a wireless keyboard data interception unit, a mobile phone Trojan data interception unit, a WiFi email interception unit, a WiFi Web data interception unit, a classified storage medium data recovery unit, a USB RubberDucky attack unit, a firmware tampering attack unit, a WHID attack unit, a USB sniffing attack unit, a USB device cross-data interception unit, and a USB mouse data interception unit. In this invention, the USB attack unit also includes a special Trojan attack unit. This unit is equipped with a customized USB flash drive component (i.e., a Trojan-implanted USB flash drive) with a built-in special Trojan program that can disguise itself as an ordinary storage device. The Trojan is implanted and executed within 30 seconds of being connected to the controlled computer, and the USB flash drive can be removed without further operation. The attacking computer (mainstream hardware configuration, WIN7 32-bit / 64-bit standard system, network-connected) and the controlled computer (mainstream hardware configuration, WIN7 32-bit / 64-bit standard system, network-connected) must be connected to the same AP or HUB beforehand. The attacking computer remotely controls the controlled computer system via the network, including accessing the camera and microphone, accessing the disk, remotely viewing and modifying files on the controlled computer, editing the registry, and running software. It also supports searching for controlled computers in the same network environment (see...). Figure 1 and Figure 2 ).

[0018] The CD-ROM espionage unit includes a CD-ROM espionage program that can run covertly on the target computer. During the file burning process, it simultaneously espionage files containing sensitive words (including recently opened Word files) to the CD-ROM. Only the burned files are displayed on the CD-ROM; the espionage files are hidden and require file recovery tools for restoration. The parameter configuration is as follows: blank CD-ROM burning; target computer hardware is mainstream (including a CD-ROM drive), and the operating system is Windows 7 32-bit / 64-bit standard edition; the file recovery computer hardware is mainstream, and the operating system is Windows 7 32-bit / 64-bit standard edition. Detailed operation procedure: 1. Preparation: Run the CDWriter.bat file in the root directory of drive C on the target computer to launch the CD-ROM trojan (see Figure 9); 2. Burning the CD: Insert a blank CD or DVD into the target computer's CD-ROM drive, drag and drop any file onto the disc, and wait for the burning process to complete (see Figure 9). Figure 10 ); 3. Recover files: Insert the burned CD into the file recovery computer, run the CDRecovery.bat file on the desktop, the recovery time is about 1 minute, and the recovered files are stored in the root directory of drive C (see Figure 11). The wireless keyboard eavesdropping unit includes a wireless keyboard listener and a matching keyboard (see appearance). Figure 12 This device can monitor the wireless keyboard input of a target computer and display it synchronously on the monitoring computer. The parameter configuration is as follows: the target computer has mainstream hardware specifications and no system restrictions; the monitoring computer has mainstream hardware specifications and runs a standard WIN7 32-bit / 64-bit system. Detailed operation procedure: 1. Search for wireless keyboards: Run the KEYBoardSPY.exe program on the monitoring computer's desktop (interface shown in...). Figure 13 If the top left corner displays "Listener connected," no further action is needed. If it displays "Error opening serial port, unable to connect to listener," enter the listener's serial port number (found in Device Manager) in the text box in the top right corner, and click "Connect Listener" until it displays "Connection successful." After successful serial port connection, continuously press keys on the target computer's wireless keyboard until the interface displays "Wireless keyboard found and n keys captured: xxx" (see...). Figure 14 ); 2. Synchronous display of input content: When Notepad or other text input tools are opened on both the target computer and the listening computer, the content entered on the target computer will be simultaneously displayed on the listening computer (see Figure 15); The mobile phone Trojan stealing unit implants a mobile phone Trojan through a QR code, which can eavesdrop on and steal mobile phone calls and stored information (including contacts, text messages, files, etc.), and can also remotely control the mobile phone microphone and camera to achieve eavesdropping and spying, and locate the mobile phone's geographical location. See the product appearance. Figure 16 The parameter configuration is as follows: the monitoring computer hardware is a mainstream configuration, the system is WIN7 32-bit / 64-bit standard edition; the mobile phone environment is Android 4.0. Detailed operation procedure: 1. Start monitoring computer Trojan viruses: Run the mobile Trojan control terminal.bat program on the computer desktop, and wait for client connections after starting (see...). Figure 17 ); 2. Mobile phone Trojan implantation: Scan the corresponding QR code with your mobile phone to complete the Trojan implantation. After successful connection, you can obtain basic mobile phone information (including phone number, IMEI, carrier, WiFi status, etc., see...). Figure 18 ); 3. Stealing mobile phone data: The phone's contact list can be obtained through the control terminal (see Figure 19 SMS (Supports filtering of received / sent SMS messages, see below) Figure 20It can also acquire mobile phone audio (you can select the microphone as the acquisition source and configure parameters such as sampling rate and sampling size, see...). Figure 21 ); 4. Remotely control your phone: Use the control terminal to take photos using the phone's front or rear camera (see...). Figure 22 ), and obtain the phone's real-time geographic location (including longitude, latitude, altitude, speed, etc., see Figure 23 ); The WiFi email interception unit lures users to connect by setting up a fake WiFi hotspot, intercepts users' wireless internet data traffic, and analyzes and reconstructs emails and attachments sent by users. (See product appearance...) Figure 24 .

[0019] The parameter configuration is as follows: the operating system is Linux; Dsniff, mitmproxy 0.18, and Twisted-15.5.0 tools need to be installed. Detailed operation procedure: 1. Access the WiFi phishing attack homepage (see...) Figure 25 Select the Web network data interception function page, click the start button to enable data interception, and click the stop button to terminate the function (see...). Figure 26 ); 2. View the online customer list and obtain information such as the MAC address, IP address, and client name of users accessing the fake WiFi hotspot (see Figure 27 ); 3. View network browsing logs to record user network access behavior data (see Figure 28 ); 4. Parse the intercepted email data using the WiFi network email interception function (see Figure 29 To view the detailed email content (including sender, recipient, sending time, and email body), see [link / reference]. Figure 30 ); 5. Supports displaying and downloading email attachments (see Figure 31 ); The WiFi Web data interception unit lures users to connect by setting up fake WiFi hotspots, intercepts users' wireless internet data traffic, parses network data information, and captures and displays the web page content browsed by the user (including image capture and web page screenshots). See product appearance for details. Figure 32 The parameter configuration is as follows: the operating system is Linux; mitmproxy 0.18 and Twisted-15.5.0 tools need to be installed; the specific operation process is as follows: 1. Access the WiFi phishing attack homepage (see Figure 33), select the Web network data interception function page, click the start button to enable data interception, and click the stop button to terminate the function (see Figure 33). Figure 34 ); 2. View the online customer list and obtain information such as the MAC address, IP address, and client name of the connected users (see Figure 35 ); 3. View network browsing logs to record user network access behavior data (see Figure 36); 4. View the content of the web pages browsed by the user (see Figure 37 ) and webpage screenshots (see Figure 38 You can view a list of all webpage screenshots (see...). Figure 39 ) and captured web browsing images (see Figure 40 Supports individual display of each captured image (see) Figure 41 ); The classified storage media data recovery unit can recover deleted or formatted files from USB flash drives. See product appearance for details. Figure 42 The parameters are as follows: The USB flash drive must have a USB 2.0 or higher interface and a capacity of no more than 1GB; the computer hardware used for recovery should be of mainstream configuration, and the operating system should be Windows 7 32-bit / 64-bit standard edition. Detailed operation procedure: 1. Boot from the USB drive and restore the usb_jpg.bat program on your computer desktop. After the program starts, a console window will be displayed (see...). Figure 43 ); 2. Insert the USB drive, and the program will automatically begin file recovery (see...). Figure 44 A 1GB USB flash drive scan will take approximately 3 minutes. Press Enter and then Y to confirm and terminate the scan (see...). Figure 45 ); 3. After terminating the scan or completing the scan, the program displays the recovered files (see...). Figure 46 The recovered files are stored in the directory D:\tools\U disk file recovery\client.n (n=1, 2, 3...), and a new directory is created each time the USB drive is plugged in or unplugged. The malicious USB flash drive attack unit includes a customized USB flash drive component with a built-in Trojan program that can disguise itself as an ordinary storage device. Upon connection to the target device, it automatically steals files containing sensitive keywords from a specified directory. These sensitive keywords can be preset via a configuration file and multiple keyword combinations are supported. The USB Rubber Ducky attack unit includes a simulated keyboard execution component. This component pre-stores attack command sequences and automatically simulates keyboard input upon connection to the target device, quickly executing preset attack operations, including permission acquisition and sensitive information theft. The firmware tampering attack unit includes a firmware read / write component and a USB device modification component. The firmware read / write component is used to read, modify, and rewrite the USB device firmware. The USB device modification component includes an Arduino Leonardo development board, an ESP32S3 development board, and a USB casing kit. The development boards use specified chip models and support double-layer wiring and easy soldering modifications. The WHID attack unit includes a 2.4G wireless communication component with a communication range of not less than 20 meters. It can be integrated into a human-machine interface device, which includes a keyboard and mouse. It sends attack commands and transmits stolen data to the target device via a wireless link. The USB sniffing attack unit includes a data capture component and an analysis component. The data capture component captures control transmissions and batch transmissions of various communication data between the USB device and the target device. The analysis component parses sensitive information from the captured data and generates attack analysis reports. The defense configuration module supports defense strategies including: USB port access permission control, disabling unauthorized USB devices, USB device firmware integrity verification, real-time malware scanning, and encrypted USB communication data transmission. The defense strategy configuration also includes a real-time attack behavior interception module, which blocks operations and triggers alarms when operations matching attack characteristics are detected. Defense strategies can be customized and deployed with a single click through a visual interface. The data monitoring module records data including attack trigger time, attack operation steps, data transmission traffic, target device response status, defense strategy execution logs, attack success rate, and defense interception rate. Data can be exported to standardized format files and can be visually displayed as line charts, bar charts, and pie charts, showing key indicators of the attack and defense process. The USB device cross-data theft unit is used for covert data theft between multiple target devices via USB devices; the USB mouse transfer unit integrates a storage module to automatically copy classified files from the target device during normal mouse use; the system also includes a comprehensive exercise module, which includes an exercise scenario parameter configuration unit that supports customizing the number of target devices, system environment, attack intensity, and defense level parameters to simulate attack and defense scenarios of varying complexity; the attack demonstration module and the defense configuration module work together to dynamically adjust attack and defense strategies and evaluate the exercise effect.

[0020] The customized USB drive component of the malicious USB drive attack unit includes an intelligent file fragmentation and theft module and a breakpoint resume module; the customized USB drive component of the malicious USB drive attack unit supports USB drive data theft functionality, and the component's appearance is as follows. Figure 3 It can be used normally as a regular USB flash drive, stealing files from a specified directory on the target device (i.e., the attacked computer) without being detected. The file types can be preset through a configuration file. The attacked computer has mainstream hardware specifications and runs Windows 7 32-bit / 64-bit standard edition. The folder options must be set to "Do not show hidden files, folders, or drives" (e.g., ...). Figure 4 As shown), configure the CMD window properties according to the steps in cmd window hiding settings.DOC; the computer hardware is a mainstream configuration, the system is WIN7 32-bit / 64-bit standard edition, and the file type viewing option in folder options is also set to not show hidden files, folders or drives (e.g. Figure 5 (As shown). The specific operation process is as follows: 1. Parameter Configuration: Insert the customized USB drive into the computer where you view the files. Open the cpsf.din file on the USB drive with Notepad. Modify a specified section to define multiple sensitive words (such as secret, confidential, top secret). Each sensitive word is enclosed in asterisks (*) on both sides and left with one space in between (e.g., ...). Figure 6(As shown); 2. Stealing files: Create a file (file type arbitrary) with a preset sensitive word in its name on the desktop or C drive of the attacked computer. Insert the customized USB flash drive into the attacked computer and remove it after about 30 seconds (e.g. Figure 7 (As shown); 3. View files: Insert the customized USB drive into the computer where you want to view the files, open File Explorer to access the USB drive, and you will see a list of stolen files with the attribute set to hidden (such as...). Figure 8 (As shown).

[0021] The intelligent file fragmentation theft and breakpoint resume module includes a dynamic fragmentation adaptation subunit, a breakpoint encrypted storage subunit, and a disguised transmission subunit. The dynamic fragmentation adaptation subunit first detects the target device's storage input and output rates, background process usage, and security software monitoring frequency. The subunit detects the target device's status every 1-3 seconds and dynamically adjusts the fragment size based on the real-time detection results to ensure the theft process matches the target device's operating status. It automatically splits sensitive files into dynamic intervals of 512KB-10MB; specifically, it splits into small fragments of 512KB-2MB under high load and large fragments of 5-10MB under low load. Furthermore, during fragmentation, random byte padding is applied to the file header and footer for obfuscation. The system circumvents file signature corruption. The breakpoint encryption storage unit uses the AES-256 algorithm to encrypt breakpoint records, hiding the storage location within unallocated sectors of the USB drive. It can only be read using a dedicated decryption command specific to the customized USB drive component. This command includes a hardware identifier (the unique chip serial number of the customized USB drive) and a dynamic key, generated and transmitted in real-time by the control unit. During fragmented transmission, the disguised transmission unit uses random 8-16 character filenames combining uppercase and lowercase letters and numbers, simulates the header structure of commonly used file formats on the target device, and intersperses 10-20KB of meaningless padding data blocks. The interval between these padding data blocks matches the normal file read / write interval on the target device. This further evades feature detection and behavior alerts from file monitoring.

[0022] A USB-based network security attack and defense demonstration method includes the following steps: S1) By pre-setting sensitive keywords, attack command sequences, and fragment size threshold parameters in the configuration file, the communication pairing between the attack unit and the control terminal is completed; The S2 system launches a comprehensive attack through multiple attack units, including a malicious USB flash drive attack unit, a USB Rubber Ducky attack unit, and a firmware tampering attack unit, integrated into the attack demonstration module. The malicious USB flash drive disguises itself as a regular storage device and, upon connection to the target device, dynamically splits and steals files based on preset sensitive keywords using an intelligent file segmentation and breakpoint resume module. The USB Rubber Ducky simulates a keyboard to quickly execute preset attack command sequences. The firmware tampering attack unit modifies devices using Arduino Leonardo and ESP32S3 development boards and rewrites firmware to implant malicious code. The WHID attack unit remotely sends attack commands via 2.4G wireless communication. The USB sniffing attack unit captures and parses USB communication data. The USB device cross-stealing unit and the USB mouse transfer unit respectively achieve covert multi-device stealing and file copying during normal use. S3) While the attack is being carried out, the defense configuration module can customize and configure defense strategies such as USB port access permission control, unauthorized device disabling, and firmware integrity verification for the target device through a visual interface and deploy them with one click to defend against various attack behaviors in real time. S4) The data monitoring module captures the attack trigger time, operation steps, data traffic, target device response status and defense strategy execution logs throughout the attack and defense process. It supports exporting data to standardized format files or displaying key indicators intuitively through charts. S5) The comprehensive exercise module imports real USB security incident cases, simulates actual attack scenarios, coordinates the attack demonstration module and the defense configuration module to dynamically adjust the attack and defense strategies, and conducts an effectiveness evaluation after the exercise is completed. S6) Based on the information recorded by the data monitoring module, generate an attack and defense review report to identify attack vulnerabilities and defense optimization directions.

[0023] A USB-based cybersecurity attack and defense demonstration device includes an attack demonstration component, a defense configuration component, a data monitoring component, a comprehensive exercise component, and auxiliary components. The attack demonstration component is located in the attack module area of ​​the device and is equipped with an independent USB interface panel. The attack demonstration component is physically connected to the target device via the USB interface panel and simultaneously connected to the device's main control board via an internal data cable. The defense configuration component includes a visual configuration terminal and a defense strategy processing module. The visual configuration terminal is located in the front-end operation area of ​​the device, and the defense strategy processing module is built into the device and connected to the visual configuration terminal via a ribbon cable. The defense configuration component establishes a communication connection with the target device through the main control board. The data monitoring component includes a data acquisition module, a storage module, and a visualization display module. The data acquisition module and storage module are integrated into the main control board inside the device, and the visualization display module is embedded within the main control board. The front-end data acquisition module connects to the attack demonstration component and defense configuration component via an internal bus. The storage module and visualization display module are directly connected via ribbon cables, and the storage module connects to external devices via a USB interface to support data export. The integrated exercise component includes a case import interface and an exercise control unit. The case import interface is located on the side of the device, and the exercise control unit is integrated with the main control board. The case import interface connects to the main control board via a data cable, and the exercise control unit connects to the attack demonstration component and defense configuration component via an internal bus. The auxiliary components include a power supply module, an interface adapter module, and a data transmission module. The power supply module is installed at the bottom of the device and connects to each functional component via a power cord to supply power. The interface adapter module is integrated at the rear of the USB interface panel and connects bidirectionally to the USB interface panel and the main control board. The data transmission module is embedded in the main control board.

[0024] A USB-based network security attack and defense demonstration storage medium is a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the steps of the USB-based network security attack and defense demonstration method of claim 8.

Claims

1. A USB-based network security attack and defense demonstration system, characterized in that: The system includes an attack demonstration module, a defense configuration module, and a data monitoring module. The attack demonstration module includes multiple USB attack units, each of which is configured with a corresponding attack execution component. The attack execution component includes a hardware driver module, an instruction parsing module, and a behavior execution module. The hardware driver module is adapted to the hardware interface of different USB attack units, the instruction parsing module decodes and converts preset attack instructions, and the behavior execution module drives the hardware to complete the attack operation. The defense configuration module is used to configure USB security defense policies for the target device; The data monitoring module is used to capture and record data interaction information during the attack and defense process.

2. The USB-based network security attack and defense demonstration system according to claim 1, characterized in that, The USB attack unit includes a malicious USB flash drive attack unit, an optical disc tampering theft unit, a wireless keyboard theft unit, a mobile phone Trojan theft unit, a WiFi email interception unit, a WiFi Web data interception unit, a classified storage medium data recovery unit, a USB Rubber Ducky attack unit, a firmware tampering attack unit, a WHID attack unit, a USB sniffing attack unit, a USB device cross-theft unit, and a USB mouse tampering unit.

3. The USB-based network security attack and defense demonstration system according to claim 2, characterized in that, The malicious USB flash drive attack unit includes a customized USB flash drive component. The customized USB flash drive component has a built-in Trojan program that can disguise itself as an ordinary storage device. After being connected to the target device, it can automatically steal files containing sensitive keywords in a specified directory. The sensitive keywords can be preset through a configuration file and support multiple keyword combinations. The USB Rubber Ducky attack unit includes a simulated keyboard execution component. The simulated keyboard execution component pre-stores attack command sequences and automatically simulates keyboard input behavior after being connected to the target device, quickly executing preset attack operations. The firmware tampering attack unit includes a firmware read / write component and a USB device modification component. The firmware read / write component is used to read, modify, and rewrite the USB device firmware. The USB device modification component includes an Arduino Leonardo development board, an ESP32S3 development board, and a USB housing kit. The WHID attack unit includes a wireless communication component with a communication distance of not less than 20 meters. It can be integrated into a human-machine interface device, which includes a keyboard and a mouse. It sends attack commands and transmits stolen data to the target device via a wireless link. The USB sniffing attack unit includes a data capture component and an analysis component; The data capture component is used to capture control transmissions and batch transmissions of various communication data between the USB device and the target device. The analysis component is used to parse sensitive information in the captured data and generate an attack analysis report.

4. The USB-based network security attack and defense demonstration system according to claim 3, characterized in that, The defense configuration module supports the following defense strategies: USB port access permission control, disabling unauthorized USB devices, USB device firmware integrity verification, real-time scanning of malicious programs, and encrypted transmission of USB communication data. The defense strategy configuration also includes a real-time attack behavior interception module, which blocks the operation and triggers an alarm when an operation matching the attack characteristics is detected. The defense strategies can be customized and deployed with one click through a visual interface.

5. The USB-based network security attack and defense demonstration system according to claim 4, characterized in that, The data monitoring module records data including attack trigger time, attack operation steps, data transmission traffic, target device response status, defense strategy execution logs, attack success rate, and defense interception rate. The data can be exported to standardized format files and can be displayed intuitively in the form of line charts, bar charts, and pie charts to show key indicators of the attack and defense process.

6. The USB-based network security attack and defense demonstration system according to claim 5, characterized in that, The USB device cross-data theft unit is used for covert data theft between multiple target devices via USB devices; The USB mouse transfer unit integrates a storage module, which automatically copies confidential files from the target device during normal mouse use; The system also includes a comprehensive exercise module, which includes an exercise scenario parameter configuration unit that supports customizing parameters such as the number of target devices, system environment, attack intensity, and defense level to simulate attack and defense scenarios of varying complexity. The attack demonstration module and the defense configuration module work together to dynamically adjust attack and defense strategies and evaluate the exercise effect.

7. The USB-based network security attack and defense demonstration system according to claim 6, characterized in that, The customized USB flash drive components of the malicious USB flash drive attack unit include an intelligent file fragmentation and theft and breakpoint resume module. The intelligent file fragmentation theft and breakpoint resume module includes a dynamic fragmentation adaptation subunit, a breakpoint encrypted storage subunit, and a disguised transmission subunit. The dynamic fragmentation adaptation subunit first detects the target device's storage input and output rates, background process usage, and security software monitoring frequency. The dynamic fragmentation adaptation subunit detects the target device's status every 1-3 seconds and dynamically adjusts the fragment size based on the real-time detection results to ensure the theft process matches the target device's operating status. It automatically splits sensitive files into dynamic intervals of 512KB-10MB; specifically, it splits into small fragments of 512KB-2MB under high load scenarios and large fragments of 5-10MB under low load scenarios. Furthermore, during fragmentation, random byte padding is applied to the file header and footer. The system employs several techniques to encrypt and store breakpoint records. The encrypted storage subunit uses the AES-256 algorithm to encrypt breakpoint records, hiding the storage location within the unallocated sectors of the USB flash drive. This encryption can only be read using a dedicated decryption command specific to the customized USB flash drive component. This dedicated decryption command includes a hardware identifier and a dynamic key. The hardware identifier is the unique chip serial number of the customized USB flash drive, and the dynamic key is generated and transmitted in real-time by the control terminal. During fragmented transmission, the spoofing transmission subunit, in addition to using random 8-16 character combinations of uppercase and lowercase letters and numbers in the filename, also simulates the header structure of commonly used file formats on the target device. Simultaneously, it intersperses the transmission of 10-20KB of meaningless padding data blocks, with the transmission interval of these padding data blocks matching the normal file read / write interval of the target device.

8. A USB-based network security attack and defense demonstration method, characterized in that, Includes the following steps: S1) By pre-setting sensitive keywords, attack command sequences, and fragment size threshold parameters in the configuration file, the communication pairing between the attack unit and the control terminal is completed; The S2 system launches a comprehensive attack through multiple attack units, including the malicious USB flash drive attack unit, USB Rubber Ducky attack unit, and firmware tampering attack unit, which are mounted on the attack demonstration module. The malicious USB flash drive is disguised as an ordinary storage device. After being connected to the target device, it dynamically splits and steals files based on preset sensitive keywords through the intelligent file segmentation and breakpoint resume module. The USB Rubber Ducky simulates a keyboard that quickly executes a preset attack command sequence. The firmware tampering attack unit modifies the device using Arduino Leonardo and ESP32S3 development boards and rewrites the firmware to implant malicious code. The WHID attack unit remotely sends attack commands via 2.4G wireless communication. The USB sniffing attack unit captures and parses USB communication data. The USB device cross-stealing unit and the USB mouse transfer unit respectively realize covert stealing of multiple devices and copying of files during normal use. S3) While the attack is being carried out, the defense configuration module can customize and configure defense strategies such as USB port access permission control, unauthorized device disabling, and firmware integrity verification for the target device through a visual interface and deploy them with one click to defend against various attack behaviors in real time. S4) The data monitoring module captures the attack trigger time, operation steps, data traffic, target device response status and defense strategy execution logs throughout the attack and defense process. It supports exporting data to standardized format files or displaying key indicators intuitively through charts. S5) The comprehensive exercise module imports real USB security incident cases, simulates actual attack scenarios, coordinates the attack demonstration module and the defense configuration module to dynamically adjust the attack and defense strategies, and conducts an effectiveness evaluation after the exercise is completed. S6) Based on the information recorded by the data monitoring module, generate an attack and defense review report to identify attack vulnerabilities and defense optimization directions.

9. A USB-based network security attack and defense demonstration device, characterized in that, It includes attack demonstration components, defense configuration components, data monitoring components, comprehensive exercise components, and auxiliary components; The attack demonstration component is located in the attack module area of ​​the device and is equipped with an independent USB interface panel. The attack demonstration component is physically connected to the target device through the USB interface panel and is also connected to the main control board of the device through an internal data cable. The defense configuration component includes a visual configuration terminal and a defense strategy processing module. The visual configuration terminal is located in the front-end operation area of ​​the device, and the defense strategy processing module is built into the device and connected to the visual configuration terminal via a ribbon cable. The defense configuration component establishes a communication connection with the target device through the main control board. The data monitoring component includes a data acquisition module, a storage module, and a visualization module. The data acquisition module and the storage module are integrated into the main control board inside the device. The visualization module is embedded in the front end of the device. The data acquisition module is connected to the attack demonstration component and the defense configuration component through an internal bus. The storage module and the visualization module are directly connected through a ribbon cable. The storage module is connected to an external device through a USB interface to support data export. The integrated training component includes a case import interface and a training control unit. The case import interface is located on the side of the device, and the training control unit is integrated with the main control board. The case import interface is connected to the main control board via a data cable, and the training control unit is connected to the attack demonstration component and the defense configuration component via an internal bus. The auxiliary components include a power supply module, an interface adapter module, and a data transmission module. The power supply module is installed at the bottom of the device and is connected to each functional component for power supply via a power cord. The interface adapter module is integrated at the rear of the USB interface panel and is bidirectionally connected to the USB interface panel and the main control board. The data transmission module is embedded in the main control board.

10. A USB-based network security attack and defense demonstration storage medium, characterized in that, The storage medium is a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of the USB-based cybersecurity attack and defense demonstration method as described in claim 8.