Peripheral Device Security Module for USB Sniffing Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures fail to adequately protect detachable peripheral devices, such as keyboards and USB drives, from security breaches like sniffing and impersonation, as they lack physical security and require impractical mechanical locks for protection.
Innovation Solution
A software-based security system that monitors and manages the attachment and detachment of peripheral devices, requiring authorization through password entry to enable communication with the computer, thereby preventing unauthorized access and breaches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If detachable peripheral devices are used for ease of operation and adaptability, then device versatility and ease of operation are improved, but security reliability deteriorates due to vulnerability to sniffing and impersonation attacks
Solution Approach 1:
The patent replaces mechanical security measures (physical locks on device ports) with a software-based authorization system. The security module monitors device attachments and manages authorization information in memory, using software logic to prevent sniffing and impersonation attacks without requiring physical modifications to hardware ports.
Solution Approach 2:
The patent introduces an intermediary security module that acts as a mediator between peripheral devices and the computer system. This module intercepts device attachment events, manages authorization information, and controls whether devices are permitted to communicate, thereby protecting against security breaches while maintaining device detachability.
2Reliability
If mechanical locks are installed on device ports to improve security, then security reliability is improved, but device complexity and ease of operation worsen due to impracticality in large organizations
Solution Approach 1:
The patent replaces mechanical locks with a software-based authorization system that uses memory structures to store and manage device authorization information. This eliminates the need for physical security measures while providing equivalent or superior protection against sniffing and impersonation attacks.
Solution Approach 2:
The security module automatically monitors device attachments and manages authorization without requiring manual intervention or physical security measures. The system self-manages the security process by detecting when devices are attached or detached and updating authorization information accordingly, eliminating the need for complex mechanical lock management.
3Reliability
If end point security products are used to control traffic, then security against network attacks is improved, but protection against peripheral device breaches worsens due to inability to detect detached device threats
Solution Approach 1:
The patent implements preliminary security measures by establishing authorization information for devices before they are attached to the computer. The security module proactively manages device authorization states and prepares security responses in advance, enabling it to immediately detect and respond to unauthorized device attachments or sniffing attempts.
Solution Approach 2:
The security module continuously monitors device attachment events and provides feedback by updating authorization information in real-time. When a device is detached or reattached, the system receives feedback about the device state and automatically adjusts security measures, ensuring continuous protection against peripheral device attacks.
Data Source
AI summary
A security system with methodology for defending against security breaches of peripheral devices is described. In one embodiment, for example, a method is described for protecting a computer from security breaches involving devices that may be attached to the computer, the method comprises steps of: when a device is first attached to the computer, specifying authorization information indicating that the device is allowed to communicate with the computer; detecting detachment of the device from the computer; updating the authorization information to indicate that the device is no longer authorized to communicate with the computer; and upon reattachment of the device, blocking communication with the device while the device remains unauthorized, thereby preventing a security breach involving the device.


