首页> 外文会议>2011 IEEE International System Conference >Risks associated with USB Hardware Trojan devices used by insiders
【24h】

Risks associated with USB Hardware Trojan devices used by insiders

机译:内部人员使用的USB硬件Trojan设备相关的风险

获取原文

摘要

This paper extends the discussion of potential damage that can be done by Hardware Trojan Horse devices by discussing the specific risks associated with an Insider's use of such a device to circumvent established security policies, even when these are implemented with state of the art Endpoint Security Solutions. The paper argues that a specific category of Hardware Trojan Horse devices, those implemented as functional peripheral devices, are particularly dangerous when used by a malicious Insider. The research discusses the implementation of a proof of concept Hardware Trojan Horse device, implemented as a USB Human Interface Devices, that exploits unintended USB channels to exfiltrate data from a computer. The work discusses unintended USB channels, paying particular attention to the observability of the channel in operation. Various scenarios are presented to show that Hardware Trojan Horse devices implemented as peripheral devices can be used to prosecute a wide variety of attacks that are not mitigated by modern defensive techniques. The work demonstrates that a Hardware Trojan Horse device and physical access by a malicious Insider are sufficient to compromise a modern computer system. The paper argues that the study of Hardware Trojan devices must become an integral part of research on Insider Threats.
机译:本文通过讨论与内部人员使用此类设备规避既定安全策略相关的特定风险,扩大了对硬件特洛伊木马设备可能造成的损害的讨论,即使这些风险是通过最新的端点安全解决方案实施的也是如此。该论文认为,特定类别的硬件特洛伊木马设备(作为功能性外围设备实现)在被恶意内部人员使用时特别危险。该研究讨论了概念验证硬件Trojan Horse设备的实现,该设备被实现为USB人机接口设备,该设备利用意外的USB通道从计算机中窃取数据。该作品讨论了意外的USB通道,并特别注意了该通道在运行中的可观察性。呈现了各种情况,以表明实现为外围设备的硬件特洛伊木马设备可用于起诉现代防御技术无法缓解的各种攻击。这项工作表明,硬件特洛伊木马设备和恶意内部人员的物理访问足以损害现代计算机系统。该论文认为,对硬件木马设备的研究必须成为内部威胁研究的组成部分。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号