Netinfo Security ›› 2016, Vol. 16 ›› Issue (2): 7-8.doi: 10.3969/j.issn.1671-1122.2016.02.002

• Orginal Article • Previous Articles     Next Articles

Research on Protection Scheme for Malicious USB Storage Devices in APT

Cheng TAN1, Ruyi DENG1, Lina WANG1(), Jing MA2   

  1. 1. School of Computer, Wuhan University, Wuhan Hubei 430072, China
    2. Key Laboratory of Information Security Technology, Beijing 100072, China
  • Received:2015-09-07 Online:2016-02-10 Published:2020-05-13

Abstract:

This paper designs a protection scheme for malicious USB storage devices in APT. The protection scheme constructs a white list of USB storage devices, and only allows the USB storage devices in white list to interact with the computer system, in order to prevent customized malicious USB storage devices in APT to get unauthorized access to the host. The scheme makes USB storage devices bind with staff at all levels and write-protects the specific USB storage device on the specific host so as to effectively prevent APT attackers utilizing social engineering to induce insiders’ exceeding accesses to system data, and prevents hidden malware stealing data from the system through monitoring the process behavior that writes data to USB storage devices. As a result, the protection scheme can guard against data theft and leakage and has good practicality. This paper describes some functional tests about the protection scheme. The test results show that the scheme is feasible.

Key words: advanced persistent threat, USB storage device, white list, Windows filter driver, data leakage prevention

CLC Number: