DocumentCode :
3402434
Title :
Host Identification via USB Fingerprinting
Author :
Letaw, Lara ; Pletcher, Joe ; Butler, Kevin
Author_Institution :
Dept. of Comput. & Inf. Sci., Univ. of Oregon, Eugene, OR, USA
fYear :
2011
fDate :
26-26 May 2011
Firstpage :
1
Lastpage :
9
Abstract :
Determining a computer´s identity is a challenge of critical importance to a forensics investigator. However, relay and impersonation attacks can defeat even computers that contain trusted computing hardware. In this paper, we consider how to leverage the virtually ubiquitous USB interface to uniquely identify computers based on the characteristics of their hardware, firmware, and software USB stacks. We use a USB protocol analyzer to collect data on 24 machines connected to a range of different USB devices, and demonstrate through machine learning classification techniques that we can differentiate not only between operating systems, but between seemingly unnoticeable differences in machine model types as well. We also show that we can differentiate between real and virtualized hosts responding to USB stimuli, and point to new ways of recognizing remote attacks. These results are a first step in showing that USB is a novel and effective means of identifying machines, and a valuable tool in the arsenal of a forensics kit.
Keywords :
computer forensics; firmware; learning (artificial intelligence); pattern classification; trusted computing; USB fingerprinting; USB protocol analyzer; computer identity; firmware USB stacks; forensics investigator; hardware USB stacks; host identification; impersonation attacks; machine learning classification techniques; operating systems; relay attacks; remote attacks; software USB stacks; trusted computing hardware; ubiquitous USB interface; Computers; Decision trees; Hardware; Operating systems; Timing; Universal Serial Bus; Forensics; USB; identification fingerprinting; security;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Systematic Approaches to Digital Forensic Engineering (SADFE), 2011 IEEE Sixth International Workshop on
Conference_Location :
Oakland, CA
Print_ISBN :
978-1-4673-1242-4
Type :
conf
DOI :
10.1109/SADFE.2011.9
Filename :
6159115
Link To Document :
بازگشت