Reducing USB Attack Surface: A Lightweight Authentication and Delegation Protocol

被引:0
|
作者
Mahboubi, Arash [1 ]
Camtepe, Seyit [2 ]
Morarji, Hasmukh [1 ]
机构
[1] Queensland Univ Technol, Elect & Comp Engn, Brisbane, Qld, Australia
[2] CSIRO, Data61, Sydney, NSW, Australia
关键词
USB security; USB attack surface; Internet of Things (IoT); mobile malware; Coloured Petri Nets (CPN) modelling; epidemic model; PROPAGATION; MALWARE;
D O I
暂无
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
A privately owned smart device connected to a corporate network using a USB connection creates a potential channel for malware infection and its subsequent spread. For example, air-gapped (a.k.a. isolated) systems are considered to be the most secure and safest places for storing critical datasets. However, unlike network communications, USB connection streams have no authentication and filtering. Consequently, intentional or unintentional piggybacking of a malware infected USB storage or a mobile device through the air-gap is sufficient to spread infection into such systems. Our findings show that the contact rate has an exceptional impact on malware spread and destabilizing free malware equilibrium. This work proposes a USB authentication and delegation protocol based on radiofrequency identification (RFID) in order to stabilize the free malware equilibrium in air-gapped networks. The proposed protocol is modelled using Coloured Petri nets (CPN) and the model is verified and validated through CPN tools.
引用
收藏
页数:7
相关论文
共 50 条
  • [41] A lightweight identity authentication protocol for wireless networks
    Badra, M
    Serhrouchni, A
    Urien, P
    COMPUTER COMMUNICATIONS, 2004, 27 (17) : 1738 - 1745
  • [42] An Anonymous Authentication Protocol With Delegation and Revocation for Content Delivery Networks
    Xiong, Hu
    Zhou, Zhida
    Wang, Lili
    Zhao, Zetong
    Huang, Xin
    Zhang, Hao
    IEEE SYSTEMS JOURNAL, 2022, 16 (03): : 4118 - 4129
  • [43] A Lightweight Continuous Authentication Protocol for the Internet of Things
    Chuang, Yo-Hsuan
    Lo, Nai-Wei
    Yang, Cheng-Ying
    Tang, Ssu-Wei
    SENSORS, 2018, 18 (04)
  • [44] A Lightweight Key Agreement Protocol with Authentication Capability
    Guan, Albert
    INTERNATIONAL JOURNAL OF FOUNDATIONS OF COMPUTER SCIENCE, 2021, 32 (04) : 389 - 404
  • [45] Provably Lightweight RFID Mutual Authentication Protocol
    Alakrut, Rima Hussin Embrak
    Samsudin, Azman
    Syafalni, Alfin
    INTERNATIONAL JOURNAL OF SECURITY AND ITS APPLICATIONS, 2013, 7 (04): : 71 - 89
  • [46] A lightweight identity authentication protocol for vehicular networks
    Li, Jung-Shian
    Liu, Kun-Hsuan
    TELECOMMUNICATION SYSTEMS, 2013, 53 (04) : 425 - 438
  • [47] A lightweight mutual authentication protocol for RFID networks
    Luo, ZW
    Chan, T
    Li, JS
    ICEBE 2005: IEEE INTERNATIONAL CONFERENCE ON E-BUSINESS ENGINEERING, PROCEEDINGS, 2005, : 620 - 625
  • [48] LIMAP: A Lightweight Multilayer Authentication Protocol for WBAN
    Das, Purbasha
    Vashisth, Anjali
    Chadha, Devanshi
    Kumar, S. Ananda
    Banerjee, Amit
    Shiaeles, Stavros
    WIRELESS PERSONAL COMMUNICATIONS, 2021, 121 (04) : 2857 - 2884
  • [49] A Novel Lightweight Authentication Protocol for YML Framework
    Lv, Xin
    Chen, Hao
    Xu, Feng
    Mao, Yingchi
    PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND SERVICE SYSTEM (CSSS), 2014, 109 : 645 - 648
  • [50] A Lightweight Mutual Authentication Protocol for Internet of Vehicles
    Tabany, Myasar
    Syed, Mohiuddin
    JOURNAL OF ADVANCES IN INFORMATION TECHNOLOGY, 2024, 15 (02) : 155 - 163