• DocumentCode
    3402434
  • Title

    Host Identification via USB Fingerprinting

  • Author

    Letaw, Lara ; Pletcher, Joe ; Butler, Kevin

  • Author_Institution
    Dept. of Comput. & Inf. Sci., Univ. of Oregon, Eugene, OR, USA
  • fYear
    2011
  • fDate
    26-26 May 2011
  • Firstpage
    1
  • Lastpage
    9
  • Abstract
    Determining a computer´s identity is a challenge of critical importance to a forensics investigator. However, relay and impersonation attacks can defeat even computers that contain trusted computing hardware. In this paper, we consider how to leverage the virtually ubiquitous USB interface to uniquely identify computers based on the characteristics of their hardware, firmware, and software USB stacks. We use a USB protocol analyzer to collect data on 24 machines connected to a range of different USB devices, and demonstrate through machine learning classification techniques that we can differentiate not only between operating systems, but between seemingly unnoticeable differences in machine model types as well. We also show that we can differentiate between real and virtualized hosts responding to USB stimuli, and point to new ways of recognizing remote attacks. These results are a first step in showing that USB is a novel and effective means of identifying machines, and a valuable tool in the arsenal of a forensics kit.
  • Keywords
    computer forensics; firmware; learning (artificial intelligence); pattern classification; trusted computing; USB fingerprinting; USB protocol analyzer; computer identity; firmware USB stacks; forensics investigator; hardware USB stacks; host identification; impersonation attacks; machine learning classification techniques; operating systems; relay attacks; remote attacks; software USB stacks; trusted computing hardware; ubiquitous USB interface; Computers; Decision trees; Hardware; Operating systems; Timing; Universal Serial Bus; Forensics; USB; identification fingerprinting; security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Systematic Approaches to Digital Forensic Engineering (SADFE), 2011 IEEE Sixth International Workshop on
  • Conference_Location
    Oakland, CA
  • Print_ISBN
    978-1-4673-1242-4
  • Type

    conf

  • DOI
    10.1109/SADFE.2011.9
  • Filename
    6159115