Security Controls for Monitored Use of USB Devices Based on the NIST Risk Management Framework
Bibliographic record
Abstract
Universal Serial Bus (USB) is one of the most popular and extensively used technologies in the world due to its user friendly nature and ease of use. It is also one of the most widely targeted technologies by hackers. Hackers have discovered a vulnerability in the USB technology, known as "Bad USB", that allows them to plant and execute a malware at any desired time once the USB device is connected to the operating system (OS). The malware remains undetected from the security applications installed in the OS because it is embedded in the firmware of the USB device and security applications usually do not scan the firmware. This makes the malware pose a significant risk to the OS since it can stay undetected and can execute itself at a pre-planned time without the knowledge of the user or the security applications installed in the OS. This research paper aims to address this vulnerability and mitigate the risks posed by it by (i) building a Bad USB device and testing it in a controlled OS environment, studying the results and (ii) recommending security controls based on the U. S. National Institute of Standards and Technology risk management framework. The recommendations are divided into three categories, those are Technical, Operational and Management. Using the outlined solutions and following the recommendations provided in this paper, organizations and individual users can protect their information assets from being exploited by any risk posed by the Bad USB threat.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame distilled prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.
Codex and Gemma teacher scores by category
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.000 | 0.000 |
| Meta-epidemiology (narrow) | 0.000 | 0.000 |
| Meta-epidemiology (broad) | 0.000 | 0.000 |
| Bibliometrics | 0.000 | 0.000 |
| Science and technology studies | 0.000 | 0.000 |
| Scholarly communication | 0.000 | 0.000 |
| Open science | 0.001 | 0.000 |
| Research integrity | 0.000 | 0.000 |
| Insufficient payload (model declined to judge) | 0.000 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one teacher head, not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".