Home > Ask the Security Experts > Application Security Questions & Answers > Can USB compromise the security of an embedded mobile device?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Can USB compromise the security of an embedded mobile device?

Michael Cobb, featured expert EXPERT RESPONSE FROM: Michael Cobb, featured expert

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 17 October 2008
Can the security of an embedded device be compromised using USB? Specifically, when a device is connected to the host PC through USB, can the device be broken into by using an application that runs on the host PC?


BROWSE BY TAG
Application Security,   Wireless Network Security: Setup and Tools,   Handheld and Mobile Device Security Best Practices,   Enterprise Network Security,   Enterprise Data Protection,   Enterprise Data Governance,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Application Security
Are Web application penetration tests still important?
What does 'invoked by uid 78' mean?
How secure are iPhone App Store mobile applications?
What security software should be installed on Internet café computers?
Are message stubs a secure part of email retention policies?
How does a Web server model differ from an application server model?
Can Google Earth and other mash-up applications threaten enterprise security?
Do European laws prevent a U.S. company from blocking spam?
Can one antivirus program be used to get rid of spyware?
How to prevent cross-site scripting (XSS) session hijacking

Handheld and Mobile Device Security Best Practices
Unified communications: Securing a converged infrastructure
RIM patches serious BlackBerry Attachment Service flaws
How secure are iPhone App Store mobile applications?
Is there a spy on my mobile device?
Mobile phones win during Pwn2Own contest
Latest Apple iPhone features prompt security concerns
Apple iPhone app could boost two-factor
What Obama's Blackberry means for mobile device security
SMS mobile worm attacks Symbian smartphones
Smartphone security lacking at many businesses
Handheld and Mobile Device Security Best Practices Research

Enterprise Data Governance
Risk management must include physical-logical security convergence
Simple information security mistakes can cause data loss, says expert
Organizations struggle with data leakage prevention, rights management
Encryption in data management should never be ignored, expert says
Attackers cash in on fundamental data handling mistakes, Verizon finds
Data loss prevention benefits in the real world
Mass., Nev. data protection laws wrong, ineffective
Cybersecurity hearing highlights inadequacy of PCI DSS
Enforcing a vendor risk assessment to avoid outsourcing security risks
How to Secure Cloud Computing

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
cut-and-paste attack  (SearchSecurity.com)
data splitting  (SearchSecurity.com)
deperimeterization  (SearchSecurity.com)
Google hacking  (SearchSecurity.com)
masquerade  (SearchSecurity.com)
snooping  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


Indeed it can. Let's look at how USB devices connect to a PC, and you'll see why. Universal Serial Bus, commonly referred to by just its acronym USB, is a serial bus standard used to connect devices to a host computer. A bus is a subsystem that transfers data between computers or among computer components. Being a serial bus, USB sends data sequentially one bit at a time. It was created to improve the plug-and-play capabilities of the increasing number of devices people wanted to connect to their computers.

If you remember back to the early days of personal PCs, it was a real chore to connect a new device. It was often necessary to set jumpers, add extra serial or parallel ports, install device drivers and reboot, probably several times. Now thanks to USB, a single standardized interface socket, those days are gone. USB devices can be connected and disconnected without rebooting the computer or turning off the device. It has, of course, been widely adopted as the connection interface of choice, and according to the USB Implementers Forum, as of 2008, there are about 2 billion wired USB devices in the world.

USB, however, is only a standard to interface devices to a host computer. It doesn't provide any security features to filter the data that passes through the connection. In this respect, it is exactly the same as an Ethernet or printer cable; any device connected to a PC via a USB connection can be accessed by an application running on the host PC. Therefore, if the PC has been infected by malware, for example, the malware could access data on a portable hard drive that is connected to the PC via a USB cable. The danger could occur in reverse as well, should a U3-enabled USB drive with auto-launching applications (including malware) connect to a PC could and then access data on the host PC or logs all characters typed on the computer keyboard.

To mitigate these risks, you can disable all USB ports on a PC, but this is rarely practical because the ports may be required for devices such as keyboards and mice. If your organization runs a Windows-based network, then you can control USB drives using Active Directory. Individuals and groups that do not need to use a USB drive can be denied access to the ubstor.pnf and ubstor.inf files through an Active Directory group policy. New to Windows Vista, an administrator can now allow users to install only devices that are on an approved list or deny read or write access to devices that are removable or that use removable media. There are also third-party programs that provide a range of access controls for USB drives.

Hopefully, you can see that USB is merely a means to connect a device to a PC, not to control what the device does. In order to protect the USB device, you will need to provide security measures, which should, of course, be supported by policies that cover and clearly communicate the appropriate use of USB devices.

More information:

  • See how earlier this year, hackers had been discovered corrupting USB sticks.
  • Rob Israel likes the iPod as much as the next guy. But he's not about to let employees plug the mobile devices into their work machines.




  • Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts