USB Protocol: Difference between revisions

From Elvis Wiki
(Created page with "== Introduction == Description what this documentation is about. == USB protocol == Das USB-Protokoll zeichnet sich durch seine hohe Flexibilit¨at aus, die sich insbeson- dere in der Unterst¨utzung sogenannter Kompositger¨ate zeigt. Kompositger¨ate k¨onnen mehrere Konfigurationen und Schnittstellen enthalten, wobei jede Schnittstelle als eigenst¨andige Einheit fungiert. Ein typisches Beispiel ist ein USB-Headset, das eine Konfiguration aufweist, welche wiederum...")
 
No edit summary
 
(8 intermediate revisions by 2 users not shown)
Line 1: Line 1:
== Introduction ==  
== Introduction ==  


Description what this documentation is about.
The USB protocol is a cornerstone of modern computer communication, offering high flexibility and universal compatibility with a wide range of devices. However, this versatility comes with significant security risks. This document provides an overview of the USB protocol, highlighting its key features, such as composite device support and device enumeration. It also explores the associated security threats, including malware transmission, abuse of HID devices, and vulnerabilities due to unencrypted data transmission. By examining these aspects, the document sheds light on the balance between functionality and security in USB technology.


== USB protocol ==
== Protocol ==  


Das USB-Protokoll zeichnet sich durch seine hohe Flexibilit¨at aus, die sich insbeson-
The USB protocol is characterized by its high flexibility, particularly in its support for so-called composite devices. Composite devices can contain multiple configurations and interfaces, with each interface functioning as an independent unit. A typical example is a USB headset, which features a configuration that includes four interfaces: a keyboard for volume control, a microphone, and two speakers. This flexibility enables various functions to be combined into a single USB device.
dere in der Unterst¨utzung sogenannter Kompositger¨ate zeigt. Kompositger¨ate k¨onnen
mehrere Konfigurationen und Schnittstellen enthalten, wobei jede Schnittstelle als
eigenst¨andige Einheit fungiert. Ein typisches Beispiel ist ein USB-Headset, das eine
Konfiguration aufweist, welche wiederum vier Schnittstellen umfasst: eine Tastatur zur
Lautst¨arkeregelung, ein Mikrofon und zwei Lautsprecher. Diese Flexibilit¨at erm¨oglicht
es, verschiedene Funktionen in einem einzigen USB-Ger¨at zu kombinieren. Allgemeine
Klassenspezifikationen
Seit der Einf¨uhrung von USB 1.0 wurde das Konzept der ”Common Class Specifi-
cations” etabliert, um eine Standardisierung verschiedener Arten von Peripherieger¨aten
zu gew¨ahrleisten. Eine USB-Klasse ist eine Gruppe von einer oder mehreren Schnittstellen,
die zusammen eine erweiterte Funktionalit¨at bieten. Eine der bekanntesten Klassen ist
die ”Human Interface Device” (HID) Klasse, die es dem USB-Hostcontroller erm¨oglicht,
mit Eingabeger¨aten wie Tastaturen und M¨ausen zu kommunizieren. Eine weitere be-
deutende Klasse ist die USB-Massenspeicherklasse, die definiert, wie Daten zwischen
dem Host und Speicherger¨aten ¨ubertragen werden.
4
Chapter 2. Technischer Hintergrund
Kompositger¨ate kombinieren mehrere Klassen, um eine umfassendere Funktion-
alit¨at zu bieten. Beispielsweise kann ein USB-Headset sowohl die HID-Klasse als auch
die Audioklasse nutzen, um sowohl Eingaben als auch Audioausgaben zu erm¨oglichen.
Dieses Designprinzip, bei dem USB-Peripherieger¨ate durch die Kombination mehrerer
Klassen geschaffen werden, hat nicht nur die Flexibilit¨at des USB-Protokolls erh¨oht,
sondern auch Sicherheitsherausforderungen mit sich gebracht.
Nach dem Anschluss eines USB-Ger¨ats an ein Hostsystem erkennt der USB-Hostcontroller
die Anwesenheit des Ger¨ats und dessen ¨Ubertragungsgeschwindigkeit, indem er die
Spannungs¨anderungen an den Datenpins ¨uberpr¨uft. Daraufhin beginnt die sogenannte
Enumeration, eine Prozedur zur Identifikation und Konfiguration des Ger¨ats. Dieser
Prozess startet mit dem Befehl GetDeviceDescriptors, bei dem der Host nach Identi-
fikationsinformationen des Ger¨ats fragt, wie beispielsweise Hersteller, Vendor ID (VID),
Produkt ID (PID) und Seriennummer.
Nach der Abfrage setzt der Hostcontroller das Ger¨at zur¨uck und weist ihm eine
Adresse f¨ur die zuk¨unftige Kommunikation zu. Anschließend erfolgt eine GetConfigDescriptors-
Anfrage, um alle verf¨ugbaren Konfigurationen des Ger¨ats abzurufen. USB-Ger¨ate
k¨onnen eine oder mehrere Konfigurationen haben, wobei jedoch immer nur eine Konfig-
uration aktiv sein kann. Jede Konfiguration kann eine oder mehrere Schnittstellen en-
thalten, die ¨uber die GetInterfaceDescriptors-Anfrage ermittelt werden. Diese Schnittstellen
repr¨asentieren die essenziellen funktionalen Einheiten, die von verschiedenen Treibern
im Betriebssystem bedient werden. Nach Abschluss dieser Anfrage l¨adt das Betrieb-
ssystem die entsprechenden Treiber und ger¨atespezifische Subprotokolle (z. B. HID,
Storage) treten in Betrieb.


== Security threads ==  
=== General Class Specifications ===


USB-Ger¨ate stellen ein großes Sicherheitsrisiko da, weil sie trotz ihrer weiten verbre-
Since the introduction of USB 1.0, the concept of "Common Class Specifications" has been established to standardize various types of peripheral devices. A USB class is a group of one or more interfaces that collectively provide enhanced functionality. One of the most well-known classes is the "Human Interface Device" (HID) class, which allows the USB host controller to communicate with input devices such as keyboards and mice. Another significant class is the USB Mass Storage class, which defines how data is transferred between the host and storage devices.
itung eine geringe Sicherheit bieten. Ein besonderes Risiko bei USB-Ger¨aten ist der
USB-Stick. Er wird h¨aufig als Tr¨ager von Schadsoftware wie Viren, W¨urmern und
5
Chapter 2. Technischer Hintergrund
Trojanern misbraucht. Diese Schadsoftware kann sich leicht verbreiten, da USB-Sticks
einfach zwischen verschiedenen Computern ausgetauscht werden k¨onnen. Ein bekan-
ntes Beispiel f¨ur eine Schwachstelle ist die AutoRun-Funktion in ¨alteren Windows-
Versionen, insbesondere Windows XP. Diese Funktion erm¨oglichte es USB-Ger¨aten,
Programme automatisch zu starten, sobald sie an einen Computer angeschlossen wur-
den. Dies wurde h¨aufig genutzt, um Treiber zu installieren, aber auch, um unbemerkt
Schadsoftware auszuf¨uhren. In sp¨ateren Windows-Versionen wurde diese Funktion je-
doch stark eingeschr¨ankt, um das Risiko zu minimieren. [SLL21] [TSK+18]
Ein weiteres ernsthaftes Risiko bei USB-Ger¨aten besteht in der M¨oglichkeit, HID-
Ger¨ate zu missbrauchen. Da HID-Ger¨ate vertrauensw¨urdig erscheinen, k¨onnen sie
leicht als Angriffsvektor genutzt werden. Beispielsweise kann ein manipuliertes USB-
Ger¨at als Tastatur auftreten und unbemerkt sch¨adliche Eingaben ausf¨uhren, um Daten
zu stehlen oder Malware zu installieren. Diese Angriffe, wie etwa das O.MG Cable,
nutzen die Tatsache aus, dass die meisten Betriebssysteme HID-Ger¨aten vertrauen
und ihnen automatisch Rechte f¨ur Benutzereingaben einr¨aumen. Durch solche An-
griffe k¨onnen Angreifer unbemerkt Befehle ausf¨uhren und Zugang zu sensiblen Daten
erlangen, was erhebliche Sicherheits- und Datenschutzrisiken birgt. [SSN+23]
Ein weitere Hauptprobleme bei der USB-Technologie ist zudem die fehlende Ver-
schl¨usselung des Datenverkehrs. Die Daten¨ubertragung zwischen USB-Ger¨aten und
dem Host-Rechner erfolgt im Klartext, was sie f¨ur passive Abh¨orangriffe anf¨allig macht.
Angreifer k¨onnen mit relativ einfachen Mitteln den Datenverkehr auf der Busleitung
mitschneiden und sensible Informationen abfangen.[NLF16] Dabei stellt die Tastertur
die gr¨oßte gef¨ahrdung da, weil sie als eingabe sensible Daten genutz wird z.B von
Passw¨orter


== Description ==
Composite devices combine multiple classes to provide more comprehensive functionality. For example, a USB headset can utilize both the HID class and the Audio class to support input and output functions. While this design principle has increased the flexibility of the USB protocol, it has also introduced security challenges.


=== Step 1 ===
=== USB Device Enumeration ===


Enter these commands in the shell
When a USB device is connected to a host system, the USB host controller detects the presence of the device and its transfer speed by monitoring voltage changes on the data pins. This triggers the process known as enumeration, which involves identifying and configuring the device. The process begins with the GetDeviceDescriptors command, where the host queries the device for identification information such as the manufacturer, Vendor ID (VID), Product ID (PID), and serial number.


echo foo
After querying, the host controller resets the device and assigns it an address for future communication. This is followed by a GetConfigDescriptors request to retrieve all available configurations of the device. USB devices can have one or more configurations, but only one configuration can be active at a time. Each configuration may include one or more interfaces, which are identified through the GetInterfaceDescriptors request. These interfaces represent the essential functional units handled by different drivers within the operating system. After completing these steps, the operating system loads the appropriate drivers, and device-specific subprotocols (e.g., HID, Storage) are activated.
echo bar


=== Step 2 ===
[[File:USB_enumeration_procedure.png]]


Make sure to read
== Protocol Vulnerabilites ==


* War and Peace
2014 at the BlackHat conference J. Lell and K. Nohl demonstrated how they reverse engineered USB mass storage devices, turning them into BadUSB. Therefore they highlighted some USB protocol inherent specifications that render it possible for a benign device turning into an attack tool:
* Lord of the Rings
* The host is incapable of knowing how many devices are actually connected to it
* The Baroque Cycle
* A device is not limited to a single functional class
* The USB standard allows devices to change their persona at any time
* Different devices have different endpoints, which are not limited to a certain set and amount
* USB devices don't have a unique identifier, they are identified through a serial number without a fix length. Some device classes don't even mandate a serial number.
* The USB device allows to go through this registration again, at any point in time. For example first, the device acts as CD-Rom drive, from which you first have to install a driver, once driver is active, the device switches over to what it actually is – a 3G modem.
* Manufacturers do not integrate firmware signing into the hardware


== Used Hardware ==
== Security threads ==  


[[Device to be used with this documentation]]
USB devices pose a significant security risk because, despite their widespread use, they offer low security. A particular risk with USB devices is USB sticks, which are often used as carriers for malware such as viruses, worms, and Trojans. This malware can spread easily since USB sticks can be quickly exchanged between different computers. A well-known example of a vulnerability is the AutoRun feature in older versions of Windows, especially Windows XP. This feature allowed USB devices to automatically start programs as soon as they were connected to a computer. While this was often used to install drivers, it was also exploited to execute malware unnoticed. In later versions of Windows, this feature was significantly restricted to minimize the risk.
[[Maybe another device to be used with this documentation]]


== Courses ==
Another serious risk with USB devices is the possibility of abusing HID (Human Interface Device) devices. Since HID devices are considered trustworthy, they can easily be used as an attack vector. For instance, a manipulated USB device can impersonate a keyboard and execute malicious inputs unnoticed to steal data or install malware. Such attacks, like those carried out using the O.MG Cable, exploit the fact that most operating systems trust HID devices and automatically grant them rights for user inputs. These attacks allow adversaries to execute commands undetected and gain access to sensitive data, posing significant security and privacy risks.


* [[A course where this documentation was used]] (2017, 2018)
Another major problem with USB technology is the lack of encryption for data transmission. The data transferred between USB devices and the host computer is sent in plaintext, making it vulnerable to passive eavesdropping attacks. Attackers can intercept the data traffic on the bus line with relatively simple methods and capture sensitive information. Keyboards are particularly vulnerable since they are often used to input sensitive data, such as passwords.
* [[Another one]] (2018)


== References ==
== References ==


* https://wikipedia.org
* Jing Tian, Nolen Scaife, Deepak Kumar, Michael Bailey, Adam Bates, and Kevin Butler. Sok: ”plug pray” today – understanding usb insecurity in versions 1 through c. In 2018 IEEE Symposium on Security and Privacy (SP), pages 1032–1047, 2018.
* https://google.com
* Chengzhi Sun, Jiyu Lu, and Yunqing Liu. Analysis and prevention of information security of usb. In 2021 International Conference on Electronic Information Engineering and Computer Science (EIECS), pages 25–32, 2021.
* Lell Jakob and Karsten Nohl. BadUSB-On accessories that turn evil. Blackhat Conference USA, 2014, https://www.youtube.com/watch?v=nuruzFqMgIw, accessed on 11 Nov 2024.
* Nongmeikapam Thoiba Singh, Aditya Shukla, Ajay Nagar, Kartavya Arya,Ashwani Tiwari, and Yash Varun. Keylogger development: Technical aspects, ethical considerations, and mitigation strategies. In 2023 International Conference on Energy, Materials and Communication Engineering (ICEMCE), pages 1-5, 2023.
* Daniel Noyes, Hong Liu, and Paul Fortier. Security analysis and improvement of usb technology. In 2016 IEEE Symposium on Technologies for Homeland Security (HST), pages 1–3, 2016.
* Yungroul Lee, Wansoo Kim, Kwangjin Bae, and Kangbin Yim. A solution to protecting usb keyboard data. In 2010 International Conference on Broadband, Wireless Computing, Communication and Applications, pages 108–111, 2010.


[[Category:Documentation]]
[[Category:Documentation]]

Latest revision as of 20:20, 1 December 2024

Introduction

The USB protocol is a cornerstone of modern computer communication, offering high flexibility and universal compatibility with a wide range of devices. However, this versatility comes with significant security risks. This document provides an overview of the USB protocol, highlighting its key features, such as composite device support and device enumeration. It also explores the associated security threats, including malware transmission, abuse of HID devices, and vulnerabilities due to unencrypted data transmission. By examining these aspects, the document sheds light on the balance between functionality and security in USB technology.

Protocol

The USB protocol is characterized by its high flexibility, particularly in its support for so-called composite devices. Composite devices can contain multiple configurations and interfaces, with each interface functioning as an independent unit. A typical example is a USB headset, which features a configuration that includes four interfaces: a keyboard for volume control, a microphone, and two speakers. This flexibility enables various functions to be combined into a single USB device.

General Class Specifications

Since the introduction of USB 1.0, the concept of "Common Class Specifications" has been established to standardize various types of peripheral devices. A USB class is a group of one or more interfaces that collectively provide enhanced functionality. One of the most well-known classes is the "Human Interface Device" (HID) class, which allows the USB host controller to communicate with input devices such as keyboards and mice. Another significant class is the USB Mass Storage class, which defines how data is transferred between the host and storage devices.

Composite devices combine multiple classes to provide more comprehensive functionality. For example, a USB headset can utilize both the HID class and the Audio class to support input and output functions. While this design principle has increased the flexibility of the USB protocol, it has also introduced security challenges.

USB Device Enumeration

When a USB device is connected to a host system, the USB host controller detects the presence of the device and its transfer speed by monitoring voltage changes on the data pins. This triggers the process known as enumeration, which involves identifying and configuring the device. The process begins with the GetDeviceDescriptors command, where the host queries the device for identification information such as the manufacturer, Vendor ID (VID), Product ID (PID), and serial number.

After querying, the host controller resets the device and assigns it an address for future communication. This is followed by a GetConfigDescriptors request to retrieve all available configurations of the device. USB devices can have one or more configurations, but only one configuration can be active at a time. Each configuration may include one or more interfaces, which are identified through the GetInterfaceDescriptors request. These interfaces represent the essential functional units handled by different drivers within the operating system. After completing these steps, the operating system loads the appropriate drivers, and device-specific subprotocols (e.g., HID, Storage) are activated.

Protocol Vulnerabilites

2014 at the BlackHat conference J. Lell and K. Nohl demonstrated how they reverse engineered USB mass storage devices, turning them into BadUSB. Therefore they highlighted some USB protocol inherent specifications that render it possible for a benign device turning into an attack tool:

  • The host is incapable of knowing how many devices are actually connected to it
  • A device is not limited to a single functional class
  • The USB standard allows devices to change their persona at any time
  • Different devices have different endpoints, which are not limited to a certain set and amount
  • USB devices don't have a unique identifier, they are identified through a serial number without a fix length. Some device classes don't even mandate a serial number.
  • The USB device allows to go through this registration again, at any point in time. For example first, the device acts as CD-Rom drive, from which you first have to install a driver, once driver is active, the device switches over to what it actually is – a 3G modem.
  • Manufacturers do not integrate firmware signing into the hardware

Security threads

USB devices pose a significant security risk because, despite their widespread use, they offer low security. A particular risk with USB devices is USB sticks, which are often used as carriers for malware such as viruses, worms, and Trojans. This malware can spread easily since USB sticks can be quickly exchanged between different computers. A well-known example of a vulnerability is the AutoRun feature in older versions of Windows, especially Windows XP. This feature allowed USB devices to automatically start programs as soon as they were connected to a computer. While this was often used to install drivers, it was also exploited to execute malware unnoticed. In later versions of Windows, this feature was significantly restricted to minimize the risk.

Another serious risk with USB devices is the possibility of abusing HID (Human Interface Device) devices. Since HID devices are considered trustworthy, they can easily be used as an attack vector. For instance, a manipulated USB device can impersonate a keyboard and execute malicious inputs unnoticed to steal data or install malware. Such attacks, like those carried out using the O.MG Cable, exploit the fact that most operating systems trust HID devices and automatically grant them rights for user inputs. These attacks allow adversaries to execute commands undetected and gain access to sensitive data, posing significant security and privacy risks.

Another major problem with USB technology is the lack of encryption for data transmission. The data transferred between USB devices and the host computer is sent in plaintext, making it vulnerable to passive eavesdropping attacks. Attackers can intercept the data traffic on the bus line with relatively simple methods and capture sensitive information. Keyboards are particularly vulnerable since they are often used to input sensitive data, such as passwords.

References

  • Jing Tian, Nolen Scaife, Deepak Kumar, Michael Bailey, Adam Bates, and Kevin Butler. Sok: ”plug pray” today – understanding usb insecurity in versions 1 through c. In 2018 IEEE Symposium on Security and Privacy (SP), pages 1032–1047, 2018.
  • Chengzhi Sun, Jiyu Lu, and Yunqing Liu. Analysis and prevention of information security of usb. In 2021 International Conference on Electronic Information Engineering and Computer Science (EIECS), pages 25–32, 2021.
  • Lell Jakob and Karsten Nohl. BadUSB-On accessories that turn evil. Blackhat Conference USA, 2014, https://www.youtube.com/watch?v=nuruzFqMgIw, accessed on 11 Nov 2024.
  • Nongmeikapam Thoiba Singh, Aditya Shukla, Ajay Nagar, Kartavya Arya,Ashwani Tiwari, and Yash Varun. Keylogger development: Technical aspects, ethical considerations, and mitigation strategies. In 2023 International Conference on Energy, Materials and Communication Engineering (ICEMCE), pages 1-5, 2023.
  • Daniel Noyes, Hong Liu, and Paul Fortier. Security analysis and improvement of usb technology. In 2016 IEEE Symposium on Technologies for Homeland Security (HST), pages 1–3, 2016.
  • Yungroul Lee, Wansoo Kim, Kwangjin Bae, and Kangbin Yim. A solution to protecting usb keyboard data. In 2010 International Conference on Broadband, Wireless Computing, Communication and Applications, pages 108–111, 2010.