Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Improving Security By Pulling The Plug On USB Ports
Articles

Improving Security By Pulling The Plug On USB Ports

ISBuzz TeamBy ISBuzz TeamApril 9, 20185 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

When it comes to cybersecurity, it’s no secret that the human aspect of any organisation is its weakest link. From bad password sharing practices to falling victim to phishing emails, these challenges are any CISO’s nightmare. After all, the holes in network security that are created by the people on the front line of an enterprise can’t be plugged with a simple software patch. And despite efforts to train staff, employees are still the easiest route for a hacker to exploit. Particularly when it comes to USB-based security.

Shut the back door

In 2016, Researchers from the University of Illinois left 300 unlabelled USB drives around the campus and tracked what happened next. 98% of the dropped drives were picked up by staff and students alike, and at least half the drives were plugged into a computer to access the files stored on them – not bad odds if you’re a hacker. Although the study was conducted two years ago, its outcome is not unusual in 2018 and is a security backdoor that is still wide open for many networks around the world.

The reason is clear: practicality. There’s no doubt USB devices are one of the easiest ways to move files between machines. However, with the impact of suffering a cyber-attack so great, convenience can’t be a driver behind IT decision making. Especially not when cloud-based sharing platforms like Dropbox exist. Zero-Trust – which means no person or device is inherently trusted – is fast becoming the go-to security stance for enterprises as a result, and is a strategy that has no place for USB devices.

So, with the use of flash drives being tackled in this way, can businesses do away with USB ports entirely? Not quite. USB ports serve many purposes beyond simply facilitating the use of storage devices. Before they can be completely disabled on end-user terminals and removed from the IT landscape in the interest of security, there are further challenges to overcome.

The software problem

One of the biggest factors preventing the phasing out of USB ports of employee machines comes from software vendors. From accountancy to law enforcement, high-value software applications have licenses that are tightly controlled and authenticated through USB dongles, a plug-in physical authentication device. Often worth thousands of dollars per license, it makes sense for vendors to take such a hard line as hardware-level protection is still the most effective mechanism for tackling software piracy and misuse. Since these applications are in use across all industries and often power software that’s at the heart of modern business, this isn’t going to change any time soon.

In some cases, it’s also a necessity. Take state police or defence bodies as an example. They need to know who’s running certain forensic software and where it is accessed, which makes relying on a physical dongle a highly logical solution. The problem, though, is that this can often increase the risk of a malicious device being plugged in if an employee relies on a USB dongle to access bespoke software for their role and a would-be hacker can exploit that.

The dongle server solution

However, this doesn’t necessarily mean that USB ports on end-user terminals and employee computers need to stay. Part of the responsibility of IT solution providers is to find a work around for issues like this, ensuring customer systems remain secure without compromising on functionality. And this is where USB device servers come into play.

A device server acts a central hub where all USB devices are managed. Rather than having each user plug a physical device into their own machine, it makes all connected USB devices available over the network. Dongle servers work on exactly the same principle, USB dongles for software authentication are plugged into a single centralised server, virtualised, and can be used by authorised users on the network as if they’d been connected directly to their computer.

They also meet the requirements of companies or organisations with high security needs. By encrypting the point-to-point connection between the end-user and the dongle server, the potential for unauthorised access is removed. More advanced dongle server vendors also make it possible to dynamically assign which user is authorised to access which dongle, ultimately controlling which computer is able to access the software.

Risk vs reward

It’s widely accepted that hackers are getting more and more sophisticated. However, that doesn’t mean that they won’t go for low-level network infiltration attempts, such as baiting with USB flash drives, when the situation presents itself. Among the 10 major cyber threats identified by BSI in 2016 (German Office for Information Security), the use of USB devices ranks second.

Unfortunately, employees are always going to be the easy targets when it comes to enterprise security. It’s logical, then, that businesses seek to minimise damage that can be inflicted as a result of employee carelessness. Something as simple as disabling USB ports can have a significant impact on reducing a company’s attack vector and it is essential that vendors and enterprises work together to find solutions that lock hackers out of every security backdoor for good without impacting productivity.

[su_box title=”About Joachim Sturmhoefel” style=”noise” box_color=”#336588″][short_info id=’104889′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}