EP3662369B1

System and method for securing a computer system from threats introduced by usb devices

Abstract

This record has no abstract on file.

EP3662369B1, drawing sheet 1
Sheet 1 of 1

Term

11.9 yearsleft in the term

Expires 1 August 2038.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

27 claims: 3 independent, 24 dependent

  1. 1
    A system for preventing attacks, on an organization having plural computers, via the computers' Universal Serial Bus, USB, ports, the system comprising:at least one processor configured to monitor at least one aspect of a connection between a peripheral and a computer's USB port, to identify aspects which match pre-configured criteria and responsively, to take action, wherein the system stores descriptor sets, each including at least one descriptor, for known rogue devices and for known legitimate devices and identifies peripherals which have these descriptors, wherein the system is updated by adding descriptor sets for new models or types of legitimate or rogue USB devices to system memory, when a Machine Learning, ML, based algorithm is able to classify a certain USB device as a legitimate non malicious device with a sufficiently high level of confidence, wherein the system determines that an unknown descriptor set, which does not match the descriptor sets for the known rogue devices and the known legitimate devices, is for an unknown legitimate device after the unknown descriptor set repeats for over a threshold number of USB devices in the organization.
  2. 19
    A method for preventing attacks of a Universal Serial Bus, USB, peripheral device on at least one computer from among plural computers belonging to an organization, the method comprising:storing, in a computer storage data repository, at least one aspect of at least one type of USB peripheral;and monitoring a connection between a peripheral instance and a computer's USB port, including using a processor configured for comparing aspects of the connection with said at least one aspect and taking action regarding at least one peripheral instance for which a result of said comparing suggests that the instance peripheral is attacking the computer, wherein descriptor sets, each including at least one descriptor, are stored, for known rogue devices and for known legitimate devices and wherein the method comprises identifying peripherals which have these descriptors, the method also comprising updating system memory by adding descriptor sets for new models or types of legitimate or rogue USB devices to the system memory, when a Machine Learning, ML, based algorithm is able to classify a certain USB device as a legitimate non malicious device with a sufficiently high level of confidence, wherein the method further comprising determining that an unknown descriptor set, which does not match the descriptor sets for the known rogue devices and the known legitimate devices, is for an unknown legitimate device after the unknown descriptor set repeats for over a threshold number of USB devices in the organization.
  3. 26
    A computer program product, comprising a non-transitory tangible computer readable medium having computer readable program code embodied therein, said computer readable program code adapted to be executed to implement a method for preventing attacks of a Universal Serial Bus, USB, peripheral device on at least one computer from among plural computers belonging to an organization, the method comprising:storing, in a computer storage data repository, at least one aspect of at least one type of USB peripheral;and monitoring a connection between a peripheral instance and a computer's USB port, including using a processor configured for comparing aspects of the connection with said at least one aspect and taking action regarding at least one peripheral instance for which a result of said comparing suggests that the instance peripheral is attacking the computer, wherein descriptor sets, each including at least one descriptor, are stored, for known rogue devices and for known legitimate devices and wherein the method comprises identifying peripherals which have these descriptors, the method also comprising updating system memory by adding descriptor sets for new models or types of legitimate or rogue USB devices to the system memory, when a Machine Learning, ML, based algorithm is able to classify a certain USB device as a legitimate non malicious device with a sufficiently high level of confidence, wherein the method further comprising determining that an unknown descriptor set, which does not match the descriptor sets for the known rogue devices and the known legitimate devices, is for an unknown legitimate device after the unknown descriptor set repeats for over a threshold number of USB devices in the organization.