USB Keypress Injection Attack Detection via Free-Text Keystroke Dynamics

Arun Negi, Santosh Singh Rathore, Debanjan Sadhya · 2021

Universal Serial Bus (USB) devices are a standard method for information exchange. The growth in the usage of USB devices has increased the risk of vulnerabilities through which an adversary can exploit connected systems. Mostly, attackers tend to hamper the firmware of USB devices and try to inject malicious scripts into the system through keypresses, causing a keypress injection attack. This paper aims to develop a framework based on free-text keystroke dynamics for detecting keypress injection attacks. The mechanism uses various machine learning models trained over different keystroke features such as duration time features (Hold Time) and latency features (Up-Down Time and Down-Down Time). We implement a realtime continuous checking over the latency features of user keystrokes. The trained models subsequently predict whether the user activity lies in the genuine or malicious region. We have used different baseline classifiers including k-Nearest Neighbour(KNN), Support Vector Machine(SVM), Random Forest, XGBoost, and investigated three custom-made keypress injection attacks in each model. The results indicate that Random Forest provides the best detection accuracy over all the three applied attacks. Furthermore, we compared the models trained with our dataset to those trained with the Buffalo dataset. Interestingly, our trained models demonstrate comparable accuracy with the former one, thereby vindicating the utility of the dataset.

Read the paper · More papers on PaperTik