kth.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Security Evaluation of a High-assurance USB sanitation system
KTH, School of Electrical Engineering and Computer Science (EECS).
2024 (English)Independent thesis Advanced level (degree of Master (Two Years)), 20 credits / 30 HE creditsStudent thesis
Abstract [en]

The Hunna USB sanitation system aims to ensure the integrity and security of USB-based data transfers into air-gapped environments through the use of antivirus scanning, whitelisting, and content disarm and reconstruction. The purpose of this thesis is to provide a comprehensive examination of the Hunna system. The security of the system is analysed through threat modeling and evaluating potential attacks with black box penetration testing. Through analysing nine threat vectors the results conclude that there are three main security gaps where an attacker may be able to bypass some of the system’s security features. These security gaps are the possibility of antivirus evasion and filetype spoofing, as well as the risk of unauthorized updates from a copy of the system’s admin USB. Additionally, the research highlights the system’s heavy reliance on the proper use of the system and the secure handling of administrative tools, emphasizing that any mishandling can significantly compromise security.

Abstract [sv]

Hunna USB-saneringssystemet har som mål att säkerställa integriteten och säkerheten vid dataöverföringar via USB till system separerade med ett luftgap genom att använda antivirus, vitlistning och ”content disarm and reconstruction”. Syftet med detta examensarbete är att utföra en grundlig granskning av Hunna-systemet. Säkerheten hos systemet analyseras genom hotmodellering och utvärdering av potentiella attacker med black box-penetrationstestning. Genom att analysera nio hotvektorer leder resultaten till slutsatsen att det finns tre huvudsakliga säkerhetsbrister där en angripare potentiellt kan kringgå vissa av systemets säkerhetsfunktioner. Dessa säkerhetsbrister innefattar möjligheten till antivirusundvikande och filtypsmanipulation, samt risken för obehöriga uppdateringar från en kopia av systemets admin-USB. Dessutom understryker forskningen systemets starka beroende av att hanteras korrekt och att administrativa verktyg hanteras på ett säkert sätt, och betonar att felhantering kan allvarligt minska säkerheten.

Place, publisher, year, edition, pages
2024. , p. 47
Series
TRITA-EECS-EX ; 2024:630
Keywords [en]
USB sanitation, Penetration testing, Digital forensics, Antivirus evasion
Keywords [sv]
USB-sanering, Penetrationstestning, Digital forensik, Antivirusundvikande
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:kth:diva-353978OAI: oai:DiVA.org:kth-353978DiVA, id: diva2:1901062
External cooperation
Armasuisse
Supervisors
Examiners
Available from: 2024-10-02 Created: 2024-09-25 Last updated: 2024-10-02Bibliographically approved

Open Access in DiVA

fulltext(753 kB)220 downloads
File information
File name FULLTEXT01.pdfFile size 753 kBChecksum SHA-512
db87913fec814285653923eff23f979228dd90640c08c11175eacf2f9896fcb6f5f52f8e0e88f5fe167f52bd7a7d042ef56cf4e0decc102c7f8d9d522a7aa408
Type fulltextMimetype application/pdf

By organisation
School of Electrical Engineering and Computer Science (EECS)
Computer and Information Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 220 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 550 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf