IBM's embarassing USB incident is the latest in a long list. But you can mitigate the risk.
When IBM handed out infected USB drives it validated one of the worst fears network managers have — a malware infested USB stick. While we, as IT professionals realize that the USB flash is convenient it is also scurrilously dangerous when it comes to delivering malicious code to our computers.
IT professionals have often reacted with a just-say-no campaign. For example in November 2008 the US army or specifically StratCom banned the use of removable data storage devices including USB sticks, CDs, and flash media cards, in order to mitigate a rapidly spreading Agent.btz virus within the army’s network. Recently the ban was lifted for certain specific use.
More recently an old social engineering strategy was deployed to test the effectiveness of security training at a credit union in East Syracuse, NY. Fifteen USB drives containing code to collect user names, passwords, and information about the host system, were seeded around the credit union’s building. plugged some of the devices into their corporate workstations. In this case there was no harm and no foul.
The results are as you would expect. Employees lured by the misrepresentation that the devices contained interesting images,
But in other circumstances the results aren’t benign.
The best mitigation steps against misuse of USB and other plug in convenience devices are security policy, enforcing security policy, and best of all security awareness training. Corporate security managers should consider getting approval for a policy of locking down all plug-in device ports and authorizing their use on an exception basis only. The policy should include an authorization mechanism based upon an associated privilege table. The privileges should be authorized by business unit managers and the authentication process should be separately managed by security administrators.
The policy should also include a mechanism for checking data on plug in devices prior to actually using the data. The goal here is to verify that data has not been inadvertently corrupted or changed, and that no malicious code has been introduced into the device. There is a range of technology available to verify data including encryption and other specific tools.
The enforcement portion of the policy should also mandate the use of auto-discovery tools that constantly look for active USB ports and compare the identity of USB devices with the approved list contained in the privilege table.
But the most important tactic is also, perhaps, the hardest — training users of the dangers. Constant security awareness training is unarguably the most effective avoidance tactic for plug-in calamities. Training should graphically illustrate to users the downside of USB misuse, such as theft of sensitive or critical corporate information; theft of their personal information; damage to corporate information; damage to their careers.
Everyone using laptops and computers for their own businesses and personal use need to remember they are just as vulnerable to expensive, painful punishment for plug-in misuse. With the almost ubiquitous interoperability of memory for cameras, games, entertainment devices and household appliances with our computers, the temptation to swap plug-in devices can be overwhelming.
But then again, so can the unintended consequences.
Have a secure week.




