rpclogo

 

USB fingerprints identify 'pod slurping' data thieves

Would your company know if the blueprints for its next invention had been stolen by an office interloper, who had quietly copied them onto a memory stick or an iPod? Probably not. But now a telltale "USB fingerprint" has been discovered that can identify which files have been targeted in so-called pod-slurping attacks.

Data theft via USB ports is rife, says Alexandra Brodie, an intellectual property lawyer with Wragge & Co in London. "We are encountering increasing volumes of IP theft committed this way, with companies losing their trade secrets and accumulated know-how," she says.

Pod slurpers might simply steal an individual document by copying it onto a USB stick. Hackers can also copy vast numbers of documents using document-scavenging tools such as USB Switchblade. This too springs to life when a memory stick is plugged into a PC running some versions of Windows, including XP. It then automatically copies the contents of the My Documents folder and no one is any the wiser. Now there is a way to spot such data theft.

Vasilios Katos and Theodoros Kavallaris at the Democritus University of Thrace in Komotini, Greece, have been testing every make and model of USB stick and iPod/iPhone. They have discovered that each one has a distinctive transfer rate when copying data from a PC's hard drive (Computers and Security, DOI: 10.1016/j.cose.2010.01.002). This is due to the differences in the microcircuitry and components that go into making each type of device.

They are able to find out if files have been copied by consulting the Windows registry, which records the make and model of every USB device plugged into that computer with a time stamp. The pair then check all document folders for any files that were accessed shortly after the USB device was plugged in - the computer registry counts copying as file access.

When they find a folder they suspect has been copied, they list the times the files within it were accessed. If the total time it took to access all the files matches the transfer rate of a particular USB stick or iPod plugged into the PC at that point, then it is fair to assume a pod-slurping attack has taken place.

Kavallaris is writing a program to automate the process of trawling the Windows registry to work out which files have been copied to a USB stick.

Brodie thinks the team's work could help investigators. "The ability to prove that downloads have taken place will be invaluable in building a case when thefts occur."

Courtesy Computer Crime

 

 

  HOW DOES THIS WORK ?
call1 Call our agents at 209-642-4483 and log your issues to us
age Our agent gets connected to your system remotely
che Sit back and relax or watch out our service
kno Once the issues are solved, the agent feeds you the knowledge transfer and disconnects from your computer
comm You can send your feedback / comments / expereince to support@remotepccure.org

 

Virus Removal Tool Names
Vcleaner
Removes the following viruses:
I-Worm/Stration, Worm/Generic.FX, Agent.A-AN, BackDoor.Agent.A-Z, BackDoor.Agent.AA-BG, Downloader.Agent.AS, I-Worm/Atak.A-I, Bagle.DA-IU, I-Worm/Bagle.A-Z, I-Worm/Bagle.AA-JD, I-Worm/Bugbear.D, I-Worm/Mytob.A-GC, I-Worm/Netsky.A-Z, Worm/Netsky.AA-AD, I-Worm/Sasser.A-F, I-Worm/Zafi.A-E, PSW.Bispy.A-E, Win32/Gaelicum, Win32/Hidrag
Worm/Downadup (Worm/Conficker)
Removes the following viruses:
Worm/Downadup (Worm/Conficker)
Downloader.Stubby.A
Removes the following viruses:
Downloader.Stubby.A
I-Worm/Bugbear.C
Removes the following viruses:
I-Worm/Bugbear.C )
I-Worm/Ganda
Removes the following viruses:
I-Worm/Ganda, papaDog Download remover:
rmganda.exe
Win32/Expiro
Removes the following viruses:
Win32/Expiro
I-Worm/Happy99
Removes the following viruses:
I-Worm/Happy99
I-Worm/Lovgate.C
Removes the following viruses:
I-Worm/Lovgate.C
I-Worm/Luder
Removes the following viruses:
I-Worm/Luder
Win32/Dundun
Removes the following viruses:
Win32/Dundun
I-Worm/Mydoom.A and B
Removes the following viruses:
I-Worm/Mydoom.A and I-Worm/Mydoom.B
I-Worm/Mydoom.F
Removes the following viruses:
I-Worm/Mydoom.F
I-Worm/Navidad
Removes the following viruses:
I-Worm/Navidad
I-Worm/Nimda
Removes the following viruses:
I-Worm/Nimda
I-Worm/Pretty_Park
Removes the following viruses:
I-Worm/Pretty_Park
I-Worm/Sircam.A
Removes the following viruses:
I-Worm/Sircam.A
I-Worm/Sober.A
Removes the following viruses:
I-Worm/Sober.A
I-Worm/Swen
Removes the following viruses:
I-Worm/Swen
I-Worm/Verona.B
Removes the following viruses:
I-Worm/Verona.B
LOP.AH/Backdoor.Generic3.SVX
Removes the following viruses:
LOP.AH/Backdoor.Generic3.SVX
Packed.Protector.C
Removes the following viruses:
Packed.Protector.C
Win32/Vampiro
Removes the following viruses:
Win32/Vampiro
VBS/Iloveyou
Removes the following viruses:
VBS/Iloveyou
Win32/Alman
Removes the following viruses:
Win32/Alman
Win32/Delf.2.B
Removes the following viruses:
Win32/Delf.2.B
Win32/Dupator
Removes the following viruses:
Win32/Dupator
Win32/Elkern, variants A, B and C
Removes the following viruses:
Win32/Elkern.A, Win32/Elkern.B, Win32/Elkern.C
Win32/Gaelicum
Removes the following viruses:
Win32/Gaelicum
Win32/Kriz
Removes the following viruses:
Win32/Kriz
Win32/Mabezat
Removes the following viruses:
Win32/Mabezat
Win32/Magistr, variants A and B
Removes the following viruses:
Win32/Magistr.A, Win32/Magistr.B
Win32/Parite
Removes the following viruses:
Win32/Parite
Win32/Prepender
Removes the following viruses:
Win32/Prepender
Win32/Sality
Removes the following viruses:
Win32/Sality
Win32/Tanatos, variants A, H, I and M
Removes the following viruses:
Win32/Tanatos A, Win32/Tanatos H, Win32/Tanatos I, Win32/Tanatos M
Win32/Valla.2048
Removes the following viruses:
Win32/Valla.2048
Win32/Virut
Removes the following viruses:
Win32/Virut
Worm/Lovsan
Removes the following viruses:
Worm/Lovsan

 

 

SERVICES FROM RPC

Antivirus Software

Computer Troubleshooting

Dell Computer Support

Toshiba Computer Support

Other Articles