Proceedings of the International scientific and practical conference ―Cambridge Education Forum‖ (June 1-3, 2026) / Publisher website: www.naukainfo.com. - Cambridge, United Kingdom, 2026. - 206 p.

124 and the USB vector remains one of the most common ways of initial penetration into protected networks where there is no direct access to the Internet [2]. The USB port is architecturally a ―trusted interface,‖ as the operating system initializes the connected device and loads the appropriate driver with little to no verification of the device’s authenticity. This feature underlies key classes of attacks. The BadUSB attack is a method of flashing a USB device’s microcontroller , causing it to appear to the system as a completely different class of device. First publicly demonstrated by researchers Carsten Nohl and Jacob Lel at the BlackHat conference in 2014, the attack remains relevant today, as the firmware of most USB controllers is not cryptographically signed and can be changed without any physical traces [3]. HID implants are hardware devices that, when connected , are automatically recognized as a keyboard and in a matter of seconds enter pre-programmed commands into the victim's system, bypassing antivirus software, because the operating system considers them to be "keystrokes" The real proof of the danger of the USB vector is the incident with the Natanz nuclear facility in Iran in 2010. The Stuxnet worm malware , considered one of the most sophisticated examples of cyberweapons in history, got into a completely isolated network precisely through an infected USB drive brought by one of the employees. After entering the system, Stuxnet spread through a vulnerability in Windows Shell and disabled uranium enrichment centrifuges while demonstrating normal performance to operators [ 4]. This case clearly showed that even physical isolation of the network does not save from a USB attack if there is no control over the connected devices. Modern USB attacks have a pronounced masking mechanism. HID devices operate at a speed unattainable for a human, since the entire malicious script can be executed in less than 10 seconds after connection - before the user has time to react. At the same time, a BadUSB device remains in the system with the appearance of a legitimate storage device, while simultaneously performing malicious functions in the background. Antivirus software, as a rule, is not able to detect such a threat, since the malicious logic is not located in the file system, but in the microcontroller firmware.

RkJQdWJsaXNoZXIy MTAxMzIwNA==