Proceedings of the International scientific and practical conference ―Cambridge Education Forum‖ (June 1-3, 2026) / Publisher website: www.naukainfo.com. - Cambridge, United Kingdom, 2026. - 206 p.

125 Standard protection measures are insufficient here. Blocking autorun does not protect against HID attacks, because the device imitates a keyboard, not a medium. Antiviruses do not scan firmware. Physically disabling a specific USB port does not solve the problem if the organization does not have a general USB policy . That is why protection requires a comprehensive approach at several levels. Methods for countering USB attacks can be divided into three levels. At the hardware level, the most radical solution is to physically block USB ports with special plugs or use USB gateways that only allow charging, disabling data transfer. At the software level, implementing USB- class solutions is effective Device Control , which allow you to apply a whitelist policy, connecting only devices with pre-approved VID / PID identifiers. Windows and Linux operating systems support blocking certain classes of USB devices through group policies and udev rules. Anomaly input of commands through a HID device can be detected using EDR systems that analyze the frequency and patterns of keystrokes. At the organizational level, it is necessary to implement a clear policy on the use of USB media: prohibiting the use of personal drives, mandatory checking of corporate drives on an isolated machine before connecting to a work PC, and regular training of personnel on the risks of connecting found USB devices is one of the most effective prevention methods. Thus, USB attacks are one of the most dangerous and most underestimated threat vectors in modern cybersecurity . They are effective even against isolated networks, are almost imperceptible to standard protection tools and do not require the attacker to be technically sophisticated. Comprehensive protection should combine hardware restrictions, software control of devices and clear organizational policies - only together can these measures significantly reduce the risk of a successful attack.

RkJQdWJsaXNoZXIy MTAxMzIwNA==