论文标题

警告供应商,用过USB驱动器所有者

Caveat Venditor, Used USB Drive Owner

论文作者

Conacher, James, Renaud, Karen, Ophoff, Jacques

论文摘要

USB驱动器是传输和备份文件的好方法。问题在于它们很容易丢失,用户不了解如何保护或正确擦除它们。当用于存储私人和敏感信息时,这构成了用户可能不知道的风险。考虑到人们在网上出售使用的USB驱动器 - 大概是他们自己的或其他人丢失的驱动器。这就提出了一些有趣的问题,例如卖家是否知道如何在放弃不知名的买家之前将私人数据删除,以及卖家是否使用这些驱动器来试图损害不明智的买家的设备。政府确实确实就二手移动媒体的风险发出了建议,但我们尚不知道该建议是否正在达到并受到公众的注意。为了评估情况,从eBay销售商那里购买了二手USB驱动器的样本,以直接确定驱动器上的内容。这是回答上面提出的问题的实际与安全相关行为的指标。使用法医分析发现,许多驱动器仍然存在大量的私人和敏感信息,但是没有恶意软件的痕迹。需要更有效的启发公众的方法,因此不会通过销售的媒体不知不觉地泄露私人数据。

USB drives are a great way of transferring and backing up files. The problem is that they are easily lost, and users do not understand how to secure or properly erase them. When used to store private and sensitive information, this constitutes a risk that users may be unaware of. Consider that people sell used USB drives online -- presumably either their own or drives others have lost. This raises some interesting questions, such as whether sellers know how to ensure that private data is erased before they relinquish the drive to an unknown buyer, and whether sellers use these drives in an attempt to compromise an unwary buyer's device. Governments do indeed issue advice about the risks of used mobile media, but we do not yet know whether this advice is reaching, and being heeded by, the general public. To assess the situation, a sample of used USB drives were purchased from eBay sellers to determine, first hand, what was on the drives. This acts as an indicator of actual security-related behaviours to answer the questions posed above. Using forensic analysis, it was found that a great deal of private and sensitive information remained on many of the drives, but there was no trace of malicious software. More effective ways of enlightening the public are needed, so that private data is not unwittingly leaked via sold used media.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源