{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,20]],"date-time":"2026-02-20T18:16:19Z","timestamp":1771611379704,"version":"3.50.1"},"reference-count":36,"publisher":"Springer Science and Business Media LLC","issue":"2","license":[{"start":{"date-parts":[[2020,3,2]],"date-time":"2020-03-02T00:00:00Z","timestamp":1583107200000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2020,3,2]],"date-time":"2020-03-02T00:00:00Z","timestamp":1583107200000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1453647"],"award-info":[{"award-number":["1453647"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["1663051"],"award-info":[{"award-number":["1663051"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Hardw Syst Secur"],"published-print":{"date-parts":[[2020,6]]},"DOI":"10.1007\/s41635-020-00092-z","type":"journal-article","created":{"date-parts":[[2020,3,2]],"date-time":"2020-03-02T16:03:02Z","timestamp":1583164982000},"page":"136-149","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":18,"title":["USB-Watch: a Generalized Hardware-Assisted Insider Threat Detection Framework"],"prefix":"10.1007","volume":"4","author":[{"given":"Kyle","family":"Denney","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Leonardo","family":"Babun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"A. Selcuk","family":"Uluagac","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,3,2]]},"reference":[{"key":"92_CR1","unstructured":"Admin: Tutorial about usb hid report descriptors. https:\/\/eleccelerator.com\/tutorial-about-usb-hid-report-descriptors\/ (2018). Accessed: 16 Sept 2018"},{"issue":"11","key":"92_CR2","doi-asserted-by":"publisher","first-page":"138","DOI":"10.1109\/MCOM.2017.1700871","volume":"56","author":"H Aksu","year":"2018","unstructured":"Aksu H, Babun L, Conti M, Tolomei G, Uluagac AS (2018) Advertising in the iot era: Vision and challenges. IEEE Commun Mag 56(11):138\u2013144. https:\/\/doi.org\/10.1109\/MCOM.2017.1700871","journal-title":"IEEE Commun Mag"},{"key":"92_CR3","doi-asserted-by":"publisher","unstructured":"Babun L, Aksu H, Uluagac AS (2019) A system-level behavioral detection framework for compromised cps devices: Smart-grid case. ACM Trans Cyber-phys Syst 4(2). https:\/\/doi.org\/10.1145\/3355300","DOI":"10.1145\/3355300"},{"key":"92_CR4","doi-asserted-by":"crossref","unstructured":"Babun L, Celik ZB, McDaniel P, Uluagac AS (2019) Real-time analysis of privacy-(un)aware iot applications","DOI":"10.2478\/popets-2021-0009"},{"key":"92_CR5","unstructured":"Babun L, Sikder AK, Acar A, Uluagac AS (2018) Iotdots: A digital forensics framework for smart environments. CoRR arXiv:abs\/1809.00745"},{"key":"92_CR6","unstructured":"Babun L, Aksu H, Uluagac SA (2018) Detection of counterfeit and compromised devices using system and function call tracing techniques. http:\/\/www.freepatentsonline.com\/10027697.html"},{"key":"92_CR7","unstructured":"Babun L, Aksu H, Uluagac SA (2019) Method of resource-limited device and device class identification using system and function call tracing techniques, performance, and statistical analysis. http:\/\/www.freepatentsonline.com\/10242193.html"},{"key":"92_CR8","unstructured":"Bursztein E (2016) Does dropping usb drives really work? Blackhat, Tech. Rep. Accessed: 16 Sept 2018"},{"key":"92_CR9","unstructured":"Celik ZB, Babun L, Sikder AK, Aksu H, Tan G, McDaniel P, Uluagac AS (2018) Sensitive information tracking in commodity iot. In: 27Th USENIX Security Symposium (USENIX Security 18). USENIX Association, Baltimore, pp 1687\u20131704"},{"key":"92_CR10","unstructured":"Cunningham A (2017) How usb became the undefeated king of connectors. https:\/\/www.wired.co.uk\/article\/usb-history. Accessed: 25 Nov 2018"},{"key":"92_CR11","unstructured":"Daley BL (2016) Usbesafe: Applying one class svm for effective usb event anomaly detection. Tech. rep., Northeastern University, College of Computer and Information Systems Boston United States. Accessed: 04 Oct 2018"},{"key":"92_CR12","doi-asserted-by":"publisher","unstructured":"Denney K, Erdin E, Babun L, Uluagac AS (2019) Dynamically detecting usb attacks in hardware: Poster. In: Proceedings of the 12th Conference on Security and Privacy in Wireless and Mobile Networks, WiSec \u201919. https:\/\/doi.org\/10.1145\/3317549.3326315. Association for Computing Machinery, New York, pp 328\u2013329","DOI":"10.1145\/3317549.3326315"},{"key":"92_CR13","doi-asserted-by":"crossref","unstructured":"Denney K, Erdin E, Babun L, Vai M, Uluagac S (2019) Usb-watch: a dynamic hardware-assisted usb threat detection framework. In: International Conference on Security and Privacy in Communication Systems, Springer, pp 126\u2013146","DOI":"10.1007\/978-3-030-37228-6_7"},{"key":"92_CR14","unstructured":"Ducklin P, Parkes M, James T, Pottage D (2016) Sidestepping your lockscreen with an innocent-looking usb stick. https:\/\/nakedsecurity.sophos.com\/2016\/09\/09\/sidestepping-your-lockscreen-with-an-innocent-looking-usb-stick\/"},{"key":"92_CR15","unstructured":"Hak5: Looks like a flash drive. types like a keyboard. https:\/\/www.hak5.org\/gear\/usb-rubber-ducky. Accessed: 28 Aug 2018"},{"key":"92_CR16","doi-asserted-by":"crossref","unstructured":"Johnson PC, Bratus S, Smith SW (2017) Protecting against malicious bits on the wire: automatically generating a usb protocol parser for a production kernel. In: Proceedings of the 33rd Annual Computer Security Applications Conference, ACM, pp 528\u2013 541","DOI":"10.1145\/3134600.3134630"},{"key":"92_CR17","doi-asserted-by":"publisher","unstructured":"Kaygusuz C, Babun L, Aksu H, Uluagac AS (2018) Detection of compromised smart grid devices with machine learning and convolution techniques. In: 2018 IEEE International Conference on Communications (ICC), pp 1\u20136. https:\/\/doi.org\/10.1109\/ICC.2018.8423022","DOI":"10.1109\/ICC.2018.8423022"},{"key":"92_CR18","unstructured":"Killourhy K, Maxion R Keystroke dynamics - benchmark data set. https:\/\/www.cs.cmu.edu\/keystroke\/. Accessed: 25 Mar 2019"},{"key":"92_CR19","doi-asserted-by":"crossref","unstructured":"Babun L. author=Aksu, H (2017) Identifying counterfeit smart grid devices: a lightweight system level framework. In: Proceedings of the IEEE ICC Intern Conf on Communications. IEEE, Paris, France","DOI":"10.1109\/ICC.2017.7996877"},{"key":"92_CR20","unstructured":"Linux: Usbmon documentation. https:\/\/www.kernel.org\/doc\/Documentation\/usb\/usbmon.txt. Accessed: 04 Oct 2018"},{"issue":"2","key":"92_CR21","doi-asserted-by":"publisher","first-page":"114","DOI":"10.1007\/s41635-017-0013-2","volume":"1","author":"J Lopez","year":"2017","unstructured":"Lopez J, Babun L, Aksu H, Uluagac AS (2017) A survey on function and system call hooking approaches. Journal of Hardware and Systems Security 1(2):114\u2013136. Accessed: 17 Nov 2018","journal-title":"Journal of Hardware and Systems Security"},{"key":"92_CR22","unstructured":"Mamiit A (2014) How bad is badusb? security experts say there is no quick fix. Retrieved November 18, 2014. Accessed: 19 Oct 2018"},{"key":"92_CR23","unstructured":"Maxion RA, Roberts RR (2004) Proper use of ROC curves in Intrusion\/Anomaly Detection. University of Newcastle upon Tyne, Computing Science. Accessed: 05 Nov 2018"},{"key":"92_CR24","doi-asserted-by":"crossref","unstructured":"Monrose F, Rubin A (1997) Authentication via keystroke dynamics. In: Proceedings of the 4th ACM Conference on Computer and Communications Security, pp 48\u201356. Citeseer. Accessed: 30 Oct 2018","DOI":"10.1145\/266420.266434"},{"key":"92_CR25","doi-asserted-by":"crossref","unstructured":"Moser A, Kruegel C, Kirda E (2007) Limits of static analysis for malware detection. In: Twenty-Third Annual Computer Security Applications Conference (ACSAC 2007), pp. 421\u2013430. IEEE. Accessed: 08 Dec 2018","DOI":"10.1109\/ACSAC.2007.21"},{"key":"92_CR26","unstructured":"Mulliner C, Weippl ER (2018) Usblock: Blocking usb-based keypress injection attacks. In: Data and Applications Security and Privacy XXXII: 32nd Annual IFIP WG 11.3 Conference, DBSec 2018, Bergamo, Italy, July 16\u201318, 2018, Proceedings, vol 10980. Springer, p 278. Accessed: 16 Sept 2018"},{"key":"92_CR27","unstructured":"Nohl K, Lell J (2014) Badusb\u2013on accessories that turn evil. Black Hat USA. Accessed: 19 Aug 2018"},{"key":"92_CR28","unstructured":"Python: Python 9.6. random - generate pseudo-random numbers. https:\/\/docs.python.org\/2\/library\/random.html"},{"key":"92_CR29","first-page":"19","volume-title":"Insider Threat Detection: Machine Learning Way","author":"MS Raval","year":"2018","unstructured":"Raval MS, Gandhi R, Chaudhary S (2018) Insider Threat Detection: Machine Learning Way. Springer International Publishing, Cham, pp 19\u201353. Accessed: 16 Oct 2018"},{"key":"92_CR30","unstructured":"RedTeam: Usb drop attacks: The danger of \u201clost and found\u201d thumb drives. https:\/\/www.redteamsecure.com\/usb-drop-attacks-the-danger-of-lost-and-found-thumb-drives\/ (2017). Accessed: 25 Jan 2019"},{"key":"92_CR31","unstructured":"Robertson J, Riley M The big hack: How china used a tiny chip to infiltrate u.s. companies. https:\/\/www.bloomberg.com\/news\/features\/2018-10-04\/the-big-hack-how-china-used-a-tiny-chip-to-infiltrate-america-s-top-companies. Accessed: 04 Mar 2019"},{"key":"92_CR32","doi-asserted-by":"publisher","unstructured":"Rondon LP, Babun L, Akkaya K, Uluagac AS (2019) Hdmi-walk: Attacking hdmi distribution networks via consumer electronic control protocol. In: Proceedings of the 35th Annual Computer Security Applications Conference, ACSAC \u201919. https:\/\/doi.org\/10.1145\/3359789.3359841. Association for Computing Machinery, New York, pp 650\u2013659","DOI":"10.1145\/3359789.3359841"},{"key":"92_CR33","unstructured":"Sikka S, Srivastva U, Sharma R (2017) A review of detection of usb malware. International Journal of Engineering Science 14283. Accessed: 14 Sept 2018"},{"key":"92_CR34","unstructured":"Smith: Say hello to badusb 2.0: A usb man-in-the-middle attack proof of concept. https:\/\/www.csoonline.com\/article\/3087484\/security\/say-hello-to-badusb-20-usb-man-in-the-middle-attack-proof-of-concept.html (2016). Accessed: 09-16-2018"},{"key":"92_CR35","unstructured":"Tian DJ, Scaife N, Bates A, Butler K, Traynor P (2016) Making USB great again with USBFILTER. In: 25th USENIX Security Symposium (USENIX Security 16), pp 415\u2013430. Accessed: 15 Mar 2019"},{"key":"92_CR36","unstructured":"Xu X, Chen X, Liu C, Rohrbach A, Darell T, Song D (2017) Can you fool ai with adversarial examples on a visual turing test. arXiv preprint arXiv:1709.08693. Accessed: 15 Feb 2019"}],"container-title":["Journal of Hardware and Systems Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s41635-020-00092-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s41635-020-00092-z\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s41635-020-00092-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,10,17]],"date-time":"2022-10-17T05:27:01Z","timestamp":1665984421000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s41635-020-00092-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,3,2]]},"references-count":36,"journal-issue":{"issue":"2","published-print":{"date-parts":[[2020,6]]}},"alternative-id":["92"],"URL":"https:\/\/doi.org\/10.1007\/s41635-020-00092-z","relation":{},"ISSN":["2509-3428","2509-3436"],"issn-type":[{"value":"2509-3428","type":"print"},{"value":"2509-3436","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,3,2]]},"assertion":[{"value":"20 September 2019","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 February 2020","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 March 2020","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}