Inspiration
USB devices are still trusted surprisingly quickly by most computers. Plug in a flash drive and, within seconds, the host system is interacting with it. We wanted to explore a different approach: what if an unknown USB device had to prove it was safe before the host trusted it?
That idea became USB Defender Gen Two, an automated system designed to intercept unknown USB storage devices, isolate them from the host, scan them in a sandbox, and only return them to Windows after they pass inspection.
What it does
USB Defender Gen Two detects a USB device when it is connected to a Windows computer and collects identifying information such as its vendor ID, product ID, and serial number.
Unknown storage devices are captured by an isolated Ubuntu virtual machine running in VirtualBox. Inside the sandbox, the drive is mounted with restrictive permissions and scanned using ClamAV. If the scan passes, the USB device is safely unmounted, released from the virtual machine, and returned to Windows.
The project also uses a whitelist database to recognize previously approved devices and maintain information about trusted hardware.
How we built it
The project combines several technologies into one security pipeline:
- C/C++ handles low-level USB detection and gathers device information from Windows.
- Python coordinates the security process, communicates with the detection layer, controls VirtualBox, and manages scanning.
- VirtualBox provides an isolated Ubuntu environment where unknown USB devices can be inspected.
- Ubuntu Linux acts as the sandboxed operating system.
- ClamAV performs malware scanning inside the sandbox.
- SQLite stores information about approved devices and provides the foundation for the whitelist.
- TCP sockets allow different components of the system to communicate locally.
The resulting pipeline is:
USB → Detection → Isolation → Sandbox → Malware Scan → Security Decision → Windows
Challenges we faced
The largest challenge was controlling ownership of a physical USB device between Windows and VirtualBox.
VirtualBox changes how Windows sees a USB device while the virtual machine controls it. We had to create temporary USB capture filters, confirm that the device successfully entered the sandbox, remove those filters at the correct time, scan the drive, and then explicitly detach it so Windows could regain control.
Getting that sequence wrong could cause VirtualBox to immediately recapture a released device or leave the device inaccessible to Windows.
We also had to coordinate multiple technologies with very different responsibilities. Windows USB detection, C/C++, Python, TCP communication, VirtualBox, SSH, Linux device mounting, and ClamAV all had to operate as one continuous process.
What we learned
This project taught us that endpoint security is much more complicated than simply scanning a file.
We learned about USB enumeration, hardware identifiers, Windows device detection, virtual machine USB passthrough, Linux block devices, secure mounting, malware scanning, local network communication, and coordinating multiple programs into a single security system.
Most importantly, we learned how quickly a seemingly simple idea like "scan a USB before trusting it" becomes a systems engineering problem when you actually try to enforce that boundary automatically.
Log in or sign up for Devpost to join the conversation.