Inspiration

USB devices are still trusted surprisingly quickly by most computers. Plug in a flash drive and, within seconds, the host system is interacting with it. We wanted to explore a different approach: what if an unknown USB device had to prove it was safe before the host trusted it?

That idea became USB Defender Gen Two, an automated system designed to intercept unknown USB storage devices, isolate them from the host, scan them in a sandbox, and only return them to Windows after they pass inspection.

What it does

USB Defender Gen Two detects a USB device when it is connected to a Windows computer and collects identifying information such as its vendor ID, product ID, and serial number.

Unknown storage devices are captured by an isolated Ubuntu virtual machine running in VirtualBox. Inside the sandbox, the drive is mounted with restrictive permissions and scanned using ClamAV. If the scan passes, the USB device is safely unmounted, released from the virtual machine, and returned to Windows.

The project also uses a whitelist database to recognize previously approved devices and maintain information about trusted hardware.

How we built it

The project combines several technologies into one security pipeline:

  • C/C++ handles low-level USB detection and gathers device information from Windows.
  • Python coordinates the security process, communicates with the detection layer, controls VirtualBox, and manages scanning.
  • VirtualBox provides an isolated Ubuntu environment where unknown USB devices can be inspected.
  • Ubuntu Linux acts as the sandboxed operating system.
  • ClamAV performs malware scanning inside the sandbox.
  • SQLite stores information about approved devices and provides the foundation for the whitelist.
  • TCP sockets allow different components of the system to communicate locally.

The resulting pipeline is:

USB → Detection → Isolation → Sandbox → Malware Scan → Security Decision → Windows

Challenges we faced

The largest challenge was controlling ownership of a physical USB device between Windows and VirtualBox.

VirtualBox changes how Windows sees a USB device while the virtual machine controls it. We had to create temporary USB capture filters, confirm that the device successfully entered the sandbox, remove those filters at the correct time, scan the drive, and then explicitly detach it so Windows could regain control.

Getting that sequence wrong could cause VirtualBox to immediately recapture a released device or leave the device inaccessible to Windows.

We also had to coordinate multiple technologies with very different responsibilities. Windows USB detection, C/C++, Python, TCP communication, VirtualBox, SSH, Linux device mounting, and ClamAV all had to operate as one continuous process.

What we learned

This project taught us that endpoint security is much more complicated than simply scanning a file.

We learned about USB enumeration, hardware identifiers, Windows device detection, virtual machine USB passthrough, Linux block devices, secure mounting, malware scanning, local network communication, and coordinating multiple programs into a single security system.

Most importantly, we learned how quickly a seemingly simple idea like "scan a USB before trusting it" becomes a systems engineering problem when you actually try to enforce that boundary automatically.

Built With

Share this project:

Updates

posted an update —

P.S. We also planned a Raspberry Pi-based red-team demonstration to show how a system like ours could potentially be bypassed or stress-tested from the attacker side. The Pi was intended to emulate a malicious USB device and present itself to the protected PC in a way that would test whether the defense could distinguish a legitimate device from a deliberately crafted one. We got the Pi running, networked, and remotely controllable, but we did not have enough time during the hackathon to finish the USB gadget implementation and include that adversarial test in the final demo.

Log in or sign up for Devpost to join the conversation.

Submission history