IP Library Granted Patent US 12,579,329
Granted Patent B2
US 12,579,329 · App. 18/678,004 · Granted Mar 17, 2026

Input/output interface security

Inventor: Cesar Augusto Rodriguez Bravo (Alajuela, CR)
Assignee: Kyndryl, Inc.
G06F21/85G06F21/577G06F21/64G06F21/81
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,579,329
App. No.
18/678,004
Granted
Mar 17, 2026
Kind
B2
Abstract

Methods, computer program products, and systems are presented. The Methods, computer program products, and systems can include, for example: examining hardware device transmitted data received through an I/O interface port of a computer system; determining in dependence on the examining whether the hardware device transmitted data received through the I/O interface port of the computer system satisfies a criterion; and in response to determining that the hardware device transmitted data received through the I/O interface port of the computer system satisfies the criterion, initiating a security process for protecting the computer system.

Claims (38)

1 . A computer implemented method comprising:

determining whether a hardware device transmitted data received through an I/O interface port of a computer system satisfies a criterion;

in response to determining that the hardware device transmitted data received through the I/O interface port of the computer system satisfies the criterion, initiating a security process for protecting the computer system,

wherein the initiating the security process comprises loading, by the computer system, a custom security driver which is operational for (i) sending an amount of electrical energy to an external device that is sufficient to overload the external device, (ii) transmitting to the external device a request for return data, and (iii) monitoring for receipt of the requested return data; and

in response to determining that a current security risk level is acceptable, disabling the I/O interface port and sending a notification that the data received through the I/O interface port satisfied the criterion.

2 . The computer implemented method of claim 1 , wherein the determining whether the hardware device transmitted data received through the I/O interface port of the computer system satisfies the criterion comprises determining whether the hardware device transmitted data specifies a human interface device classification.

3 . The computer implemented method of claim 1 , wherein the determining whether the hardware device transmitted data received through the I/O interface port of the computer system satisfies the criterion comprises determining whether the hardware device transmitted data matches a signature string.

4 . The computer implemented method of claim 1 , wherein the determining whether the hardware device transmitted data received through the I/O interface port of the computer system satisfies the criterion is performed in response to determining that the computer system is in a locked state.

5 . The computer implemented method of claim 1 , wherein the security process comprises one or more actions selected from the group consisting of (a) the disabling the I/O interface port, (b) outputting at least one notification, (c) producing an audit trail of a detected attack, and (d) destroying an external device that has transmitted the hardware device transmitted data.

6 . The computer implemented method of claim 1 , further comprising installing an installation package on the computer system during runtime of the computer system, wherein the installation package includes user application layer software code that modifies behavior of an operating system of the computer system so that the operating system performs the determining whether the hardware device transmitted data received through the I/O interface port of the computer system satisfies the criterion, and the initiating the security process for protecting the computer system.

7 . The computer implemented method of claim 1 , wherein the initiating the security process comprises initiating a security process wherein the computer system loads a custom security driver that supports communications with an external device that has transmitted the hardware device transmitted data, wherein the custom security driver sends data request communications to the external device that emulate operation of a device driver loaded for support of an authorized hardware device, receives in response to the data request communications subsequent data from the external device, and initiates creation of an audit file record recording the subsequent data.

8 . The computer implemented method of claim 1 , wherein the custom security driver is further operational for (iv) iteratively performing the sending, the transmitting, and the monitoring until the return data is determined to be not received by the monitoring.

9 . The computer implemented method of claim 1 , wherein the disabling the I/O interface port comprises one or more actions selected from the group consisting of: configuring the computer system to ignore transmitted data of an external device that has transmitted the hardware device transmitted data, even where the transmitted data is compliant with a format required of an I/O interface associated to the I/O interface port, restricting the computer system from presenting a descriptive data request to an attached hardware device, restricting launch of a device driver for facilitating communication with the attached hardware device, and restricting delivery of electrical power for powering the attached hardware device.

10 . The computer implemented method of claim 1 , wherein the determining whether the hardware device transmitted data received through the I/O interface port of the computer system satisfies the criterion is selectively performed while the computer system is in a locked operating state.

11 . A computer program product comprising:

a computer readable storage medium readable by one or more processing circuit and storing instructions for execution by one or more processor for performing a method comprising:

determining whether hardware device transmitted data received through an I/O interface port of a computer system satisfies a criterion;

in response to determining that the hardware device transmitted data received through the I/O interface port of the computer system satisfies a criterion, initiating a security process for protecting the computer system,

wherein the initiating the security process comprises loading, by the computer system, a custom security driver, and

wherein the custom security driver is operational for (i), sending an amount of electrical energy to an external device that is sufficient to overload the external device; (ii) transmitting to the external device a request for return data; and (iii) monitoring for receipt of the requested return data; and

in response to determining that a current security risk level is acceptable, disabling the I/O interface port and sending a notification that the data received through the I/O interface port satisfied the criterion.

12 . The computer program product of claim 11 , wherein the whether the hardware device transmitted data received through the I/O interface port of the computer system satisfies the criterion comprises determining whether the hardware device transmitted data matches a signature string.

13 . The computer program product of claim 11 , wherein the security process comprises one or more actions selected from the group consisting of the disabling the I/O interface port, outputting at least one notification, producing an audit trail of a detected attack, and destroying an external device that has transmitted the hardware device transmitted data.

14 . The computer program product of claim 11 , wherein the method comprises installing an installation package on the computer system during runtime of the computer system, wherein the installation package comprises user application layer software code that modifies behavior of an operating system of the computer system so that the operating system performs the determining whether the hardware device transmitted data received through the I/O interface port of the computer system satisfies the criterion, and the initiating the security process for protecting the computer system.

15 . The computer program product of claim 11 , is further operational iteratively performing the sending, the transmitting, and the monitoring until the return data is determined to be not received by the monitoring.

16 . The computer program product of claim 11 , wherein the disabling the I/O interface port comprises one or more actions selected from the group consisting of configuring the computer system to ignore transmitted data of an external device that has transmitted the hardware device transmitted data, even where the transmitted data is compliant with a format required of an I/O interface associated to the I/O interface port, restricting the computer system from presenting a descriptive data request to an attached hardware device, restricting launch of a device driver for facilitating communication with the attached hardware device, and restricting delivery of electrical power for powering the attached hardware device.

17 . A system comprising:

a memory;

at least one processor in communication with the memory; and

program instructions executable by one or more processor via the memory to perform a method comprising:

determining whether a hardware device transmitted data received through an I/O interface port of a computer system satisfies a criterion;

in response to determining that the hardware device transmitted data received through the I/O interface port of the computer system satisfies the criterion, initiating a security process for protecting the computer system,

wherein the initiating the security process comprises loading, by the computer system, a custom security driver, and

wherein the custom security driver is operational for (i), sending an amount of electrical energy to an external device that is sufficient to overload the external device; (ii) transmitting to the external device a request for return data; and (iii) monitoring for receipt of the requested return data; and

in response to determining that a current security risk level is acceptable, disabling the I/O interface port and sending a notification that the data received through the I/O interface port satisfied the criterion.

18 . The system of claim 17 , wherein the determining whether the hardware device transmitted data received through the I/O interface port of the computer system satisfies the criterion comprises determining whether the hardware device transmitted data matches a signature string.

19 . The system of claim 17 , wherein the security process comprises one or more actions selected from the group consisting of disabling the I/O interface port, outputting at least one notification, producing an audit trail of a detected attack, and destroying an external device that has transmitted the hardware device transmitted data.

20 . The system of claim 17 , wherein the custom security driver is further operational for iteratively performing the sending, the transmitting, and the monitoring until the return data is determined to be not received by the monitoring.

Continuity (2)
Continuation 17515365 · Oct 29, 2021
Related Publication 20240320378A1 · Sep 26, 2024
References Cited (53)
US 7721115B2 · Luttmann et al. · 2010 [cited by applicant]
US 7904565B2 · Holden et al. · 2011 [cited by applicant]
US 8386795B2 · Lu et al. · 2013 [cited by applicant]
US 9832199B2 · Boivie · 2017 [cited by examiner]
US 9875354B1 · Srivastava · 2018 [cited by examiner]
US 10140454B1 · Spath · 2018 [cited by examiner]
US 10419459B2 · Touboul · 2019 [cited by applicant]
US 10581869B2 · Simons · 2020 [cited by applicant]
US 10771478B2 · Fahrny et al. · 2020 [cited by applicant]
US 10789370B2 · Nair · 2020 [cited by examiner]
US 10885200B2 · Ciano · 2021 [cited by examiner]
US 11042644B2 · Sheng · 2021 [cited by applicant]
US 11336621B2 · Touboul · 2022 [cited by examiner]
US 11399031B2 · McBride et al. · 2022 [cited by applicant]
US 11580224B2 · Shattuck et al. · 2023 [cited by applicant]
US 11652815B2 · Keith, Jr. et al. · 2023 [cited by applicant]
US 11775327B2 · Pepus et al. · 2023 [cited by applicant]
US 11783062B2 · Lounsberry · 2023 [cited by applicant]
US 20110296164A1 · Boebert et al. · 2011 [cited by applicant]
US 20150365237A1 · Soffer · 2015 [cited by applicant]
US 20170019443A1 · Conan et al. · 2017 [cited by applicant]
US 20170022082A1 · Prabhu et al. · 2017 [cited by applicant]
US 20170214701A1 · Hasan · 2017 [cited by applicant]
US 20170220823A1 · Law · 2017 [cited by examiner]
US 20180293376A1 · El Abed et al. · 2018 [cited by applicant]
US 20190073478A1 · Khessib · 2019 [cited by examiner]
US 20210084032A1 · Ding et al. · 2021 [cited by applicant]
US 20210149837A1 · Mishra · 2021 [cited by examiner]
US 20210251019A1 · Sayed · 2021 [cited by applicant]
US 20220004635A1 · Nemiroff · 2022 [cited by examiner]
US 20220103351A1 · Cooper · 2022 [cited by applicant]
US 20220198004A1 · Balin · 2022 [cited by examiner]
US 20230009470A1 · Ponnuru · 2023 [cited by examiner]
CN 102314574 · 2012 [cited by applicant]
CN 104462940 · 2015 [cited by applicant]
WO 2016209203 · 2016 [cited by applicant]
WO 2019030748 · 2019 [cited by applicant]
Tian, “Defending Against Malicious USB Firmware with GoodUSB,” ACSAC '15, Dec. 7-11, 2015, Los Angeles, CA USA, pp. 1-10. [cited by applicant]
Wikipedia, “USB Human Interface Device Class,” Wikipedia.org, Retrieved from the Internet, accessed Apr. 22, 2021, pp. 1-5 <https://en.wikipedia.org/wiki/USB_human_interface_device_class>. [cited by applicant]
USB, “Universal Serial Bus—Device Class Definition for Human Interface Devices (HID),” 1996-2001 USB Implementers' Forum, Jun. 27, 2001, pp. 1-97 <http://www.usb.org/developers/hidpage/HID1_11.pdf>. [cited by applicant]
YOUTUBE, “USB Credential Stealing While Screen is Locked,” YOUTUBE.com, Retrieved from the Internet, accessed Apr. 22, 2021, pp. 1-3 <https://www.youtube.com/watch?v=Oplubg5q7ao>. [cited by applicant]
Fuller, “Snagging Creds From Locked Machines,” Malicious.Link, Sep. 6, 2016, Retrieved from the Internet, accessed Apr. 22, 2021, pp. 1-9 <https://malicious.link/post/2016/snagging-creds-from-lockedmachines/>. [cited by applicant]
Eaton, “Building a USB Rubber Ducky for $7,” Aug. 7, 2017, Medium.com, Retrieved from the Internet, accessed Apr. 22, 2021, pp. 1-7 <https://medium.com/@EatonChips/building-a-usb-rubber-ducky-for7-c851aae30a1d>. [cited by applicant]
Brody, “USB Rubber Ducky Tutorial: The Missing Quickstart Guide to Running Your First Keystroke Payload Hack,” Hartleybrody.com, Retrieved from the Internet, accessed Apr. 22, 2021, pp. 1-11 <https://blog.hartleybrody.c… [cited by applicant]
Hak5, “USB Rubber Ducky—HAK5,” hak5.org, Retrieved from the Internet, accessed Apr. 22, 2021, pp. 1-4 <https://shop.hak5.org/products/usb-rubber-ducky-deluxe>. [cited by applicant]
Behind the Sciences, “Make Your Own DIY USB Rubber Ducky,” Behindthesciences.com, May 12, 2017, Retrieved from the Internet, accessed Apr. 22, 2021, pp. 1-11 <https://behindthesciences.com/electronics/make-your-own-diy-… [cited by applicant]
BASIC4, “USB-Rubber-Ducky-Clone-Using-Arduino-Leonardo-Beetle,” Github.com, Retrieved from the Internet, accessed Apr. 22, 2021, pp. 1-2 <https://github.com/basic4/USB-Rubber-Ducky-Clone-usingArduino-Leonardo-Beetle>. [cited by applicant]
Markets and Markets, “Cybersecurity Market Size, Share and Global Market Forecast to 2023,” Market-Reports, Retrieved from the Internet, accessed Apr. 22, 2021, pp. 1-19 <https://www.marketsandmarkets.com/Market-Reports… [cited by applicant]
Zhukov, “Turning a Regular USB Flash Drive into a USB Rubber Ducky,” HackMag.com, Retrieved from the Internet, accessed Apr. 22, 2021, pp. 1-17 <https://hackmag.com/security/rubber-ducky/>. [cited by applicant]
LMG Security, “Bad USB, Very Bad USB,” lmgsecurity.com, Retrieved from the Internet, accessed Apr. 27, 2021, p. 1-6 <https://www.lmgsecurity.com/bad-usb-very-bad-usb/>. [cited by applicant]
Nachreiner, “USB Lock Screen Bypass—Daily Security Byte,” Secplicity.org, Retrieved from the Internet, accessed Apr. 22, 2021, pp. 1-2 <https://www.secplicity.org/2016/09/12/usb-lock-screen-bypass-dailysecurity-byte/>. [cited by applicant]
Gaul, “Cyber Security Market Statistics—2027,” AlliedMarketResearch.com, Retrieved from the Internet, accessed Apr. 22, 2021, pp. 1-13 <https://www.alliedmarketresearch.com/cyber-security-market>. [cited by applicant]
Mell, Peter, et al., “The NIST Definition of Cloud Computing”, NIST Special Publication 800-145, Sep. 2011, Gaithersburg, MD, 7 pgs. [cited by applicant]