Some malware modifies the firmware of USB devices (for example, a USB flash drive) to trick the operating system into detecting the USB device as a keyboard. As a result, when the device is connected to a computer, the malware may execute commands (for example, download other malware).
The BadUSB Attack Prevention component prevents infected USB devices emulating a keyboard from connecting to the computer.
This feature is available only if you activated Kaspersky Endpoint Security Cloud under a Kaspersky Endpoint Security Cloud Pro license.
When a USB device is connected to the computer and identified as a keyboard by the operating system, the application prompts the user to use this keyboard and enter a numerical code generated by the application. This procedure is known as keyboard authorization.
If the code has been entered correctly, the application saves the identification parameters—VID/PID of the keyboard and the number of the port to which it has been connected—in the list of authorized keyboards. Keyboard authorization does not need to be repeated when the keyboard is reconnected or after the operating system is restarted.
When the authorized keyboard is connected to a different USB port of the computer, the application shows a prompt for authorization of this keyboard again.
If the numerical code has been entered incorrectly, the application generates a new code. You can configure the number of attempts for entering the numerical code. If the numerical code is entered incorrectly several times or the keyboard authorization window is closed, the application blocks input from this keyboard. When the USB device blocking time elapses or the operating system is restarted, the application prompts the user to perform a keyboard authorization again.
The application allows use of an authorized keyboard and blocks a keyboard that has not been authorized.
To configure the BadUSB Attack Prevention component:
The Security profiles section contains a list of security profiles configured in Kaspersky Endpoint Security Cloud.
The security profile properties window displays settings available for all devices.
The BadUSB Attack Prevention component settings page opens.
After the security profile is applied, the BadUSB Attack Prevention component is enabled and configured on Windows devices.Page top