Real-Time Detection of USB Rubber Ducky Attacks Using Behavioral Keystroke Analysis
Main Article Content
Abstract
The USB Rubber Ducky is a malicious device that disguises itself as a standard flash drive while functioning as a keyboard to inject commands at extremely high speeds. Such attacks are file-less, exploit the inherent trust of operating systems in Human Interface Devices (HIDs), and therefore bypass traditional antivirus and endpoint security solutions. This work proposes a real-time detection system that monitors USB activity and applies behavioral analysis of keystrokes to identify anomalies such as excessive typing speed, rapid command execution, and irregular input sequences. Upon detection, the system generates alerts, maintains logs, and can optionally disable the suspicious device. The proposed solution is lightweight, cost-effective, and enhances protection against HID-based cyberattacks.
Downloads
Article Details

This work is licensed under a Creative Commons Attribution-NoDerivatives 4.0 International License.