Development of a Raspberry Pi-Based Secure USB Passthrough System to Mitigate Bad USB Keystroke-Injection Attacks

Authors

Muhammad Alif Nukman bin Nor Azman

Faculty of Artificial Intelligence and Cyber Security, Universiti Teknikal Malaysia Melaka, Hang Tuah Jaya, 76100 Durian Tunggal, Melaka (Malaysia)

Nurhashikin Mohd Salleh

Faculty of Artificial Intelligence and Cyber Security, Universiti Teknikal Malaysia Melaka, Hang Tuah Jaya, 76100 Durian Tunggal, Melaka (Malaysia)

Siti Rahayu Selamat

Faculty of Artificial Intelligence and Cyber Security, Universiti Teknikal Malaysia Melaka, Hang Tuah Jaya, 76100 Durian Tunggal, Melaka (Malaysia)

Aimi Liyana Amir

Faculty of Computer and Mathematical Sciences, Universiti Teknologi Mara, Cawangan Melaka, Kampus Jasin, Jalan Lembah Kesang 1/1-2, Kampung Seri Mendapat, 77300 Merlimau, Melaka (Malaysia)

Mohd Taufik Mishan

Faculty of Computer and Mathematical Sciences, Universiti Teknologi Mara, Cawangan Melaka, Kampus Jasin, Jalan Lembah Kesang 1/1-2, Kampung Seri Mendapat, 77300 Merlimau, Melaka (Malaysia)

Article Information

DOI: 10.47772/IJRISS.2026.100800329

Subject Category: Social science

Volume/Issue: 10/8 | Page No: 4974-4984

Publication Timeline

Submitted: 2026-08-19

Accepted: 2026-08-24

Published: 2026-09-03

Abstract

BadUSB attacks exploit the implicit trust that operating systems place in USB Human Interface Devices (HIDs), enabling a malicious peripheral to inject automated keystrokes and execute commands as if they originated from a legitimate user. This study develops a low-cost USB passthrough system that operates independently of host-side security software, using a Raspberry Pi 4 as an intermediary security layer between a keyboard and a host computer. The prototype combines VID/PID-based device identification, whitelist and blacklist controls, real-time keystroke-timing analysis, CAPTCHA-based human verification, input forwarding, and security-event logging. A Raspberry Pi Pico configured as a malicious HID was used in a preliminary, attack-driven functional evaluation comprising seven black-box test cases covering device enrolment, normal keyboard passthrough, resilience, malicious-keystroke detection, human verification, logging, and administrative functions. Of 18 predefined functional outcomes, 16 passed, one partially passed, and one failed. These outcomes demonstrate the functional feasibility of the prototype under the tested configuration but do not represent detection accuracy or general classification performance. The limited evaluation did not support the calculation of a confusion matrix, precision, recall, F1-score, or false-positive rate. The preliminary latency comparison indicated an additional average delay of 1.15 ms; however, the available experiment did not provide sufficient statistical evidence for broader performance interpretation. Broader repeated testing involving multiple users, devices, operating systems, attack patterns, and statistically rigorous latency measurements is required before operational deployment.

Keywords

BadUSB, Human Interface Device (HID), Raspberry Pi, USB Passthrough, Keystroke Injection

Downloads

References

1. Axelson, J. (2015). USB complete: The developer’s guide. Lakeview Research. [Google Scholar] [Crossref]

2. Fakiha, B. S. (2024). Forensic analysis of BadUSB attacks: A methodology for detecting and mitigating malicious USB device activities. Edelweiss Applied Science and Technology, 8(5), 1090–1100. [Google Scholar] [Crossref]

3. Charan, V., & Kulkarni, L. (2023). Survey on micro-controller-based BadUSB attacks. Journal of Positive School Psychology, 7(1), 965–974. [Google Scholar] [Crossref]

4. Nissim, N., Yahalom, R., & Elovici, Y. (2017). USB-based attacks. Computers & Security, 70, 675–688. [Google Scholar] [Crossref]

5. Karystinos, E., Andreatos, A., & Douligeris, C. (2019). Spyduino: Arduino as a HID exploiting the BadUSB vulnerability. In Proceedings of the IEEE International Conference on Distributed Computing in Sensor Systems (DCOSS). [Google Scholar] [Crossref]

6. Nicho, M., & Sabry, I. (2023). Bypassing multiple security layers using malicious USB Human Interface Device. In Proceedings of the 9th International Conference on Information Systems Security and Privacy (pp. 501–508). [Google Scholar] [Crossref]

7. Tian, D. J., Bates, A., & Butler, K. (2015). Defending against malicious USB firmware with GoodUSB. In Proceedings of the 31st Annual Computer Security Applications Conference. [Google Scholar] [Crossref]

8. Wang, C.-Y., & Hsu, F.-H. (2024). USBIPS framework: Protecting hosts from malicious USB peripherals. arXiv. [Google Scholar] [Crossref]

9. Dumitru, R., Beaumont, M., & Hopkins, B. (2023). USB proxy. In Proceedings of the 2023 Australasian Computer Science Week (pp. 122–125). [Google Scholar] [Crossref]

10. Koffi, K. A., Smiliotopoulos, C., Kolias, C., & Kambourakis, G. (2024). To (US)Be or not to (US)Be: Discovering malicious USB peripherals through neural network-driven power analysis. Electronics, 13(11), Article 2117. [Google Scholar] [Crossref]

11. Seo, J.-H., & Moon, J.-S. (2017). Analysis and countermeasure for BadUSB vulnerability. IEMEK Journal of Embedded Systems and Applications, 12(6), 359–368. [Google Scholar] [Crossref]

12. Blanchet, S. (2018). BadUSB: The threat hidden in ordinary objects. ResearchGate. [Google Scholar] [Crossref]

13. Pham, D. V., Syed, A., & Halgamuge, M. N. (2011). Universal Serial Bus-based software attacks and protection solutions. Digital Investigation, 7(3–4), 172–184. [Google Scholar] [Crossref]

14. Dasgupta, R. K. (2018). Turning regular AVR microcontroller to Human Interface Device (HID) for hacking and penetration testing. [Google Scholar] [Crossref]

Metrics

Views & Downloads

Similar Articles