Skip to content
Open access

Development of a Raspberry Pi-Based Secure USB Passthrough System to Mitigate Bad USB Keystroke-Injection Attacks

2026 · International journal of research and innovation in social science · 0 citations

Abstract

BadUSB attacks exploit the implicit trust that operating systems place in USB Human Interface Devices (HIDs), enabling a malicious peripheral to inject automated keystrokes and execute commands as if they originated from a legitimate user. This study develops a low-cost USB passthrough system that operates independently of host-side security software, using a Raspberry Pi 4 as an intermediary security layer between a keyboard and a host computer. The prototype combines VID/PID-based device identification, whitelist and blacklist controls, real-time keystroke-timing analysis, CAPTCHA-based human verification, input forwarding, and security-event logging. A Raspberry Pi Pico configured as a malicious HID was used in a preliminary, attack-driven functional evaluation comprising seven black-box test cases covering device enrolment, normal keyboard passthrough, resilience, malicious-keystroke detection, human verification, logging, and administrative functions. Of 18 predefined functional outcomes, 16 passed, one partially passed, and one failed. These outcomes demonstrate the functional feasibility of the prototype under the tested configuration but do not represent detection accuracy or general classification performance. The limited evaluation did not support the calculation of a confusion matrix, precision, recall, F1-score, or false-positive rate. The preliminary latency comparison indicated an additional average delay of 1.15 ms; however, the available experiment did not provide sufficient statistical evidence for broader performance interpretation. Broader repeated testing involving multiple users, devices, operating systems, attack patterns, and statistically rigorous latency measurements is required before operational deployment.

Read PDF

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.