| name | cis-ubuntu2004-v300-1-1-1-9 |
| description | Ensure usb-storage kernel module is not available |
| category | cis-storage |
| version | 3.0.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu","linux","ubuntu-20.04","kernel-module"] |
| cis_id | 1.1.1.9 |
| cis_benchmark | CIS Ubuntu Linux 20.04 LTS Benchmark v3.0.0 |
| tech_stack | ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Ensure usb-storage kernel module is not available
Profile
Level 1 - Server, Level 2 - Workstation, Assessment: Automated
Description
USB storage provides a means to transfer and store files ensuring persistence and availability of the files independent of network connection status. Its popularity and utility has led to USB-based malware being a simple and common means for network infiltration and a first step to establishing a persistent threat within a networked environment.
Rationale
Restricting USB access on the system will decrease the physical attack surface for a device and diminish the possible vectors to introduce malware.
Impact
Disabling the usb-storage module will disable any usage of USB storage devices.
If requirements and local site policy allow the use of such devices, other solutions should be configured accordingly instead. One example of a commonly used solution is USBGuard.
Audit Procedure
Command Line
Verify the usb-storage kernel module is not available on the system - OR - has been disabled.
Run the following script to determine if the usb-storage kernel module is available on the system:
#!/usr/bin/env bash
{
l_mod_name="usb-storage" l_mod_type="drivers"
while IFS= read -r l_mod_path; do
if [ -d "$l_mod_path/${l_mod_name}//-/\/" ] && [ -n "$(ls -A "$l_mod_path/${l_mod_name}//-/\/")" ]; then
printf '%s\n' "$l_mod_name exists in $l_mod_path"
fi
done < <(readlink -f /usr/lib/modules/**/kernel/$l_mod_type || readlink -f /lib/modules/**/kernel/)
}