Streetwise Security Zone

Practical security and privacy coaching

Honey Stick Project - Phase 1 Results

By Scott Wright - October 2010

This report summarizes the findings from Phase 1 of the Honey Stick Project. For background on the project and its methodology, see the project overview.

Methodology

Twenty USB flash drives were prepared with a tracking beacon - a small HTML file that, when opened, sends a GET request to our monitoring server with a unique identifier, timestamp, and the requesting IP address. No executable code was placed on the drives. Each drive also contained several decoy files (fake spreadsheets, text documents) to make the drive appear legitimate.

Drives were distributed across five location categories:

Each drive was labeled with one of four categories: "Confidential", "Salary Info Q3", "Photos", or no label.

Results Summary

Overall Access Rate

Of the 20 drives dropped, 13 (65%) were plugged into a computer and had at least one file accessed. The remaining 7 drives either were not picked up, were picked up but not plugged in, or were turned in to a lost-and-found without being accessed.

Access by Label

Access by Location

Network Analysis

Based on reverse DNS and IP geolocation of the beacon requests:

Notable Observations

The conference venue results were particularly interesting. These drives were dropped at a security conference - an event attended primarily by IT security professionals. Even in this audience, 50% of the drives were accessed. This suggests that awareness of the threat does not reliably translate to changed behavior.

The corporate network access pattern is concerning. These drives were not just plugged in at home out of curiosity - they were brought into corporate environments and connected to machines on internal networks. In a real attack scenario, this would provide an attacker with an initial foothold inside the corporate perimeter.

Zero people who accessed a drive reported it to their organization's IT security team during the monitoring period.

Recommendations

  1. Security awareness training should include hands-on demonstrations, not just slides. Show people what happens when a malicious USB is plugged in.
  2. Organizations should implement USB device controls that prevent unauthorized storage devices from being mounted.
  3. Endpoint detection solutions should monitor for new USB device connections and flag unknown devices.
  4. Regular social engineering testing - including USB drop campaigns - should be part of an organization's security assessment program.
  5. Create a simple, non-punitive reporting process for employees who find unknown devices. The current "do not plug it in" message is not working. Give people a positive action to take instead.

Next Steps

Phase 2 of the Honey Stick Project will expand the experiment to include more locations, test the effectiveness of different security awareness interventions, and measure whether organizations that have completed awareness training show lower access rates than those that have not.