USB Protection and Anti-Bridging

Overview

NPAV EDR provides advanced endpoint protection through comprehensive USB Device Control and Anti-Bridging capabilities. These features help prevent unauthorized hardware access, protect against USB-based attacks, and ensure that managed endpoints cannot be used to bypass organizational network security controls.

USB Device Protection

NPAV EDR protects endpoints from malicious and unauthorized USB devices by enforcing centralized device control policies. The solution detects and blocks reprogrammed USB devices, including devices that emulate keyboards or other Human Interface Devices (HIDs), preventing automated command execution and unauthorized access.

Key capabilities include:

  • Detection and blocking of keyboard-emulating USB devices (BadUSB).
  • Protection against unauthorized Human Interface Devices (HIDs).
  • Prevention of malicious USB command injection.
  • Centralized USB device policy management.
  • Real-time monitoring and logging of USB connection events.

On-Screen Keyboard Control

NPAV EDR enables administrators to configure policies that control the use of on-screen keyboards during authorization and authentication processes. This helps enforce secure authentication practices and supports organizational security policies for sensitive operations.

Anti-Bridging Protection

NPAV EDR includes Anti-Bridging functionality for Windows workstations to prevent endpoints from creating unauthorized network bridges between trusted and untrusted networks.

The solution continuously monitors network interfaces and blocks attempts to establish network bridges that could bypass firewall protections, network segmentation, or other perimeter security controls.

Key capabilities include:

  • Prevention of unauthorized network bridging.
  • Blocking of traffic forwarding between multiple network interfaces.
  • Protection against bypassing perimeter security controls.
  • Enforcement of network segmentation policies.
  • Monitoring and logging of network bridge attempts.
  • Centralized configuration and policy enforcement through the management console.

Key Benefits

  • Blocks reprogrammed USB devices and keyboard-emulation attacks.
  • Controls the use of on-screen keyboards for secure authorization.
  • Prevents unauthorized USB-based access and malicious HID attacks.
  • Protects Windows endpoints against unauthorized network bridging.
  • Prevents bypass of firewall and perimeter security controls.
  • Provides centralized policy management, monitoring, and reporting through the NPAV EDR Management Console.