This would basically be a packet-inspecting firewall for USB instead of IP. I agree that this would pose a number of technical challanges as a lot of the tools and optimizations we have in IP stacks don't exist for USB, but I don't see how that would be principally impossible.
In fact, as there is a lot more standardization in USB profiles than in IP protocols, it might even be easier. I.e. if you just inspected messages of the mass storage profile and blocked everything else, you might already get pretty far. I agree that the performance problem would stay though.