Unprivileged Black box Detection of User Space Keystroke Harvesting Malware
- 1Anna University Chennai, Francis Xavier Engineering College, Tirunelveli ,Tamilnadu,India., IN
- 2Anna University Chennai, Francis Xavier Engineering College, Tirunelveli ,Tamilnadu,India., IN
Key loggers are used on a machine to monitor the user activity by logging keystrokes and delivering them to a third party. The main goal is to prevent user-space key loggers from stealing confidential data originally intended for a legitimate foreground application. Therefore, a new detection technique has been proposed that simulates carefully crafted keystroke sequences in input and observes the behaviour of the key logger in output to identify it among all the running processes. The proposed detection technique is implemented in C#, it runs as an unprivileged application for the Windows OS. An unprivileged black box approach for accurate detection of user space key loggers has been devised by correlating the input (keystrokes) with the output (I/O patterns produced by the key logger).
Conclusion
An unprivileged black-box approach for accurate detection of the most common key loggers i.e., user space keyloggers. The behavior of a keylogger by surgically correlating the input (i.e., the keystrokes) with the output (i.e., the I/O patterns produced by the keylogger). The detection technique can be used to detect any kind of keyloggers such as keylogger monitoring, email keylogger and so on. It is detected based on the behaviour of the key stroke harvesting malware. Sub sequent, an implementation of detection technique on Windows, arguably the most vulnerable OS to the threat of keyloggers. This technique has been successfully evaluated prototype system against the most common free keyloggers. This approach considerably raises the bar for protecting the user against the threat of keyloggers.
References
- S. Ortolani and B. Crispo, “Noisykey: Tolerating KeyloggersviaKeystrokes Hiding,” Proc. Seventh USENIX Workshop Hot Topics in Security, 2012.
- San Jose Mercury News, “Kinkois Spyware Case Highlights Risk of Public Internet Terminals,” 2012.
- N. Grebennikov, “Keyloggers: How They Work and How to Detect Them,” 2012.
- M. Vuagnoux and S. Pasini, “Compromising Electromagnetic Emanations of Wired and Wireless Keyboards,” Proc. 18thUSENIX Security Symp., pp. 1-16, 2009.
- T. Holz, M. Engelberth, and F. Freiling, “Learning More About the Underground Economy: A Case-Study of Keyloggers and Dropzones,” Proc. 14th European Symp. Research in Computer Security, pp. 1-18, 2009.
- D. Brumley, C. Hartwig, Z. Liang, J. Newsome, D. Song, and H. Yin, “Automatically Identifying Trigger-Based Behavior in Malware,” Advances in Information Security, vol. 36, pp. 65-88, 2008.
- J. Han, J. Kwon, and H. Lee, “Honeyid: Unveiling Hidden Spywares by Generating Bogus Events,” Proc. IFIP 23rd Int’l Information Security Conf., pp. 669-673, 2008.
- Y. Al-Hammadi and U. Aickelin, “Detecting Bots Based on Keylogging Activities,” Proc. Third Int’l Conf. Availability, Reliability and Security, pp. 896-902, 2008.
- A. Moser, C. Kruegel, and E. Kirda, “Exploring Multiple Execution Paths for Malware Analysis,” Proc. IEEE 28th Symp. Security and Privacy, pp. 231-245, May 2007.
- E. Kirda, C. Kruegel, G. Banks, G. Vigna, and R. Kemmerer, “Behavior-Based Spyware Detection,” Proc. 15th USENIX Security Symp., pp. 273-288, 2006.
- L. Goodwin and N. Leech, “Understanding Correlation: Factors that Affect the Size of r,” Experimental Education, vol. 74, no. 3,pp. 249-266, 2006.
- L. Zhuang, F. Zhou, and J.D. Tygar, “Keyboard Acoustic Emanations Revisited,” ACM Trans. Information and System Security, vol. 13, no. 1, pp. 1-26, 2009.
- M. Aslam, R. Idrees, M. Baig, and M. Arshad, “Anti-Hook Shield against the Software Key Loggers,” Proc. Nat’l Conf. Emerging Technologies, pp. 189-191, 2004.
- G. Kochenberger, F. Glover, and B. Alidaee, “An Effective Approach for Solving the Binary Assignment Problem with Side Constraints,” Information Technology and Decision Making, vol. 1,pp. 121-129, May 2002.
- J.L. Rodgers and W.A. Nicewander, “Thirteen Ways to Look at the Correlation Coefficient,” The Am. Statistician, vol. 42, no. 1, pp. 59-66, Feb. 1988.
Keywords: Invasive software, keylogger, security, black-box
Citation: J. Rosli Jeba*, J. Rosli Jeba, J. Rosli Jeba, J. Rosli Jeba ( 2014), Unprivileged Black box Detection of User Space Keystroke Harvesting Malware. , 2(1): 1-6
Received: 02/06/2024; Accepted: 02/06/2024;
Published: 02/06/2024
Edited by:
Mr.ERES JOURNALS

