Keylogger Detection via Simulated Keystroke Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for detecting keyloggers on information handling systems require manual inspection and rely on signature-based anti-malware/anti-virus software, making it difficult to detect both known and unknown malicious programs without user intervention.
Innovation Solution
Implementing a non-signature based system that simulates keystrokes with known characteristics and monitors system resource activity to identify keylogger processes, which can automatically detect and respond to potential keylogger presence by simulating keystrokes and analyzing resulting system resource usage patterns.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual inspection methods are used to detect keyloggers, then detection accuracy for known keyloggers is improved, but automation level and productivity deteriorate
Solution Approach 1:
The system performs self-detection by automatically generating test keystrokes and monitoring system responses without requiring user intervention. The keylogger detection process is autonomous, with the system serving itself to identify malicious software through automated behavioral analysis.
Solution Approach 2:
The system performs preliminary actions by injecting test keystrokes before actual user input to provoke and detect keylogger behavior. This proactive approach allows the system to identify potential keyloggers before they can capture real sensitive information.
2Measurement precision
If signature-based anti-malware software is used, then detection of known keyloggers is improved, but detection of unknown keyloggers deteriorates
Solution Approach 1:
The system changes the approach from static signature matching to dynamic behavioral parameter analysis. By monitoring parameters such as keystroke timing, frequency, and system resource usage patterns, the system can detect both known and unknown keyloggers based on their operational characteristics rather than predefined signatures.
Solution Approach 2:
Instead of analyzing keylogger code signatures to detect malware, the system inverts the approach by analyzing the behavioral output and system resource usage caused by keylogger execution. This reverse engineering approach detects malware based on what it does rather than what it is.
3Productivity
If automated detection systems are implemented, then productivity and automation level are improved, but system complexity increases
Solution Approach 1:
The system uses an intermediary approach by introducing test keystrokes as a mediator between the user and the keylogger detection process. This intermediary mechanism allows automated detection without requiring complex direct analysis of user input patterns or system deep inspection.
4Measurement precision
If manual inspection of running processes and network connections is required, then detection accuracy is improved, but ease of operation deteriorates
Solution Approach 1:
The system performs self-detection by automatically generating test keystrokes and monitoring system responses without requiring user intervention. The keylogger detection process is autonomous, with the system serving itself to identify malicious software through automated behavioral analysis.
Data Source
AI summary
Systems and methods are provided for detecting the presence of a key logger program that is executing on a processing device of an information handling system by inputting simulated keystrokes to an information handling system with known key stroke characteristic/s (e.g., quantity of keystrokes as a function of time, keystroke data size as a function of time, and/or keystroke values as a function of time), and monitoring to detect resulting system activity characteristics that match the known key stroke characteristic/s of the simulated key strokes.


