Keylogger Detection via Simulated Keystroke Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for detecting keyloggers on information handling systems require manual inspection and rely on signature-based anti-malware/anti-virus software, making it difficult to detect both known and unknown malicious programs without user intervention.

Innovation Solution

Implementing a non-signature based system that simulates keystrokes with known characteristics and monitors system resource activity to identify keylogger processes, which can automatically detect and respond to potential keylogger presence by simulating keystrokes and analyzing resulting system resource usage patterns.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual inspection methods are used to detect keyloggers, then detection accuracy for known keyloggers is improved, but automation level and productivity deteriorate

Engineering Contradiction:
Improvedetection accuracyVSAvoidautomation level
Core Design Contradiction:
Measurement precisionVSExtent of automation

Solution Approach 1:

The system performs self-detection by automatically generating test keystrokes and monitoring system responses without requiring user intervention. The keylogger detection process is autonomous, with the system serving itself to identify malicious software through automated behavioral analysis.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by injecting test keystrokes before actual user input to provoke and detect keylogger behavior. This proactive approach allows the system to identify potential keyloggers before they can capture real sensitive information.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If signature-based anti-malware software is used, then detection of known keyloggers is improved, but detection of unknown keyloggers deteriorates

Engineering Contradiction:
Improvedetection accuracy for known keyloggersVSAvoiddetection capability for unknown keyloggers
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system changes the approach from static signature matching to dynamic behavioral parameter analysis. By monitoring parameters such as keystroke timing, frequency, and system resource usage patterns, the system can detect both known and unknown keyloggers based on their operational characteristics rather than predefined signatures.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

Instead of analyzing keylogger code signatures to detect malware, the system inverts the approach by analyzing the behavioral output and system resource usage caused by keylogger execution. This reverse engineering approach detects malware based on what it does rather than what it is.

Inventive Principle:
Principle #13The other way round (Inversion)

3Productivity

If automated detection systems are implemented, then productivity and automation level are improved, but system complexity increases

Engineering Contradiction:
Improvedetection efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system uses an intermediary approach by introducing test keystrokes as a mediator between the user and the keylogger detection process. This intermediary mechanism allows automated detection without requiring complex direct analysis of user input patterns or system deep inspection.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Measurement precision

If manual inspection of running processes and network connections is required, then detection accuracy is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvedetection accuracyVSAvoiduser effort required
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system performs self-detection by automatically generating test keystrokes and monitoring system responses without requiring user intervention. The keylogger detection process is autonomous, with the system serving itself to identify malicious software through automated behavioral analysis.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11281772B2Systems and methods to detect key loggers
Publication Date: 2022.03.22 DELL PROD LP
  • US11281772B2 patent drawing
  • US11281772B2 patent drawing
  • US11281772B2 patent drawing

AI summary

Systems and methods are provided for detecting the presence of a key logger program that is executing on a processing device of an information handling system by inputting simulated keystrokes to an information handling system with known key stroke characteristic/s (e.g., quantity of keystrokes as a function of time, keystroke data size as a function of time, and/or keystroke values as a function of time), and monitoring to detect resulting system activity characteristics that match the known key stroke characteristic/s of the simulated key strokes.