TY - GEN
T1 - Bait your Hook: a Novel Detection Technique for Keyloggers
AU - Ortolani, S.
AU - Giuffrida, C.
AU - Crispo, B.
PY - 2010
Y1 - 2010
N2 - Software keyloggers are a fast growing class of malware often used to harvest confidential information. One of the main reasons for this rapid growth is the possibility for unprivileged programs running in user space to eavesdrop and record all the keystrokes of the users of the system. Such an ability to run in unprivileged mode facilitates their implementation and distribution, but, at the same time, allows to understand and model their behavior in detail. Leveraging this property, we propose a new detection technique that simulates carefully crafted keystroke sequences (the bait) in input and observes the behavior of the keylogger in output to univocally identify it among all the running processes. We have prototyped and evaluated this technique with some of the most common free keyloggers. Experimental results are encouraging and confirm the viability of our approach in practical scenarios.
AB - Software keyloggers are a fast growing class of malware often used to harvest confidential information. One of the main reasons for this rapid growth is the possibility for unprivileged programs running in user space to eavesdrop and record all the keystrokes of the users of the system. Such an ability to run in unprivileged mode facilitates their implementation and distribution, but, at the same time, allows to understand and model their behavior in detail. Leveraging this property, we propose a new detection technique that simulates carefully crafted keystroke sequences (the bait) in input and observes the behavior of the keylogger in output to univocally identify it among all the running processes. We have prototyped and evaluated this technique with some of the most common free keyloggers. Experimental results are encouraging and confirm the viability of our approach in practical scenarios.
U2 - 10.1007/978-3-642-15512-3_11
DO - 10.1007/978-3-642-15512-3_11
M3 - Conference contribution
T3 - Lecture Notes in Computer Science
SP - 200
EP - 217
BT - Proceedings of the 13th International Symposium on Recent Advances in Intrusion Detection
PB - Springer
ER -