154
2 Computer Viruses, Malicious Logic, and Spyware
Software based on visualization technologies can be considered as a means of
creating and using false objects in the telecommunication part of the information
space. Such software visualization means as VMware ESX/ESXi, Microsoft HyperV, Citrix Xen Server, and so on help create a virtual infrastructure, fill it with false
objects containing deceptive information, and subsequently control such system [10].
In addition to the above visualization means, it is possible to use other means
and methods of creating false objects. They can include creation of false objects by
substituting addresses of network objects, deployment of additional networks with
organization of misleading information exchange, and the use of network protection
means with deliberately embedded vulnerabilities (so-called baits). Examples of such
solutions can be found in works of Russian specialists [11–13].
2.4 Software Keyboard Spies
2.4.1 Operating Principle of Keyloggers
Keyloggers are programs for hidden recording of the keys pressed by the user. The
term “keylogger” has a number of synonyms: Keyboard Logger, KeyLogger, or
snooper.
Keyloggers make up a large category of malware that poses a great danger to user
security. Like rootkits described in the previous article, keyloggers are not viruses,
which means that they aren’t able to reproduce.
As a rule, software keyloggers don’t just record codes of the pressed keys: they
link the keyboard input to the current window and the input element. Moreover,
many keyboard loggers track the list of running applications, can take screenshots
according to the set schedule or events, spy over the clipboard contents, and solve
a number of tasks aimed at secretly tracking the user. The recording information
is saved on the hard drive; most modern keyboard loggers are able to form various
reports and transfer them via e-mail or http/FTP protocol. Moreover, a number of
modern keyloggers use rootkit technologies to mask the traces of their presence in
the system.
A keylogger is usually harmless for the system—it cannot affect its operation.
However, it is extremely dangerous for the user—with a keylogger, an intruder can
intercept passwords and other confidential information input by the user; There are
hundreds of various keyloggers, many of which are not detected by antiviruses.
Figure 2.12 shows a simplified model of hardware input of the Windows system.
In case of emergence of certain input events (pressing of keys, movement of the
mouse), these events are processed by the corresponding driver and placed in the
system queue of hardware input. The system has a special raw input stream (RIT—
Raw input thread), which extracts events from the system queue and transforms them
into message. The messages formed are placed at the end of the queue of virtualized
input of one of the streams (VIQ—Virtualized input queue). RIT itself determines
Précédent

- 175/839

Suivant