3.2 Hardware Trojans in Computers
219
Keylogger (keyboard logger) is, in fact, a keyboard spy.
In general, it is necessary to say that today there are countless variants of realization
of keyloggers; however, they all share the common principle of work, which consists
in interruption of the signal passing process from the key pressing moment until the
moment of appearance of a symbol of the screen.
The most common way of implementation of such Trojans is a keylogger installing
special keyboard hooks. It has nothing to do with boxing—the term “hook” in
Windows is used to refer to a mechanism of the message interception system using
a special function.
Win32API is usually used for implementation of this function. Most keyboard
spies of this type known to us use the hook WH_Keyboard. In addition to
WH_KEYBOARD, the hook WH_ JOURNALRECORD is also used.
The difference between them lies in the fact that WH_JOURNALRECORD does
not require a separate dynamic library (DLL), which simplifies distribution of this
foul thing through a network.
Keyboard hooks read information from the system queue of hardware input placed
in a system process. This method gained special popularity due to the fact that a
filtering hook allows intercepting absolutely all pressed keys, since the hook controls
all system streams.
Creation of such spy does not require special skills except for knowledge of Visual
C++ or Delphi and Win32API. However, the use of this method forces the hacker to
create a separate dynamic library (DLL) as well.
It should be noted that the operating method of such hooks is fairly simple and
effective; however, it has a number of flaws. The first disadvantage is the fact that
DLL with the hook is projected to the address space of all GUI processes, which
can be used to detect the keylogger.
One of the most widely used methods of operation of such Trojan is periodic
polling of the current keyboard state. This method does not require introduction of
DLL into GUI processes; as a result, such keylogger is more difficult to find.
The disadvantage of all keyloggers of this type is the necessity of periodic polling
of the current keyboard state with a fairly high rate of at least 10–20 polls per second.
Another type of keyloggers includes driver-based keyloggers. This method is most
effective as compared with the ones described above. There are at least two ways
of implementation of this method—writing and installing custom keyboard driver
instead of the standard one or installing a filter driver. This method (similar to the
hook) is a documented method of keyboard input tracking. This method is described
in detail in the in Chap. 2.
Another popular option is a rootkit keylogger. It can be implemented both in user
mode and in kernel mode. In user mode, keyboard input tracking can be based on
intercepting the exchange of the process csrss.exe by the keyboard driver or using
tracking of calls of API functions like GetMessage and PeekMessage.
In many cases, even virtual keyboards, which are often presented as a magic pill
for all types of keyloggers, cannot protect the user.
219
Keylogger (keyboard logger) is, in fact, a keyboard spy.
In general, it is necessary to say that today there are countless variants of realization
of keyloggers; however, they all share the common principle of work, which consists
in interruption of the signal passing process from the key pressing moment until the
moment of appearance of a symbol of the screen.
The most common way of implementation of such Trojans is a keylogger installing
special keyboard hooks. It has nothing to do with boxing—the term “hook” in
Windows is used to refer to a mechanism of the message interception system using
a special function.
Win32API is usually used for implementation of this function. Most keyboard
spies of this type known to us use the hook WH_Keyboard. In addition to
WH_KEYBOARD, the hook WH_ JOURNALRECORD is also used.
The difference between them lies in the fact that WH_JOURNALRECORD does
not require a separate dynamic library (DLL), which simplifies distribution of this
foul thing through a network.
Keyboard hooks read information from the system queue of hardware input placed
in a system process. This method gained special popularity due to the fact that a
filtering hook allows intercepting absolutely all pressed keys, since the hook controls
all system streams.
Creation of such spy does not require special skills except for knowledge of Visual
C++ or Delphi and Win32API. However, the use of this method forces the hacker to
create a separate dynamic library (DLL) as well.
It should be noted that the operating method of such hooks is fairly simple and
effective; however, it has a number of flaws. The first disadvantage is the fact that
DLL with the hook is projected to the address space of all GUI processes, which
can be used to detect the keylogger.
One of the most widely used methods of operation of such Trojan is periodic
polling of the current keyboard state. This method does not require introduction of
DLL into GUI processes; as a result, such keylogger is more difficult to find.
The disadvantage of all keyloggers of this type is the necessity of periodic polling
of the current keyboard state with a fairly high rate of at least 10–20 polls per second.
Another type of keyloggers includes driver-based keyloggers. This method is most
effective as compared with the ones described above. There are at least two ways
of implementation of this method—writing and installing custom keyboard driver
instead of the standard one or installing a filter driver. This method (similar to the
hook) is a documented method of keyboard input tracking. This method is described
in detail in the in Chap. 2.
Another popular option is a rootkit keylogger. It can be implemented both in user
mode and in kernel mode. In user mode, keyboard input tracking can be based on
intercepting the exchange of the process csrss.exe by the keyboard driver or using
tracking of calls of API functions like GetMessage and PeekMessage.
In many cases, even virtual keyboards, which are often presented as a magic pill
for all types of keyloggers, cannot protect the user.
