3.2 Hardware Trojans in Computers
221
– Using the web script page that uses peculiarities of Internet browsers helping the
programs to boot automatically when the user visits these pages;
Using a previously installed malicious program that can download and install similar
programs in the system.
Let us give a brief list of known methods of searching of keyloggers. It turns out
that regardless of all the sophistication of keyloggers examined in Chap. 2, there
are specific and fairly successful methods for their detection; we will consider these
methods below.
Signature-based search. This method is basically identical to typical methods of
virus search. Signature search helps the user unambiguously identify keyloggers; with
correct selection of signatures, the possibility of a mistake is close to zero. However,
a signature scanner will be able to detect previously known objects recorded in its
database; therefore, this base needs to be large and requires constant updating.
Heuristic algorithms. These methods of keylogger search are based on its characteristic (individual) peculiarities. Heuristic search is always probability-based
and more effective for finding keyloggers of the most popular type (hook-based);
however, these methods sometimes return many false positives in practice. Some
studies have shown that there are hundreds of safe programs that are not keyboard
spies but use hooks to track keyboard input and mouse. The most popular examples
are Punto Switcher and software of multimedia keyboards and mouses.
Monitoring of API functions used by keyloggers. This method is based on interception of a number of functions applied by a keyboard spy, in particular, the functions
SetWindowsHookEx, UnhookWindowsHookEx, GetAsyncKeyState, and GetKeyboardState. Alarm is raised promptly if these functions are called by applications;
however, the problem of multiple false positives will be the same as with the previous
method.
Tracking of drivers, processors, and services used by the system. This is a multipurpose method that can be used not only against keyboard spies. In the most basic
case, it is possible to use programs like Kaspersky Inspector that track emergence of
new files in a system.
This is the basic information about search methods; now, let us have a look at the
methods of protection from both hardware and software keyloggers.
It should be said that most antivirus companies today add popular keyloggers
to their bases, and the method of protection from them is similar to methods of
protection from any other malware:
– Antivirus product is installed;
– Bases are updated in a timely manner.
However, it doesn’t always help: since most antivirus products classify keyloggers
as potentially hazardous software (riskware), it is necessary to make sure that the
default settings of the used antivirus product allow detecting of the programs of this
class. Otherwise, it is necessary to configure this setting manually. This will provide
real protection from most widely spread keyloggers.
221
– Using the web script page that uses peculiarities of Internet browsers helping the
programs to boot automatically when the user visits these pages;
Using a previously installed malicious program that can download and install similar
programs in the system.
Let us give a brief list of known methods of searching of keyloggers. It turns out
that regardless of all the sophistication of keyloggers examined in Chap. 2, there
are specific and fairly successful methods for their detection; we will consider these
methods below.
Signature-based search. This method is basically identical to typical methods of
virus search. Signature search helps the user unambiguously identify keyloggers; with
correct selection of signatures, the possibility of a mistake is close to zero. However,
a signature scanner will be able to detect previously known objects recorded in its
database; therefore, this base needs to be large and requires constant updating.
Heuristic algorithms. These methods of keylogger search are based on its characteristic (individual) peculiarities. Heuristic search is always probability-based
and more effective for finding keyloggers of the most popular type (hook-based);
however, these methods sometimes return many false positives in practice. Some
studies have shown that there are hundreds of safe programs that are not keyboard
spies but use hooks to track keyboard input and mouse. The most popular examples
are Punto Switcher and software of multimedia keyboards and mouses.
Monitoring of API functions used by keyloggers. This method is based on interception of a number of functions applied by a keyboard spy, in particular, the functions
SetWindowsHookEx, UnhookWindowsHookEx, GetAsyncKeyState, and GetKeyboardState. Alarm is raised promptly if these functions are called by applications;
however, the problem of multiple false positives will be the same as with the previous
method.
Tracking of drivers, processors, and services used by the system. This is a multipurpose method that can be used not only against keyboard spies. In the most basic
case, it is possible to use programs like Kaspersky Inspector that track emergence of
new files in a system.
This is the basic information about search methods; now, let us have a look at the
methods of protection from both hardware and software keyloggers.
It should be said that most antivirus companies today add popular keyloggers
to their bases, and the method of protection from them is similar to methods of
protection from any other malware:
– Antivirus product is installed;
– Bases are updated in a timely manner.
However, it doesn’t always help: since most antivirus products classify keyloggers
as potentially hazardous software (riskware), it is necessary to make sure that the
default settings of the used antivirus product allow detecting of the programs of this
class. Otherwise, it is necessary to configure this setting manually. This will provide
real protection from most widely spread keyloggers.
