munotes®

Keyloggers and Spyware: the Architecture

Get access to whole semester resourcesSemester Pass

Chapter One Hundred Twelve

Syllabus topic Module 2, "Malware Analysis and Threat Detection: types of malware (... spyware), malware behaviour"

Pages 514 to 517 of 578

In one line

Spyware secretly gathers information about the user; a keylogger is the spyware that records keystrokes (capturing passwords and messages as they are typed). Understood defensively, every such payload must capture the information, store it, and exfiltrate it to the attacker, and each of those three stages is where a defender detects and stops it.

In examination wording: spyware is malware that covertly collects information about a user or system and transmits it to a third party; a keylogger is spyware that records keystrokes to capture typed credentials and communications; defensively, such payloads follow a capture-store-exfiltrate pattern, and detection targets the anomalous exfiltration of data and the presence of the covert program.

Why understand the architecture, defensively

MU asks for "malware behaviour", and for spyware the useful behaviour to understand is the shape every covert-information payload must have, because that shape is where a defender catches it. This chapter describes that shape, the capture, store, exfiltrate pattern, strictly as a detection map: knowing the three stages a spyware program must perform tells a defender the three places to look for it. It is not a guide to building one; it is the structure a defender uses to recognise and stop one, which is exactly the defensive value MU intends by "behaviour".

The reason this works: spyware's purpose is to get the user's information to the attacker. That purpose forces a structure, and the structure has observable points. A defender who knows the structure knows what to monitor.

Spyware and the keylogger

Spyware is the general payload: software that covertly gathers information about the user or the system, browsing habits, files, credentials, screenshots, and reports it to a third party, all without the user's knowledge. Its defining properties are that it is covert (hidden from the user) and that it gathers and reports information (rather than encrypting or destroying).

A keylogger is the specific and important case: spyware that records what the user types. It is important because typed keystrokes include the most sensitive things, passwords as they are entered, messages, card numbers, before any encryption protects them, so a keylogger captures secrets at the one moment they are in the clear. This connects to the password chapters: a keylogger defeats even a strong password, because it captures the password as it is typed, which is why it is a serious threat and why defences like multi-factor authentication (something beyond the typed password) matter, since a captured password alone is then not enough.

The three stages, as detection points

Every covert-information payload, to fulfil its purpose, must do three things, and the defensive point is that each is a detection opportunity:

  1. Capture. It must obtain the information, recording keystrokes, taking screenshots, reading files. Detection point: the act of capturing often requires the program to interpose itself in a way that monitoring and endpoint protection can recognise as anomalous (a program watching all keystrokes is unusual and detectable), and the covert program's mere presence can be found by scanning.
  2. Store. It must hold the captured information, at least briefly, before sending it. Detection point: hidden accumulation of captured data can be found by inspection, and the storage is a forensic artefact after the fact.
  3. Exfiltrate. It must send the information to the attacker, which means communicating out of the machine or network. Detection point, and the strongest: the exfiltration is a network event, so monitoring outbound traffic (the network-detection chapters) can catch data leaving to an unexpected destination. This is the most reliable detection, because the payload's whole purpose requires it to communicate out, and it cannot avoid this stage.
munotes.in514

Keyloggers and Spyware: the Architecture

The examinable insight: the exfiltration stage is the payload's necessary weakness. However covert the capture and storage, the information must reach the attacker, so it must leave the machine, and that departure is detectable by network monitoring. A defender who watches for anomalous outbound data has a detection that spyware cannot fully evade, because evading it would defeat the spyware's purpose.

Defending against spyware and keyloggers

The defences follow from the stages and from the delivery:

  • Prevent installation (the delivery is usually a trojan or an exploit): user awareness, execution control, patching, least privilege, the defences already built.
  • Detect the program: endpoint protection and scanning find known spyware and recognise the anomalous behaviour of capture (the detection chapter's methods).
  • Detect the exfiltration: network monitoring for unexpected outbound connections and unusual data transfers, the stage the payload cannot skip.
  • Limit the value of what is captured: multi-factor authentication, so a captured password alone is insufficient; and not entering the most sensitive data on untrusted machines.
  • Least privilege, limiting what spyware can read.

The layered point: prevent delivery, detect the program and its capture behaviour, and above all detect the exfiltration, while multi-factor authentication limits the damage of what a keylogger captures.

A worked example, framed defensively

An analyst investigates a suspected data-theft incident, using the capture-store-exfiltrate map to guide detection, on the organisation's systems.

  • Monitoring flagged an unexpected outbound connection sending data to an unfamiliar destination at regular intervals. The exfiltration stage, the payload's necessary weakness, is what surfaced the incident, illustrating why network monitoring is the strongest detection.
  • Investigation found a covert program recording keystrokes (a keylogger), delivered earlier by a trojan. The capture stage: the program interposed to record typing, and its presence and behaviour were then identifiable.
  • A hidden store of captured keystrokes was found on the machine. The storage stage, a forensic artefact confirming what was taken.
  • Response and lessons: the entry was a trojan (so awareness and execution control), the capture was detectable behaviour (so endpoint protection), the exfiltration was the catch (so continued network monitoring), and because passwords were captured, multi-factor authentication limited the damage and captured passwords were reset.
munotes.in515

Keyloggers and Spyware: the Architecture

The investigation used the three-stage map as a detection guide, catching the incident at the exfiltration stage the payload could not avoid. The analyst detects, investigates and defends, and does not build or deploy the spyware.

What beginners get wrong

  • Thinking spyware is defined by damage. It is covert information gathering and reporting, not destruction; its harm is the theft and exposure of information.
  • Underrating the keylogger. It captures passwords and messages as they are typed, before encryption protects them, so it defeats even a strong password, which is why multi-factor authentication matters.
  • Missing that exfiltration is unavoidable. The payload must send the information to the attacker, so it must communicate out, making network monitoring the detection it cannot fully evade.
  • Treating the architecture as a build guide. The three stages are a detection map: they tell a defender the three places to look, which is the defensive value of understanding the behaviour.
  • Relying only on anti-virus. Detecting the program matters, but detecting the exfiltration (network monitoring) is the stronger, evasion-resistant catch, and preventing delivery stops it earlier.
  • Forgetting to limit captured value. Multi-factor authentication and not entering secrets on untrusted machines reduce the damage even when capture occurs.

Quick revision

  • Spyware: covert software that gathers information and reports it to a third party. Keylogger: spyware that records keystrokes, capturing passwords and messages as typed, before encryption, defeating even a strong password (hence multi-factor authentication).
  • Understood defensively, every such payload must capture, store, and exfiltrate, and each stage is a detection point.
  • Exfiltration is the necessary weakness: the information must reach the attacker, so it must leave the machine, and network monitoring of outbound traffic catches it, the evasion-resistant detection.
  • Defence layers: prevent delivery (trojan/exploit defences), detect the program and capture behaviour (endpoint protection), detect exfiltration (network monitoring), limit captured value (multi-factor authentication, least privilege).

Test yourself

  1. What is spyware, what is a keylogger, and why is a keylogger especially dangerous?

Spyware is malware that covertly gathers information about the user or system, such as browsing habits, files, or credentials, and reports it to a third party without the user's knowledge, defined by being hidden and by gathering and reporting rather than destroying. A keylogger is the specific spyware that records what the user types, and it is especially dangerous because typed keystrokes include passwords, messages and card numbers at the one moment they are in the clear, before any encryption protects them, so a keylogger captures secrets directly and defeats even a strong password.

munotes.in516

Keyloggers and Spyware: the Architecture

  1. What three stages must every covert-information payload perform, and why is each a detection point?

It must capture the information, store it at least briefly, and exfiltrate it to the attacker. Capture is a detection point because interposing to record keystrokes or screens is anomalous behaviour that endpoint protection can recognise, and the covert program can be found by scanning; storage is a detection point because hidden accumulated data can be found by inspection and is a forensic artefact; and exfiltration is a detection point, the strongest, because sending the data out is a network event that monitoring of outbound traffic can catch.

  1. Why is the exfiltration stage described as the payload's necessary weakness?

Because the payload's whole purpose is to get the user's information to the attacker, so however covert the capture and storage, the information must ultimately leave the machine and travel to the attacker, which is an observable network event. The payload cannot skip this stage without failing its purpose, so a defender who monitors for anomalous outbound data has a detection that spyware cannot fully evade, since evading it would mean never delivering the stolen information.

  1. How does multi-factor authentication limit the damage of a keylogger, and why is that necessary?

Multi-factor authentication requires something beyond the typed password, such as a code from a separate device or a hardware key, so that a password captured by a keylogger is not by itself enough to gain access. It is necessary because a keylogger captures the password as it is typed, before encryption, which defeats the password no matter how strong it is, so the password alone can no longer be trusted; requiring an additional factor that the keylogger did not capture preserves security despite the captured password.

  1. Why is understanding the capture-store-exfiltrate architecture a defensive skill rather than a construction guide?

Because knowing the three stages a covert-information payload must perform tells a defender the three places to look for it: the anomalous capture behaviour and the covert program, the hidden storage, and above all the unavoidable exfiltration over the network. The architecture is used as a detection map that directs monitoring and investigation to where the payload is observable, which is the defensive value MU intends by asking for malware behaviour, and it describes what to recognise and stop rather than anything to build.

munotes.in517

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.

Issue
Done!