munotes®

Spyware and Keyloggers from the Defensive Side

Get access to whole semester resourcesSemester Pass

Chapter Fifty-Three

Syllabus topic Module 1, "System Hacking and Privilege Escalation Concepts: Analyze ... spyware technologies from a defensive perspective"

Pages 258 to 261 of 578

In one line

Spyware secretly collects information and sends it to someone else; a keylogger is the specific form that records what is typed. Both are detected the same way as any covert program: by the traces their necessary parts leave, and prevented by the same endpoint discipline that limits all malware.

In examination wording: spyware is software that covertly gathers information about a user or system and transmits it to a third party; a keylogger is spyware that records keystrokes to capture credentials, messages and other typed data; both are countered by endpoint protection, least privilege, control over what may be installed and connected, and monitoring for the collection, persistence and exfiltration behaviours they must exhibit.

Why they are studied with rootkits

Spyware shares the rootkit's instinct to stay quiet, but its goal is collection rather than concealment of a foothold. Where a rootkit hides an intrusion, spyware harvests: passwords, banking details, messages, documents, browsing, and, in the keylogger's case, every keystroke including the ones typed into a password box before any masking.

They are placed together because they are the covert half of the malware world, the programs whose success depends on not being noticed, and so they are detected by the same principle: a covert program still has to do things, and the things it must do leave traces.

The parts a covert collector must have

A defender is told the parts not in order to build one but because each part is a place to look. Any program that quietly collects and sends information must, at concept level, have:

  • a collection component that captures what it wants: keystrokes, screen contents, files, browsing, or audio and video from a device;
  • a staging component that holds the collected data on the machine until it can be sent;
  • an exfiltration component that sends it to the collector, usually disguised as ordinary traffic;
  • a persistence component so it survives a restart, which is the auto-start machinery of the earlier chapter;
  • often a concealment component to avoid notice, which in the worst case is the rootkit machinery of the previous chapter.

The defensive value is that each part leaves a distinct kind of trace, so knowing the parts tells a defender what to monitor:

PartThe trace a defender looks for
CollectionHooking of input or screen capture, unusual access to input devices
StagingAn unexpected growing file, data accumulating in a temporary area
ExfiltrationUnexplained outbound connections, the single most reliable indicator, seen off-host
PersistenceA start-up entry not in the baseline, from the auto-start audit
ConcealmentThe cross-view discrepancies of the rootkit chapter

Exfiltration is the one a covert collector cannot avoid: the data must leave the machine to be useful, and that departure is visible from the network and in the off-host logs, regardless of how well the program hides on the host. That is why egress monitoring, met in the Log4Shell case and again here, is such a powerful control against this whole category.

munotes.in258

Spyware and Keyloggers from the Defensive Side

Software and hardware keyloggers

A keylogger deserves a specific note because it has a form the others do not.

A software keylogger is a program, and it is detected and prevented like any covert program: by endpoint protection, by the traces above, and by controlling what may be installed.

A hardware keylogger is a physical device placed between a keyboard and a computer, or inside one. It has a property that matters for defence: because it captures keystrokes in hardware, before the operating system, no software running on the machine can see it, so software detection cannot find it. It also has a corresponding weakness: it is physical, so it is found by physical inspection and prevented by physical controls over access to machines. This is a rare case in this book where the defence is a lock and a look rather than a configuration, and it is worth knowing precisely because it defeats the software-only mindset.

Prevention and detection

The controls are the endpoint discipline that limits all malware, previewed here and treated fully in the Module 2 endpoint chapter:

Prevention:

  • Least privilege, so that a collector installed under an ordinary account can capture less and persist less easily; deep collection and system-wide keylogging generally need elevated rights.
  • Control over what may be installed, ideally application allow-listing so unapproved programs cannot run at all, which stops most spyware before it starts. Much spyware arrives bundled with something the user chose to install, which is the baiting route from the social-engineering block.
  • Control over what may be connected, restricting removable devices, which addresses both the bundled-download route and the hardware keylogger.
  • Patching and email and web filtering, to close the arrival routes.
  • Physical security of machines, for the hardware case.

Detection:

  • Endpoint detection tools watching for input hooking, screen capture, and the creation of persistence.
  • Egress monitoring for the exfiltration that a collector cannot avoid, which is the most reliable single signal.
  • The auto-start audit of the persistence chapter, which finds the survival mechanism.
  • Integrity and cross-view methods from the rootkit chapter where concealment is involved.
  • Physical inspection for hardware devices.

The unifying point, and the reason this chapter can be short: spyware and keyloggers are covert programs, and covert programs are caught by the traces of the things they must do, which are the same traces the last two chapters taught a defender to watch.

munotes.in259

Spyware and Keyloggers from the Defensive Side

A worked example, run as a defender

A finance team member reports that money moved from an account after they logged in normally, with no phishing they can recall. The team investigates the workstation.

  • Egress monitoring shows the machine made periodic connections to an unfamiliar external address, small and regular, at times unrelated to the user's activity. This is the exfiltration trace, and it is visible from the network without trusting the host.
  • The auto-start audit finds a start-up entry not in the baseline: the persistence trace.
  • Endpoint telemetry shows the responsible program hooking keyboard input: the collection trace, consistent with a keylogger that captured the banking credentials as they were typed.
  • Because concealment was involved, the analysts corroborate from clean examination rather than trusting the live system.

The response follows the system-hacking block: isolate the host, preserve evidence, treat it as compromised and rebuild from clean media, and, crucially, rotate every credential the user entered on that machine, because a keylogger captured them regardless of how strong they were, which is why the password chapters coming next insist that multi-factor authentication matters precisely because it survives a stolen password. The team also checks how the program arrived, finding it bundled with an unapproved download, which turns into a recommendation for application allow-listing.

Each trace corresponded to a part the collector could not do without, which is the chapter's method in practice.

What beginners get wrong

  • Thinking a covert program is undetectable because it hides on the host. It must still collect, persist and, above all, send the data, and those actions leave traces, most reliably the outbound connection seen off-host.
  • Trying to detect a hardware keylogger with software. It captures before the operating system, so software cannot see it; it is found by physical inspection and prevented by physical control.
  • Believing a strong password defeats a keylogger. A keylogger captures the password as typed, whatever its strength; multi-factor authentication is what limits the damage, which is why it recurs as the key control.
  • Forgetting the arrival route. Much spyware is bundled with a chosen download or arrives through phishing; controlling installation and filtering mail and web addresses the source.
  • Underrating egress monitoring. The data must leave to be useful, so its departure is the trace a collector cannot avoid.
  • Cleaning instead of rebuilding after a confirmed infection, and forgetting to rotate credentials the machine may have captured.

Quick revision

  • Spyware covertly collects and transmits information; a keylogger is the form that records keystrokes, capturing credentials as typed.
  • A covert collector must have collection, staging, exfiltration, persistence and often concealment; each part leaves a trace, and exfiltration, the outbound connection, is the one it cannot avoid and the most reliable signal, visible off-host.
  • Software keyloggers are detected and prevented like any covert program; hardware keyloggers capture before the operating system, so software cannot see them, and are found by physical inspection and prevented by physical control.
  • Prevention: least privilege, application allow-listing, control over connected devices, patching, mail and web filtering, physical security.
  • Detection: endpoint tools for input hooking and persistence creation, egress monitoring, the auto-start audit, integrity and cross-view methods, and physical inspection.
  • After a confirmed infection: rebuild from clean media and rotate every credential the machine may have captured; multi-factor authentication limits the damage of a stolen password.
munotes.in260

Spyware and Keyloggers from the Defensive Side

Test yourself

  1. What is the difference between spyware and a keylogger, and what do they have in common with a rootkit?

Spyware covertly collects information about a user or system and transmits it to a third party; a keylogger is the specific form that records keystrokes to capture credentials and other typed data. They share with a rootkit the instinct to remain unnoticed, so all three are covert programs, but spyware and keyloggers exist to harvest information whereas a rootkit exists to conceal an intrusion.

  1. Why does knowing the parts of a covert collector help a defender, and which part cannot be avoided?

Because each part, collection, staging, exfiltration, persistence and concealment, leaves a distinct kind of trace, so knowing the parts tells a defender what to monitor. Exfiltration cannot be avoided, because the collected data must leave the machine to be of any use, and that departure is visible as an outbound connection from the network and in off-host logs regardless of how well the program hides on the host.

  1. Why can software not detect a hardware keylogger, and how is one found?

Because a hardware keylogger captures keystrokes in the physical path between keyboard and computer, before the operating system processes them, so no software running on the machine can observe it. It is found by physical inspection of the machine and its connections and prevented by physical controls over who can access the hardware.

  1. Why is a strong password no defence against a keylogger, and what is?

Because a keylogger records the password exactly as it is typed, so its strength is irrelevant once it has been entered on the compromised machine. Multi-factor authentication limits the damage, because a captured password alone is then insufficient to authenticate, which is why it is emphasised as the key control against credential theft.

  1. What must be done to credentials after a confirmed keylogger infection, and why?

Every credential the user entered on the affected machine must be rotated, because the keylogger will have captured them as they were typed regardless of their strength or how they were stored elsewhere. The host itself should be rebuilt from clean media, since a confirmed covert infection means it can no longer be trusted, and the arrival route should be investigated to prevent recurrence.

munotes.in261

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.

Issue
Done!