Detecting Kernel Level Keyloggers Through Dynamic Taint Analysis

Duy Le, Chuan Yue, Tyler J. Smart, Haining Wang · 2008

Keyloggers as invisible keystroke recorders have posed a serious threat to user privacy and security. It is difficult to detect keyloggers, especially kernel keyloggers that operate at the operating system’s kernel level, because of their inconspicuous activities and flexible interception methods. In this paper, we propose a framework using a dynamic taint analysis technique to detect kernel level keyloggers. Our design is originated from the observation that kernel keyloggers usually manipulate the data flow of a keyboard driver in order to record typed keystrokes. By tainting and monitoring the keystroke data, this framework detects and analyzes any illegitimate uses of the tainted keystroke data. Based on Argos, a system that can perform host-based intrusion detection and support dynamic taint analysis, we build a prototype of the proposed framework and evaluate its effectiveness. Our experimental results show that the proposed framework can accurately detect kernel level keylogging activities and identify their root causes.

Read the paper · More papers on PaperTik