US2013061323A1PendingUtilityA1

System and method for protecting against malware utilizing key loggers

Assignee: TRUSTED KNIGHT CORPPriority: Apr 23, 2008Filed: Nov 2, 2012Published: Mar 7, 2013
Est. expiryApr 23, 2028(~1.7 yrs left)· nominal 20-yr term from priority
Inventors:Lloyd Liske
G06F 21/53
35
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A software, system and methodology for protecting against malware key logger attacks that utilize, for example, form-grabbing techniques. The application protects the browser from key logging malware attacks, and the loss of critical user confidential information often entered into internet forms for the purpose of buying items or logging into financial institutions. An embodiment of a method for blocking form-grabbing attacks includes the following steps. Upon detecting a form submission event from the browser, and immediately after allowing the data to be properly submitted, the form input fields are cleared of data. The method prevents hook-based key loggers or form-grabbing key loggers from capturing form input data, thereby protecting the user from theft of passwords or credentials.

Claims

exact text as granted — not AI-modified
1 . A method for preventing malicious memory table patching injection into an Internet browser by comparing known browser memory table entry points with altered table entry points in browser process chains and software hooks, comprising the steps of:
 determining a 0 ring hook in an operating system to be scanned;   scanning active browser memory tables;   comparing memory entry points against known memory tables to establish if a malicious patch has occurred;   when the malicious patch occurs, restoring an altered memory table address to a clean state to render the malicious browser memory injection process null; and   restoring the 0 ring hook.   
     
     
         2 . A method for monitoring and restoring system memory tables of computer operating system processes executed when a malicious process has injected itself into a new system processes, comprising the steps of:
 determining a local system hook;   scanning an entry point of an executable or dynamic link library file specified in a at least one of a Portable Executable header or a private hook procedure;   comparing entry points against known malware memory table entry points in system processes or Internet browser memory tables;   restoring injected memory tables to original memory entry points; and   releasing a local system hook.   
     
     
         3 . A method for monitoring and blocking maliciously created program mutexes from a database, comprising the steps of:
 determining a 0 ring hook or local system hook of established system processes;   monitoring system API calls for new established or created mutexes;   comparing mutexes with a database of known malicious mutex names;   when a match is found, creating an exact null mutex with the same name; and   verifying malicious mutex has terminated and restoring system hooks.   
     
     
         4 . A method for determining system memory NTDLL protection of base addresses, comprising the steps of:
 determining a 0 ring hook or system level hook;   monitoring access to base addresses CONTAINING_RECORD(NtCurrentTeb( )→Peb—Ldr→InInitializationOrderModuleList.Flink, LDR_MODULE or InInitializationOrderModuleList)→BaseAddress or system entry point API functions of NTDLL!NtQueryDirectoryFile, NTDLL!NtVdmControl, NTDLL!NtEnumerateValueKey, NTDLL!NtResumeThread, NTDLL!LdrLoadDll,user32.dll!TranslateMessage,wininet.dll!Internet CloseHandle,wininet.dll!HttpSendRequestA,wininet.dll!HttpSendRequestW,nspr4.dll!PR_Write (called by Firefox),ws2 —  32.dll!send,Advapi32.dll!CryptEncrypt;   when a memory injection or table alteration is detected, restoring tables   restoring the 0 ring hook or system hook.   
     
     
         5 . A method for blocking malicious system buffer based API calls and system hooks by blocking malware anti-memory break point functions, comprising the steps of:
 establishing a 0 ring hook or local hook;   scanning system calls in a loop for GetprocAddress based lookups;   comparing 32 or 64 bit ROL-7-XOR hash lookup processes against known malicious GetProcAddress based lookups;   restoring dynamically loaded images to null; and   restore the system hooks.   
     
     
         6 . A method for blocking malicious system API hooking through the use of standard detour hooks, comprising the steps of:
 determining a 0 ring hook in system API stack;   monitoring system memory locations and attempts to relocate memory locations Jcc rel 8 or LOOPcc, JMP rel32, CALL rel 32 or rel8 instructions;   inserting a nulled memory call with an INC EAX/DEC EAX [40h/48h] memory instruction to fool a malicious process into assuming the API function is hooked already; and   restoring system hooks.   
     
     
         7 . A method for blocking injection of a malicious memory image injection into a remote processProtect, SedebugPrivilege escallation or NtReadVirtualMemory to access memory calls of a target process, comprising the steps of:
 determining a local hook;   monitoring for processProtect, SedebugPrivilege escallation or NtReadVirtualMemory memory calls;   comparing to a known database of malicious calls; and   restoring memory tables to null.   
     
     
         8 . A method for blocking memory injection based keystroke logging, comprising the steps of:
 determining a 0 ring system API hook;   monitoring for TranslateMessage, GetKeyboardState and ToUnicode(lpMsg wParam) hooks; and   when at least one the TranslateMessage, GetKeyboardState and ToUnicode(lpMsg wParam) hooks is detected, unhooking an API call; and   restoring system hooks.   
     
     
         9 . A method for detecting malicious system named pipes by comparing created system mutexes against established database of known malware mutexes and malware named pipes, comprising the steps of:
 determining a 0 ring hook or local system hook;   monitoring created mutexes or created system named pipe calls;   scanning and comparing named pipes and created mutexes against an established database;   when a match is found, terminating the named pipe call or mutex; and   restoring system hooks.   
     
     
         10 . A method for blocking malicious memory injection based screen recording or screen scraping attempts, comprising the steps of:
 determining 0 ring hook or local system hook;   monitor import hook API calls to user32!TranslateMessage with calls to WM_LBUTTONDOWN with an accompanying call to HttpSendRequestA hook iii) block call to HttpSendRequestA iv) restore system hooks   
     
     
         11 . A method for blocking malicious memory Browser injection, comprising the steps of:
 determining a 0 ring hook or local system hook;   monitoring for at least one of the following wininet functions for memory based hooks: wininet.dll!HttpSendRequestW, wininet.dll!HttpSendRequestA,wininet.dll!HttpSendRequestExW,wininet.dll!HttpSendRequestExA,wininet.dll!InternetReadFile,wininet.dll!InternetReadFileExW,wininet.dll!InternetReadFileExA,wininet.dll!InternetQueryDataAvailable,wininet.dll!InternetCloseHandle,wininet.dll!HttpQueryInfoA,wininet.dll!HttpQueryInfoW;   detecting and nullifying attempted hooks; and   restoring system hooks to a previous state.   
     
     
         12 . A method for blocking ring 3 keystroke logging using a windows function call TranslateMessage, comprising the steps of:
 determining a 0 ring hook or local level hook;   monitoring for TranslateMessage system calls;   when a TranslateMessage call by wininet call is detected, unhooking the call;   restore the system call to null; and   restoring system hooks.

Join the waitlist — get patent alerts

Track US2013061323A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.