IP Library › Granted Patent US 9,798,879
Granted Patent B2
US 9,798,879 · App. 15/616,728 · Granted Oct 24, 2017

Apparatus, system, and method for protecting against keylogging malware

Inventor: Raymond Lloyd Reddington (Delta, CA)
Assignee: Trusted Knight Corporation
G06F21/566G06F21/52G06F21/53G06F21/6245H04L63/105H04L63/145H04L63/1416H04L63/1441H04L63/1483G06F2221/031G06F2221/2143
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,798,879
App. No.
15/616,728
Granted
Oct 24, 2017
Kind
B2
Abstract

An apparatus, system, and method is disclosed for protecting against key logger malware. The protection includes protection form grabbing keylogger malware. In response to detecting a form submission event from a browser associated with a user entering data into a form, confidential data is cleared to prevent it being captured by malware. Additional protection of data inputs, entered at a driver level, may be provided as an additional level of protection against hook based malware operating at a virtual keyboard level or operating system level. Data inputs received at a physical driver level may be protected as they pass through a virtual keyboard level and an operating system level. The projection against malware may be provided as a preventive measure that does not require detection of the key logger malware itself.

Claims (50)

1. A method for preventing software key logging executable by a microprocessor, comprising:

invoking an anti-key logger by an individual web page or website accessed by a user in an online access session;

installing and maintaining the anti-key logger at a most privileged access level;

detecting, by the anti-key logger, a form submission initiation call event associated with data inputs entered by a user to be submitted to the individual webpage or the website;

encrypting at least some of the data inputs to generate encrypted data inputs;

submitting the encrypted data inputs to an intended application;

decrypting, by a component of the intended application, the encrypted data inputs;

submitting the decrypted data inputs to a designated receiving party; and

preventing, by the anti-key logger, malware from capturing the at least some of the data inputs.

2. The method of claim 1 , wherein the most privileged access level is a most privileged access level for browser events.

3. The method of claim 1 , wherein the anti-key logger does not require detection of the malware to prevent the malware from capturing the at least some of the data inputs.

4. The method of claim 1 , wherein the form submission initiation call event is an OnSubmit call event or a BeforeNavigate call event.

5. A method for preventing software key logging executable by a microprocessor, comprising:

invoking an anti-key logger in response to an initiation of an online access session;

installing and maintaining the anti-key logger at a most privileged access level;

detecting, by the anti-key logger, a form submission initiation call event associated with data inputs entered by a user to be submitted to a website;

encrypting at least some of the data inputs to generate encrypted data inputs;

submitting the encrypted data inputs to an intended application;

decrypting the encrypted data inputs;

submitting the decrypted data inputs to a designated receiving party;

preventing, by the anti-key logger, malware from capturing the at least some of the data inputs;

and uninstalling the anti-key logger in response to a logoff of the online access session.

6. The method of claim 5 , wherein the most privileged access level is a most privileged access level for browser events.

7. The method of claim 5 , wherein the anti-key logger does not require detection of the malware to prevent the malware from capturing the at least some of the data inputs.

8. The method of claim 5 , wherein the form submission initiation call event is an OnSubmit call event or a BeforeNavigate call event.

9. A computer program product to prevent software key logging including computer program code embedded in a non-transitory microprocessor-readable storage medium executable by a microprocessor, which when executed on the microprocessor, implements a method, comprising:

invoking an anti-key logger by an individual web page or website accessed by a user in an online access session;

installing and maintaining the anti-key logger at a most privileged access level;

detecting, by the anti-key logger, a form submission initiation call event associated with data inputs entered by a user to be submitted to the individual webpage or the website;

encrypting at least some of the data inputs to generate encrypted data inputs;

submitting the encrypted data inputs to an intended application;

decrypting, by a component of the intended application, the encrypted data inputs;

submitting the decrypted data inputs to a designated receiving party; and

preventing, by the anti-key logger, malware from capturing the at least some of the data inputs.

10. The computer program product of claim 9 , wherein the most privileged access level is a most privileged access level for browser events.

11. The computer program product of claim 9 , wherein the anti-key logger does not require detection of the malware to prevent the malware from capturing the at least some of the data inputs.

12. The computer program product of claim 9 , wherein the form submission initiation call event is an OnSubmit call event or a BeforeNavigate call event.

13. A computer program product to prevent software key logging including computer program code embedded in a non-transitory microprocessor-readable storage medium executable by a microprocessor, which when executed on the microprocessor, implements a method, comprising:

invoking an anti-key logger in response to an initiation of an online access session;

installing and maintaining the anti-key logger at a most privileged access level;

detecting, by the anti-key logger, a form submission initiation call event associated with data inputs entered by a user to be submitted to a website;

encrypting at least some of the data inputs to generate encrypted data inputs;

submitting the encrypted data inputs to an intended application;

decrypting the encrypted data inputs;

submitting the decrypted data inputs to a designated receiving party;

preventing, by the anti-key logger, malware from capturing the at least some of the data inputs; and

uninstalling the anti-key logger in response to a logoff of the online access session.

14. The computer program product of claim 13 , wherein the most privileged access level is a most privileged access level for browser events.

15. The computer program product of claim 13 , wherein the anti-key logger does not require detection of the malware to prevent the malware from capturing the at least some of the data inputs.

16. The computer program product of claim 11 , wherein the form submission initiation call event is an OnSubmit call event or a BeforeNavigate call event.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 5, 2017
From: REDDINGTON, RAYMOND LLOYD
To: TRUSTED KNIGHT CORPORATION
Reel/Frame 043487/0940 →
Continuity (7)
Continuation 15356325 · Nov 18, 2016
Continuation 15207279 · Jul 11, 2016
Continuation 14709224 · May 11, 2015
Continuation In Part 13667256 · Nov 2, 2012
Continuation 12427833 · Apr 22, 2009
Provisional Application 61125178 · Apr 23, 2008
Related Publication 20170270300A1 · Sep 21, 2017