IP Library › Granted Patent US 12,615,286
Granted Patent B2
US 12,615,286 · App. 18/136,922 · Granted Apr 28, 2026

Keystroke log monitoring systems

Inventors: Pei-Wen Chu (Germantown, MD); Daniel W. File (Baltimore, MD); Hao Liu (Oakton, VA); Stephen Shiao (Fairfax, VA)
Assignee: Capital One Services, LLC
H04L63/1466G06N3/04G06N3/08H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,615,286
App. No.
18/136,922
Granted
Apr 28, 2026
Kind
B2
Abstract

Aspects described herein may allow keystroke logs to be monitored. A computing device may receive a plurality of keystroke logs and provide, to a machine learning model, the plurality of keystroke logs. The computing device may receive, as output from the machine learning model, a value representing a likelihood that a first keystroke log comprises a first command to change a computing system. The computing device may retrieve, from a database, one or more change orders, each indicating an authorization to change the computing system. The computing device may send, to a second computing device and based on determining that the first command does not match the one or more change orders, an alert indicating the first keystroke log. In this way, unauthorized change to the computing system may be detected.

Claims (66)

1 . A method comprising:

receiving, by a first computing device, a plurality of keystroke logs;

generating a plurality of tokenized keystroke logs by tokenizing each of the plurality of keystroke logs into one or more respective tokens;

providing, to a machine learning model, the plurality of tokenized keystroke logs, wherein the machine learning model is trained, based on a plurality of training keystroke logs comprising labeled change commands, to output, in response to an input keystroke log, a value representing a likelihood that the input keystroke log comprises a command to change a computing system, wherein the likelihood is lower than one hundred percent;

receiving, as output from the machine learning model, a value representing a likelihood that a first keystroke log comprises a first command to change a computing system by:

tokenizing the first keystroke log into one or more first tokens; and

calculating the value based the one or more first tokens;

retrieving, from a database, one or more change orders, each indicating an authorization to change the computing system;

comparing the first keystroke log with the one or more change orders;

determining that the first command does not match the one or more change orders; and

sending, to a second computing device and based on the determining, an alert indicating the first keystroke log.

2 . The method of claim 1 , further comprising:

receiving a response to the alert, wherein the response indicates whether the first keystroke log comprises the first command or not; and

adjusting, based on the response, the machine learning model.

3 . The method of claim 1 , wherein each of the plurality of keystroke logs indicates keystrokes made by one or more users during a secure socket shell (SSH) session.

4 . The method of claim 1 , wherein the value representing the likelihood that the first keystroke log comprises the first command to change the first computing system is based on a logistic regression model.

5 . The method of claim 1 , wherein the receiving the plurality of keystroke logs comprises:

receiving, from a second database, binary large object (BLOB) data recorded during one or more secure socket shell (SSH) sessions; and

extracting, from the BLOB data, the plurality of keystroke logs.

6 . The method of claim 1 , further comprising:

replacing, before the providing and based on a mapping between a plurality of keywords and a plurality of file extensions, a portion of the plurality of keystroke logs with one or more of the plurality of keywords.

7 . A system comprising:

a first computing device; and

a second computing device;

wherein the first computing device is configured to:

receive a plurality of keystroke logs;

generate a plurality of tokenized keystroke logs by tokenizing each of the plurality of keystroke logs into one or more respective tokens;

provide, to a machine learning model, the plurality of tokenized keystroke logs, wherein the machine learning model is trained, based on a plurality of training keystroke logs comprising labeled change commands, to output, in response to an input keystroke log, a value representing a likelihood that the input keystroke log comprises a command to change a computing system, wherein the likelihood is lower than one hundred percent;

receive, as output from the machine learning model, a value representing a likelihood that a first keystroke log comprises a first command to change a first computing system by:

tokenizing the first keystroke log into one or more first tokens; and

calculating the value based on the one or more tokens;

retrieve, from a database, one or more change orders each indicating an authorization to change the first computing system;

compare the first keystroke log with the one or more change orders;

determine the first command does not match the one or more change orders; and

send, to a second computing device and based on the determining, an alert indicating the first keystroke log; and

wherein the second computing device is configured to:

receive, from the first computing device, the alert.

8 . The system of claim 7 , wherein the first computing device is further configured to: receive a response to the alert, wherein the response indicates whether the first keystroke log comprises the first command or not; and

adjust, based on the response, the machine learning model.

9 . The system of claim 7 , wherein each of the plurality of keystroke logs indicates keystrokes made by one or more users during a secure socket shell (SSH) session.

10 . The system of claim 7 , wherein the value representing the likelihood that the first keystroke log comprises the first command to change the first computing system is based on a logistic regression model.

11 . The system of claim 7 , wherein the first computing device is configured to receive the plurality of keystroke logs by performing actions comprising:

receiving, from a second database, binary large object (BLOB) data recorded during one or more secure socket shell (SSH) sessions; and

extracting, from the BLOB data, the plurality of keystroke logs.

12 . The system of claim 7 , wherein the first computing device is further configured to:

replace, before the providing and based on a mapping between a plurality of keywords and a plurality of file extensions, a portion of the plurality of keystroke logs with one or more of the plurality of keywords.

13 . A non-transitory computer-readable medium storing computer instructions that, when executed by one or more processors, cause performance of actions comprising:

receiving a plurality of keystroke logs;

generate a plurality of tokenized keystroke logs by tokenizing each of the plurality of keystroke logs into one or more respective tokens;

providing, to a machine learning model, the plurality of tokenized keystroke logs, wherein the machine learning model is trained, based on a plurality of training keystroke logs comprising labeled change commands, to output, in response to an input keystroke log, a value representing a likelihood that the input keystroke log comprises a command to change a computing system, wherein the likelihood is lower than one hundred percent;

receiving, as output from the machine learning model, a value representing a likelihood that a first keystroke log comprises a first command to change a first computing system by:

tokenizing the first keystroke log into one or more first tokens; and

calculating the value based on the one or more tokens;

retrieving, from a database, one or more change orders each indicating an authorization to change the first computing system;

comparing the first keystroke log with the one or more change orders;

determining the first keystroke log does not match the one or more change orders;

sending, to a second computing device and based on the determining, an alert indicating the first keystroke log;

receiving a response, to the alert, that indicates whether the first keystroke log comprises the first command or not; and

adjusting, based on the response, the machine learning model.

14 . The non-transitory computer-readable medium of claim 13 , wherein each of the plurality of keystroke logs indicates keystrokes made by one or more users during a secure socket shell (SSH) session.

15 . The non-transitory computer-readable medium of claim 13 , wherein the value representing the likelihood that the first keystroke log comprises the first command to change the first computing system is based on a logistic regression model.

16 . The non-transitory computer-readable medium of claim 13 , wherein the instructions, when executed by the one or more processors, cause receiving the plurality of keystroke logs by performing actions comprising:

receiving, from a second database, binary large object (BLOB) data recorded during one or more secure socket shell (SSH) sessions; and

extracting, from the BLOB data, the plurality of keystroke logs.

17 . The non-transitory computer-readable medium of claim 13 , wherein the instructions, when executed by the one or more processors, further cause performance of actions comprising:

replacing, before the providing and based on a mapping between a plurality of keywords and a plurality of file extensions, a portion of the plurality of keystroke logs with one or more of the plurality of keywords.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 20, 2023
From: CHU, PEI-WEN; FILE, DANIEL W.; LIU, HAO; SHIAO, STEPHEN
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 063387/0957 →
Continuity (1)
Related Publication 20240356965A1 · Oct 24, 2024
References Cited (8)
US 8131281B1 · Hildner · 2012 [cited by examiner]
US 8732476B1 · Van · 2014 [cited by examiner]
US 10581851B1 · File · 2020 [cited by examiner]
US 20080263636A1 · Gusler · 2008 [cited by examiner]
Hohnstein, Dwight, “Man in the Terminal,” Apr. 5, 2021 (Published in Posts by SpecterOps Team Members); <https://posts.specterops.io/man-in-the-terminal-65476e6165b9>. [cited by applicant]
M?nica, Diogo, “Poor man's SSH keylogger,” Feb. 3, 2011; <https://blog.diogomonica.com/2011/02/03/poor-mans-ssh-keylogger/>. [cited by applicant]
Deoxykev, “ssh keylogger ? GitHub,” Feb. 1, 2020; <https://gist.github.com/deoxykev/f335574effda2d7fd2433baa075f3ea9>. [cited by applicant]
Bathla, Shivam, “ELK Log Analysis: SSH Logs,” Jun. 28, 2020 (Published in Pentester Academy Blog); <https://blog.pentesteracademy.com/elk-log-analysis-ssh-logs-2c7924726973>. [cited by applicant]