Keystroke log monitoring systems
Aspects described herein may allow keystroke logs to be monitored. A computing device may receive a plurality of keystroke logs and provide, to a machine learning model, the plurality of keystroke logs. The computing device may receive, as output from the machine learning model, a value representing a likelihood that a first keystroke log comprises a first command to change a computing system. The computing device may retrieve, from a database, one or more change orders, each indicating an authorization to change the computing system. The computing device may send, to a second computing device and based on determining that the first command does not match the one or more change orders, an alert indicating the first keystroke log. In this way, unauthorized change to the computing system may be detected.
1 . A method comprising:
receiving, by a first computing device, a plurality of keystroke logs;
generating a plurality of tokenized keystroke logs by tokenizing each of the plurality of keystroke logs into one or more respective tokens;
providing, to a machine learning model, the plurality of tokenized keystroke logs, wherein the machine learning model is trained, based on a plurality of training keystroke logs comprising labeled change commands, to output, in response to an input keystroke log, a value representing a likelihood that the input keystroke log comprises a command to change a computing system, wherein the likelihood is lower than one hundred percent;
receiving, as output from the machine learning model, a value representing a likelihood that a first keystroke log comprises a first command to change a computing system by:
tokenizing the first keystroke log into one or more first tokens; and
calculating the value based the one or more first tokens;
retrieving, from a database, one or more change orders, each indicating an authorization to change the computing system;
comparing the first keystroke log with the one or more change orders;
determining that the first command does not match the one or more change orders; and
sending, to a second computing device and based on the determining, an alert indicating the first keystroke log.
2 . The method of claim 1 , further comprising:
receiving a response to the alert, wherein the response indicates whether the first keystroke log comprises the first command or not; and
adjusting, based on the response, the machine learning model.
3 . The method of claim 1 , wherein each of the plurality of keystroke logs indicates keystrokes made by one or more users during a secure socket shell (SSH) session.
4 . The method of claim 1 , wherein the value representing the likelihood that the first keystroke log comprises the first command to change the first computing system is based on a logistic regression model.
5 . The method of claim 1 , wherein the receiving the plurality of keystroke logs comprises:
receiving, from a second database, binary large object (BLOB) data recorded during one or more secure socket shell (SSH) sessions; and
extracting, from the BLOB data, the plurality of keystroke logs.
6 . The method of claim 1 , further comprising:
replacing, before the providing and based on a mapping between a plurality of keywords and a plurality of file extensions, a portion of the plurality of keystroke logs with one or more of the plurality of keywords.
7 . A system comprising:
a first computing device; and
a second computing device;
wherein the first computing device is configured to:
receive a plurality of keystroke logs;
generate a plurality of tokenized keystroke logs by tokenizing each of the plurality of keystroke logs into one or more respective tokens;
provide, to a machine learning model, the plurality of tokenized keystroke logs, wherein the machine learning model is trained, based on a plurality of training keystroke logs comprising labeled change commands, to output, in response to an input keystroke log, a value representing a likelihood that the input keystroke log comprises a command to change a computing system, wherein the likelihood is lower than one hundred percent;
receive, as output from the machine learning model, a value representing a likelihood that a first keystroke log comprises a first command to change a first computing system by:
tokenizing the first keystroke log into one or more first tokens; and
calculating the value based on the one or more tokens;
retrieve, from a database, one or more change orders each indicating an authorization to change the first computing system;
compare the first keystroke log with the one or more change orders;
determine the first command does not match the one or more change orders; and
send, to a second computing device and based on the determining, an alert indicating the first keystroke log; and
wherein the second computing device is configured to:
receive, from the first computing device, the alert.
8 . The system of claim 7 , wherein the first computing device is further configured to: receive a response to the alert, wherein the response indicates whether the first keystroke log comprises the first command or not; and
adjust, based on the response, the machine learning model.
9 . The system of claim 7 , wherein each of the plurality of keystroke logs indicates keystrokes made by one or more users during a secure socket shell (SSH) session.
10 . The system of claim 7 , wherein the value representing the likelihood that the first keystroke log comprises the first command to change the first computing system is based on a logistic regression model.
11 . The system of claim 7 , wherein the first computing device is configured to receive the plurality of keystroke logs by performing actions comprising:
receiving, from a second database, binary large object (BLOB) data recorded during one or more secure socket shell (SSH) sessions; and
extracting, from the BLOB data, the plurality of keystroke logs.
12 . The system of claim 7 , wherein the first computing device is further configured to:
replace, before the providing and based on a mapping between a plurality of keywords and a plurality of file extensions, a portion of the plurality of keystroke logs with one or more of the plurality of keywords.
13 . A non-transitory computer-readable medium storing computer instructions that, when executed by one or more processors, cause performance of actions comprising:
receiving a plurality of keystroke logs;
generate a plurality of tokenized keystroke logs by tokenizing each of the plurality of keystroke logs into one or more respective tokens;
providing, to a machine learning model, the plurality of tokenized keystroke logs, wherein the machine learning model is trained, based on a plurality of training keystroke logs comprising labeled change commands, to output, in response to an input keystroke log, a value representing a likelihood that the input keystroke log comprises a command to change a computing system, wherein the likelihood is lower than one hundred percent;
receiving, as output from the machine learning model, a value representing a likelihood that a first keystroke log comprises a first command to change a first computing system by:
tokenizing the first keystroke log into one or more first tokens; and
calculating the value based on the one or more tokens;
retrieving, from a database, one or more change orders each indicating an authorization to change the first computing system;
comparing the first keystroke log with the one or more change orders;
determining the first keystroke log does not match the one or more change orders;
sending, to a second computing device and based on the determining, an alert indicating the first keystroke log;
receiving a response, to the alert, that indicates whether the first keystroke log comprises the first command or not; and
adjusting, based on the response, the machine learning model.
14 . The non-transitory computer-readable medium of claim 13 , wherein each of the plurality of keystroke logs indicates keystrokes made by one or more users during a secure socket shell (SSH) session.
15 . The non-transitory computer-readable medium of claim 13 , wherein the value representing the likelihood that the first keystroke log comprises the first command to change the first computing system is based on a logistic regression model.
16 . The non-transitory computer-readable medium of claim 13 , wherein the instructions, when executed by the one or more processors, cause receiving the plurality of keystroke logs by performing actions comprising:
receiving, from a second database, binary large object (BLOB) data recorded during one or more secure socket shell (SSH) sessions; and
extracting, from the BLOB data, the plurality of keystroke logs.
17 . The non-transitory computer-readable medium of claim 13 , wherein the instructions, when executed by the one or more processors, further cause performance of actions comprising:
replacing, before the providing and based on a mapping between a plurality of keywords and a plurality of file extensions, a portion of the plurality of keystroke logs with one or more of the plurality of keywords.