IP Library Patent Application 19542494
Patent Application
App. No. 19/542,494

CYBER SECURITY SYSTEMS AND METHODS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
19/542,494
Abstract

A data stream generated by a user operating a human-computer interface (HCI) is obfuscated, or “scrambled,” for keylogging prevention. Obfuscating the data stream generated by the user comprises, by a web browser, setting a hook for intercepting keypress events. Keypress events comprise user input events into the first HCI or virtual keypress events. Based on capturing a keypress event corresponding to a first keypress code that triggers the hook, the web browser scrambles the first keypress code to generate a second keypress code that differs from the first keypress code. Scrambling the first keypress code comprises changing, salting, or skipping the first keypress code to generate the second keypress code.

Claims (36)

1 . A method comprising:

obfuscating a data stream generated by a user operating a first human-computer interface (HCI), wherein obfuscating the data stream generated by the user comprises, by a web browser,

setting a hook for intercepting keypress events, wherein keypress events comprise user input events into the first HCI or virtual keypress events; and

based on capturing a keypress event corresponding to a first keypress code that triggers the hook, scrambling the first keypress code to generate a second keypress code that differs from the first keypress code, wherein scrambling the first keypress code comprises changing, salting, or skipping the first keypress code to generate the second keypress code.

2 . The method of claim 1 , further comprising determining if the user engaging with sensitive materials of an organization, wherein determining if the user is engaging with sensitive materials of the organization comprises determining if the user is engaging with sensitive materials of the organization based on at least one of a confidentiality level of a material with which the user is engaging and a security clearance level of the user, wherein obfuscating the data stream is based on determining that the user is engaging with sensitive materials of the organization.

3 . The method of claim 2 , wherein determining that the user is engaging with sensitive materials of the organization comprises determining that the security clearance level of the user is greater than an upper threshold or determining that the security clearance level of the user is less than a lower threshold.

4 . The method of claim 2 , wherein determining that the user is engaging with sensitive materials of the organization comprises determining that the confidentiality level of the material exceeds a threshold.

5 . The method of claim 1 , further comprising setting a refresh rate for the hook to maintain priority of the hook.

6 . The method of claim 5 , wherein setting the refresh rate for the hook comprises setting the refresh rate for the hook based on at least one of a confidentiality level of sensitive materials of an organization with which the web browser is associated and a security clearance level of the user.

7 . The method of claim 1 , wherein setting the hook for intercepting keypress events comprises at least one of setting a hook for intercepting keypress scan codes generated by a keyboard and setting a hook for intercepting virtual codes generated by a keyboard driver.

8 . The method of claim 1 , further comprising:

based on scrambling the first keypress code, blocking transmission of the first keypress code to a destination application to which the first keypress code corresponds; and

transmitting the second keypress code to the destination application.

9 . The method of claim 8 , further comprising unscrambling, by the destination application, the second keypress code, wherein unscrambling the second keypress code comprises, by the destination application,

performing a lookup for the second keypress code in a lookup table; and

determining an original keypress code scrambled to generate the second keypress code based on a result of the lookup, wherein the original keypress code is the first keypress code.

10 . The method of claim 1 , further comprising prompting the user to switch from the first HCI to a second HCI at least one of periodically and in response to a stochastic prompt.

11 . One or more non-transitory machine-readable media having program code stored thereon, the program code comprising instructions to:

obfuscate a data stream generated by a user operating a human-computer interface (HCI), wherein obfuscating the data stream generated by the user comprises, by a web browser,

set a hook for intercepting keypress events, wherein keypress events comprise user input events into the HCI or virtual keypress events; and

based on capturing a keypress event corresponding to a first keypress code that triggers the hook, scramble the first keypress code to generate a second keypress code that differs from the first keypress code, wherein the instructions to scramble the first keypress code comprise instructions to change, salt, or skip the first keypress code to generate the second keypress code.

12 . The non-transitory machine-readable media of claim 11 , wherein the program code further comprises instructions to determine whether the user engaging with sensitive materials of an organization, wherein the instructions to determine whether the user is engaging with sensitive materials of an organization comprise instructions to determine whether the user is engaging with sensitive materials of the organization based on at least one of a confidentiality level of a material with which the user is engaging and a security clearance level of the user, wherein the instructions to obfuscate the data stream comprise instructions to obfuscate the data stream based on a determination that the user is engaging with sensitive materials of the organization.

13 . The non-transitory machine-readable media of claim 11 , wherein the program code further comprises instructions to set a refresh rate for the hook to maintain priority of the hook.

14 . The non-transitory machine-readable media of claim 13 , wherein the instructions to set the refresh rate for the hook comprise instructions to set the refresh rate for the hook based on at least one of a confidentiality level of sensitive materials of an organization with which the web browser is associated and a security clearance level of the user.

15 . The non-transitory machine-readable media of claim 11 , wherein the instructions to set the hook for intercepting keypress events comprise at least one of instructions to set a hook for intercepting keypress scan codes generated by a keyboard and instructions to set a hook for intercepting virtual codes generated by a keyboard driver.

16 . The non-transitory machine-readable media of claim 11 , wherein the program code further comprises instructions to:

based on scrambling the first keypress code, block transmission of the first keypress code to a destination application to which the first keypress code corresponds; and

transmit the second keypress code to the destination application.

17 . A system comprising:

a human-computer interface (HCI); and

a device that obfuscates a data stream generated by a user operating the HCI, wherein the device comprises a web browser that,

sets a hook for intercepting keypress events, wherein keypress events comprise user input events into the HCI or virtual keypress events; and

based on capturing a keypress event corresponding to a first keypress code that triggers the hook, scrambles the first keypress code to generate a second keypress code that differs from the first keypress code, wherein the web browser scrambling the first keypress code comprises the web browser changing, salting, or skipping the first keypress code to generate the second keypress code.

18 . The system of claim 17 , wherein the device obfuscating the data stream generated by the user operating the HCI comprises the device obfuscating the data stream generated by the user operating the HCI based on a determination that the user is engaging with sensitive materials of an organization to which the web browser corresponds.

19 . The system of claim 17 , wherein the web browser of the device setting the hook for intercepting keypress events comprises at least one of the web browser of the device setting a hook for intercepting keypress scan codes generated by a keyboard and the web browser setting a hook for intercepting virtual codes generated by a keyboard driver.

20 . The system of claim 17 , wherein the web browser of the device sets a refresh rate for the hook to maintain priority of the hook.

Assignments (2)
NUNC PRO TUNC ASSIGNMENT Recorded Jul 24, 2026
From: BEN-NOON, OFER; BOBROV, OHAD; ADLER, NIR
To: TALON CYBER SECURITY LTD.
Reel/Frame 075391/0840 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 24, 2026
From: TALON CYBER SECURITY LTD.
To: PALO ALTO NETWORKS, INC.
Reel/Frame 075391/0958 →