Anti-key logger apparatus, system, and method
An apparatus, system, and method are disclosed for protecting against key logger malware. The protection includes protection form grabbing keylogger malware. In response to detecting a form submission event from a browser associated with a user entering data into a form, confidential data is prevented from being captured by malware. The protection against malware may be provided as a preventive measure that does not require detection of the key logger malware itself.
1. A method for preventing software key logging executable by a microprocessor, comprising:
invoking an anti-key logger by an individual web page or website of a financial institution accessed by a user in an online access session;
installing and maintaining the anti-key logger at a most privileged access level for browser events;
detecting, by the anti-key logger, a browser form submission initiation call event associated with data inputs entered by a user, wherein the data inputs include confidential data;
submitting the data inputs to a designated entity; and
preventing, by the anti-key logger, malware from capturing the confidential data.
2. The method of claim 1 , wherein the anti-key logger does not require detection of the malware to prevent the malware from capturing the confidential data.
3. The method of claim 1 , further comprising detecting presence of the malware.
4. The method of claim 3 , further comprising removing the detected malware.
5. The method of claim 3 , further comprising generating an alert of a malware risk.
6. The method of claim 5 , wherein a graphical alert is generated when a browser is directed to a website determined to pose a malware risk.
7. The method of claim 1 , wherein a browser form submission initiation call event is an OnSubmit call event.
8. The method of claim 1 , wherein the microprocessor is disposed within a computer, a mobile communication device, a smartphone, or a mobile Internet device.
9. The method of claim 8 , wherein the mobile Internet device is one of a personal digital assistant (PDA), a handheld computer, a tablet computer, a laptop computer, or a notebook computer.
10. The method of claim 1 , wherein the anti-key logger is installed in response to an initiation of the online access session, and uninstalled in response to cessation of the online access session.
11. A method for preventing software key logging executable by a microprocessor, comprising:
dynamically installing an anti-key logger by a master server and maintaining the anti-key logger at a most privileged access level for browser events;
detecting, by the anti-key logger, a browser form submission initiation call event associated with data inputs entered by a user, wherein the data inputs include confidential data;
submitting the data inputs to a designated entity;
preventing, by the anti-key logger, malware from capturing the confidential data; and
tracking, by the master server, the anti-key logger installation.
12. A method for preventing software key logging executable by a microprocessor, comprising:
invoking an anti-key logger in response to an initiation of an online access session;
installing and maintaining the anti-key logger at a most privileged access level for browser events:
detecting, by the anti-key logger, a browser form submission initiation call event associated with data inputs entered by a user, wherein the data inputs include confidential data;
submitting the data inputs to a designated entity;
preventing, by the anti-key logger, malware from capturing the confidential data;
and uninstalling the anti-key logger in response to a logoff of the online access session.
13. The method of claim 12 , wherein the anti-key logger does not require detection of the malware to prevent the malware from capturing the confidential data.
14. The method of claim 12 , wherein the microprocessor is disposed within a computer, a mobile communication device, a smartphone, or a mobile Internet device.
15. The method of claim 14 , wherein the mobile Internet device is one of a personal digital assistant (PDA), a handheld computer, a tablet computer, a laptop computer, or a notebook computer.
16. A computer program product to prevent software key logging including computer program code embedded in a non-transitory microprocessor-readable storage medium executable by a microprocessor, which when executed on the microprocessor, implements a method, comprising:
invoking an anti-key logger by an individual web page or website of a financial institution accessed by a user in an online access session;
installing the anti-key logger and maintaining the anti-key logger at a most privileged access level for browser events;
detecting, by the anti-key logger, a browser form submission initiation call event associated with data inputs entered by a user, wherein the data inputs include confidential data;
submitting the data inputs to a designated entity; and
preventing, by the anti-key logger, malware from capturing the confidential data.
17. The computer program product of claim 16 , wherein the anti-key logger does not require detection of the malware to prevent the malware from capturing the confidential data from the data inputs.
18. The computer program product of claim 16 , further comprising detecting presence of malware.
19. The computer program product of claim 18 , further comprising removing the detected malware.
20. The computer program product of claim 18 , further comprising generating an alert of a malware risk.
21. The computer program product of claim 20 , wherein a graphical alert is generated when a browser is directed to a website determined to pose a malware risk.
22. The computer program product of claim 16 , wherein the browser form submission initiation call event is an OnSubmit call event.
23. The computer program product of claim 16 , wherein the microprocessor is disposed within a computer, a mobile communication device, a smartphone, or a mobile Internet device.
24. The computer program product of claim 23 , wherein the mobile Internet device is one of a personal digital assistant (PDA), a handheld computer, a tablet computer, a laptop computer, or a notebook computer.
25. The computer program product of claim 16 , wherein the anti-key logger is installed in response to an initiation of the online access session, and uninstalled in response to cessation of the online access session.
26. A computer program product to prevent software key logging including computer program code embedded in a non-transitory microprocessor-readable storage medium executable by a microprocessor, which when executed on the microprocessor, implements a method, comprising:
dynamically installing an anti-key logger by a master server and maintaining the anti-key logger at a most privileged access level for browser events;
detecting, by the anti-key logger, a browser form submission initiation call event associated with data inputs entered by a user, wherein the data inputs include confidential data;
submitting the data inputs to a designated entity; and
preventing, by the anti-key logger, malware from capturing the confidential data; and
tracking, by the master server, the anti-key logger installation.
27. A computer program product to prevent software key logging including computer program code embedded in a non-transitory microprocessor-readable storage medium executable by a microprocessor, which when executed on the microprocessor, implements a method, comprising:
invoking an anti-key logger in response to an initiation of an online access session;
installing and maintaining the anti-key logger at a most privileged access level for browser events:
detecting, by the anti-key logger, a browser form submission initiation call event associated with data inputs entered by a user;
submitting the data inputs to a designated entity;
preventing, by the anti-key logger, malware from capturing the confidential data;
and uninstalling the anti-key logger in response to a logoff of the online access session.
28. The computer program product of claim 27 , wherein the anti-key logger does not require detection of the malware to prevent the malware from capturing the confidential data.
29. The computer program product of claim 27 , wherein the microprocessor is disposed within a computer, a mobile communication device, a smartphone, or a mobile Internet device.
30. The computer program product of claim 29 , wherein the mobile Internet device is one of a personal digital assistant (PDA), a handheld computer, a tablet computer, a laptop computer, or a notebook computer.