Home > Ask the Security Experts > Application Security Questions & Answers > Can keyloggers monitor mouse clicks and keyboard entries?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Can keyloggers monitor mouse clicks and keyboard entries?

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 25 February 2007
I'm looking for a software program that can monitor all keyboard entries and mouse clicks throughout the course of a day. My manager then wants a summary report of the activity; he doesn't care what information is entered, but he wants the number of key hits on the keyboard, number of mouse clicks, as well as time statistics. What are the risks of using a keylogger for this purpose? Are there better alternatives?

>
EXPERT RESPONSE
It sounds like your manager is looking to carry out some sort of productivity or behavioral research. I say this because he seems more interested in time statistics than actual inputted content.

The definition of a keylogger is any device or program that captures and records information from an input device. Input devices include keyboards, mice, touch screens and voice commands. So, yes, a keylogger is what you need to use, but most keyloggers only capture keyboard input.

Recording mouse clicks, however, is fairly meaningless unless you know what the user is clicking on. The main legitimate purpose of keyloggers is to monitor user activity. If, for example, an organization suspects an employee of sending confidential information to a third party, they may want to record his or her actions. This type of keylogger can be either a software program or a hardware dongle that sits between the keyboard and the desktop. With keyloggers, the main aim is capture the data input. Therefore the time between inputs is not critical, and time statistics are not recorded. Even a hacker's keyloggers do not record time-related data.

If you can't find a keylogger that captures all the data that you need, you could very easily write your own simple program to do this. If you're not that familiar with coding such a program, you could start by looking at the code for Keymail. Keymail is a keylogger that emails keystrokes to a chosen email address, but this program could easily be adapted to capture and store the information that your boss needs. If you need to capture data from users running different operating systems, then a hardware keylogger is the way to go; these are usually OS independent and do not require any software to be installed. They also have the advantage of not being affected by hardware crashes or system formats.

Whatever route you choose, you should be aware of the personal privacy rules that need to be adhered to. Also, you need to ensure that the logged data does not fall into the wrong hands, captured keystrokes may well include network passwords and other sensitive data. This is why hackers use keyloggers so frequently. They install keyloggers on users' machines in order to gather useful information for further attacks.

More information:

  • Learn more about keylogger basics.
  • See how a JavaScript keylogger helped spread a malicious backdoor Trojan.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Application Security
    What risks do application virtualization products pose to enterprise security?
    Do BlackBerrys and other mobile devices put sensitive data at risk when used overseas?
    How can quality assurance tools aid software development?
    Should UTM and Web security filtering software be used together?
    Is the iPhone amenable to any method of email encryption?
    What are effective ways to stop instant messaging (IM) spam?
    Is it impossible to successfully remove a rootkit?
    Can IBM's SMash technology secure Web applications?
    Why is backscatter spam so difficult to block?
    What are the risks of disabling the User Account Control (UAC) feature on Windows Vista?

    Insider Threats
    Express Scripts offers reward in hacker extortion case
    Societe Generale bolsters internal controls, discovers second insider
    Information security book excerpts and reviews
    I am concerned that a former employee will utilize corporate information in a malicious way.
    Security pros focused on internal threat, training
    Reasearch on Coding Backdoors Presents Ugly Picture
    Deloitte survey finds overconfidence, lack of planning on security
    Data loss prevention from the inside out
    Insider dangers
    Survey finds access control problems at many firms

    Data Privacy
    IRS faulted for lax security controls, dangerous data risks
    Learning the language of global compliance
    PCI is about eliminating data, not securing it, former QSA says
    Google amends log retention rules, privacy advocates respond
    Security of customer data, IP sustains security budgets
    Product Review: Workshare Protect Premium 6.0
    Data breach discovery, disclosure outpaces 2007
    PCI groups to focus on wireless, pre-authorization changes
    PCI DSS 1.2 clarifies wireless, antivirus use
    Architect Security and Compliance Programs to Be Complementary
    Data Privacy Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    insider threat  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts