Skip to main content

Malboard: Hackers can now pose as victims through their keyboards

Alexa, are keyboards going extinct? Wishful thinking, maybe, but according to a recent survey there's broad support for voice technology over tactile interfaces.

A new form of cyberattack has been developed by researchers which is able to mimic a user's identity through their keystrokes.

The continual evolution of cyberattacks and their increasing sophistication has led to a situation where signature-based antivirus products are no longer enough.

Security

A multi-layered approach to personal security -- including two-factor authentication (2FA) -- is slowly becoming commonplace in order to reduce our reliance on passwords alone.

The idea of verifying our identity through behavioral patterns, such as through keystrokes or mouse movements, is also being explored, but as Ben-Gurion University of the Negev (BGU) Malware Lab researchers have revealed, no single security solution is foolproof.

On Wednesday, the team said they have developed a new form of attack, dubbed Malboard, which is able to evade detection products "that are intended to continuously verify the user's identity based on personalized keystroke characteristics."

See also: CCTV cameras enslaved to infiltrate air-gap networks

It is not just the speed of keystrokes which can be used to verify a user -- how we respond to typographical errors and whether or not we tend to mistype particular characters are behavioral elements which can be used to verify our identity, too.  

In a paper published in the academic journal Computer and Security, available online, BGU showed how a compromised keyboard can be used to generate and send malicious keystrokes which mimic its victim.

The team used keyboards developed by Microsoft, Lenovo, and Dell in their research. The aim was to fool KeyTrac, TypingDNA and DuckHunt, which are all risk-based behavioral authentication systems.

These forms of software use AI-based algorithms and machine learning to analyze our keystrokes in order to add another layer of verification to user accounts. However, these same algorithms can also be used to fool them.

In order to develop Malboard, the team used behavioral data generated from 30 participants performing three different keystroke tests. This information was fed into the attack's underlying AI database and algorithms created by the system were pitted against the detection software.

A keyboard infected with Malboard was able to automatically generate keystrokes in the style of the participants by injecting keystroke movements "as malicious software." In 83 to 100 percent of the tests, KeyTrac, TypingDNA, and DuckHunt were fooled.

TechRepublic: 6 questions to consider before implementing a disaster recovery plan

According to Dr. Nir Nissim, head of the David and Janet Polak Family Malware Lab at Cyber@BGU, Malboard would be particularly effective in two scenarios; remote attacks launched by hackers wirelessly, or by inside attackers -- such as disgruntled employees -- who would be able to physically launch Malboard on a keyboard to compromise an internal system.

The paper also proposes detection modules which could be used to improve keyboard-based verification, including power consumption monitoring, keystroke sounds, and typographical error detection.

CNET: Scam artists reportedly stole $19 million worth of iPhones

"Each of the proposed detection modules is capable of detecting the Malboard attack in 100 percent of the cases, with no false positives," Nissim added. "Using them together as an ensemble detection framework will ensure that an organization is immune to the Malboard attack as well as other keystroke attacks."

The best beach reads for hackers in 2019 SEE FULL GALLERY 1 - 5 of 8

Previous and related coverage


Have a tip? Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0


156 Comments

I in addition to my pals happened to be following the nice items on your website and quickly got an awful suspicion I had not thanked the website owner for those techniques. These guys were absolutely very interested to see all of them and have in effect truly been using them. We appreciate you truly being well considerate and also for making a decision on some fine ideas most people are really needing to discover. My very own honest apologies for not expressing gratitude to you earlier. hermes http://www.hermesonlineshop.com

I happen to be commenting to let you understand what a nice discovery our girl gained visiting your web site. She picked up a lot of issues, with the inclusion of how it is like to have an ideal coaching character to have other individuals without difficulty know chosen tricky issues. You undoubtedly surpassed our own expected results. Many thanks for delivering such valuable, dependable, informative as well as fun thoughts on that topic to Tanya. kobe shoes http://www.kobe-shoes.us.com

Thanks for your entire labor on this blog. My aunt loves conducting internet research and it's really simple to grasp why. Many of us hear all regarding the dynamic method you give both interesting and useful guidelines by means of the blog and even recommend response from other people on this content while our favorite princess is certainly learning so much. Have fun with the remaining portion of the new year. You are always carrying out a remarkable job. hermes http://www.hermes-handbags.us.com

I am also writing to make you understand of the nice encounter my wife's daughter found checking your blog. She learned such a lot of things, which include how it is like to possess an incredible giving heart to have men and women clearly learn selected grueling topics. You truly did more than her expectations. I appreciate you for distributing the beneficial, safe, educational and as well as cool guidance on the topic to Kate. birkin bag http://www.hermesbirkins.com

My spouse and i felt very delighted Raymond could deal with his inquiry while using the ideas he came across while using the weblog. It is now and again perplexing to simply choose to be making a gift of information which many people have been selling. So we do know we have got the writer to thank because of that. The most important explanations you've made, the simple web site menu, the friendships your site make it easier to foster - it's mostly spectacular, and it's really leading our son and the family do think the concept is satisfying, and that is exceedingly serious. Many thanks for all! kobe basketball shoes http://www.kobebasketballshoes.net

I just wanted to send a simple note to thank you for some of the fantastic concepts you are showing at this website. My time consuming internet look up has finally been recognized with reasonable information to share with my visitors. I would point out that many of us website visitors are very much fortunate to exist in a wonderful site with very many perfect people with very beneficial secrets. I feel very privileged to have come across your site and look forward to plenty of more brilliant moments reading here. Thanks a lot again for all the details. lebron shoes http://www.lebronjames.us.com

I must show my respect for your generosity giving support to those people who should have assistance with this question. Your real dedication to getting the solution throughout was wonderfully invaluable and has surely made many people like me to arrive at their desired goals. This informative report entails so much a person like me and much more to my office workers. Many thanks; from everyone of us. yeezy http://www.yeezy-supply.us.org

I not to mention my pals were looking through the good tactics from your web page and all of the sudden I got a terrible feeling I had not thanked the website owner for those tips. Most of the men had been consequently passionate to read them and have very much been taking advantage of those things. Thanks for getting very accommodating and then for picking out such ideal topics most people are really needing to be informed on. Our honest apologies for not expressing gratitude to you earlier. moncler http://www.monclersoutletstore.com

I just wanted to construct a quick message to appreciate you for these wonderful solutions you are sharing here. My time-consuming internet look up has now been recognized with useful concept to go over with my companions. I would declare that we readers are very much fortunate to dwell in a superb site with very many awesome people with valuable tricks. I feel very happy to have seen your webpage and look forward to tons of more brilliant minutes reading here. Thank you again for a lot of things. yeezy boost 350 http://www.yeezy350s.com

https://ko-fi.com/tiktokfansfree https://www.funadvice.com/1631714592_6118572 #Card# AMONG US Hack 2022| AMONG US Cheats Free Skins Unlocked Working Script Iphone Android Mod Tongtonglihai Version. You Are Welcome To Our New AMONG US Hack Tool We Called It Free AMONG US Skins | Hat | Pets Generator. This Is The Easiest Way To Get Free Hack, Skins | Hat | Pets And Likers On The AMONG US Network. Get Our Complimentary Free Skins | Hat | Pets With The First-Rate AMONG US Hack Skins | Hat | Pets Generator. If You’Re Seeking Complimentary Free Skins | Hat | Pets On My Instagram Internet Site, You’Ve Come To The Appropriate Place. Allow Me Inform You, There Is No Much Better Web Site For The AMONG US Hack Skins | Hat | Pets Generator, Where You Can Right Away Secure Free Skins | Hat | Pets AMONG US Hack - AMONG US Hack iOS, Iphone,Ipad Unlock Everything And Always Be Imposter/Mod Menu. AMONG US Hacks - How To Get Free Pets And Skins In AMONG US With No Ads On iOS / Android. AMONG US Hack PC Many Features, Impostor And More. [New] AMONG US Hack Download | Pc And Mac Os Download AMONG US Mod Men; Working (2022). AMONG US Hack, AMONG US Hacked Apk, AMONG US Hack Script, AMONG US Hack Download, AMONG US Hacked Version, AMONG US Hack Always Imposter, AMONG US AMONG US Hack Script: %Updated% AMONG US Hack Free Skins Unlocked Pets And Hats Remove Ads Mod Apk. This AMONG US Hack Android Will Allow You To Access Unlimited Amounts Of Both Skins And Pets Dead AMONG US Hack Latest Version. AMONG USfreeskins Hats Pets Generator By Click Hack Now Button Input Amount Of Among US Hackxbox One. It Is Simple We Have To Do Is Use Our Online Generator. Use AMONG US Hack Android Is. Use AMONG US Hack App Pay. Fornite Battle Pass For 950 AMONG US Hack Free AMONG US Hackgenerator 2021 Get Free. AMONG US Hackgenerator 2022 Get Free. Ways To Earn AMONG US Hack Free AMONG US AMONG US Hackgenerator 2022. Select The Amount Of AMONG US Hackgenerator 2021 Get Free Skins Hats Pets App. Seeyou Soon Freeskins Hats Petsgenerator 2021.Are You Lookingforfreeskins Hats Petsgeneratortogenerator Unlimited Free Skins Hats Pets In 2022. Latest Working Among Usfreeskins Hats Petsgeneratortogenerator Unlimited Free Skins Hats Pets In AMONG US Hackxbox One. It Is Necesery To Fill Up To 4 Players Fight Against One. A Co-Op Survival Mode Where Players Fight Against One Another To 1500 ROBUX. Injustice Gods AMONG US Hackxbox One Another To Become The Games. Seeyou Soon Freeskins Hats Petshack Xbox One. Seeyou Soon Freeskins Hats Petsforfree. Hackers Black Screen 2022 Hackers On AMONG US 2022 AMONG US Hack Menu iOS 2022 AMONG US HACK 2021 #FREE AMONG US Hack 2022 GENERATOR #AMONG US HACK 2022 / #Among-Us-Hack-Petsgenerator #[[AMONG US 2021]] AMONG US Hack Unlimited #[AMONG US FREE Skins Generator]♔100%-Working Real Codes #Among Us Hack Generator #【FREE AMONG US HACKGENERATOR 2022 】【UNLIMITEDSKINS,PET,HATS [REMOVE ALLADS]!]】 #AMONG US Hack Always Imposter 2022 Working Script #AMONG US FREE SKINS | HATS | PETS GENERATOR 2021(Free-Skins| Hats|Pets-In-AmongUS)✌ #AMONG US Online Generator Free Skins, Pets And Hats #AMONG US Generator, #[AMONG US Hack]- #[ AMONG-US-HACK-2022 ] #✌[AMONG US SKINGENERATOR] Hack ¶

I and also my pals were examining the great information and facts from the website then at once I got a terrible feeling I had not expressed respect to you for them. Most of the men happened to be as a consequence glad to read through all of them and have sincerely been using these things. Thanks for indeed being really helpful as well as for obtaining certain fantastic themes most people are really wanting to be aware of. Our honest regret for not expressing appreciation to you sooner. cheap jordans http://www.cheapjordan.us

Add new comment

Plain text

  • No HTML tags allowed.
  • Lines and paragraphs break automatically.
  • Web page addresses and email addresses turn into links automatically.
The comment language code.