Share

Related Stories

  • A Rotting Security Apple?
    Vendors, analysts, and commentators alike have long predicted a surge in malware affecting Apple’s products. Yet, until recently, these prognostications have failed to materialize. Drew Amorosi examines recent malware threats to Apple’s OS X operating system to find out if this is an anomaly, or a sign of things to come
  • New financial trojan - Sunspot - arrives with Zeus/SpyEye capabilities
    A new financial trojan called Sunspot has been spotted in the wild and, claims Trusteer, its research into the malware suggests it is pitched into the same cybercrime arena as Zeus and SpyEye.
  • ZeuS now targeting enterprise access gateways
    After plundering users' online bank accounts using stolen credentials, it seems that the continually evolving ZeuS malware is now targetting company data assets via their enterprise access gateways.
  • RSA: Check Point unveils secure USB drive technology
    Check Point Software Technologies has taken the wraps off a secure USB drive system. Known as Abra, the unit is designed to offer PC or Windows-based terminal users a secure virtualised workspace that is highly portable between machines.
  • The Rise and Fall of Online Credit Fraud
    While Chip and Pin technology has certainly decreased in-store fraud, it has also re-directed criminals’ attention to online banks and shoppers. Stephen Pritchard investigates what methods cybercriminals are using to steal credit card data, and reports on how the finance sector is fighting back

Top 5 Stories

News

German Firm Develops World's First "Trojan-proof" Password System

17 September 2008

Global IP Communications claims to have developed the world's first Trojan-proof password dialog system for Windows PCs.

Developed in conjunction with PMC Ciphers and CyProtect, respectively,
encryption and Internet security specialists, the as-yet unnamed
system works by using a triple-interlacing display technology that
"flashes" a virtual keyboard onto the PC screen at very high speeds.

Because the screen display writing speed is effectively intermittent -
by is treated as persistent by the human eye - any attempts to screen-
scrape or similarly grab a copy of the screen by Trojan Horse malware
will, it is claimed, only produce the basic "skin" of the virtual
keyboard, without the all-important overlay keypad.

According to CB Roellgen, chief technology officer of PMC Ciphers and
the originator of the Turbocrypt disk encryption system - on which the
Trojan-proof dialog software is based - the technology has been tested
on a Windows PC infected with several Trojans but, thanks to the
virtual display system, which is driven by an encrypted section of the
PC's hard disk, screen grabs are impossible.

PMC Ciphers says that most Trojans use under one per cent of a PC's
processing power in order to stay "under the radar" of even the most
innovative IT security software.

Even on one of the most powerful dual-core Intel-driven PCs available
on the market at the moment, the firm says that a Trojan would have to
use around 15 per cent of the powerful PC's processing power to even
begin to be capable of scraping the virtual display screen, assuming
that the hackers had the necessary source code of the program.

As each character is entered on the virtual on-screen keyboard, the
screen interlacing environment - which draws on three sets of discrete
encryption and display programs - changes to a new "keyboard."

This means that, even if hackers were able to deduce the program code
generating the virual keyboard at one particular point in time, as
each password character is entered, the program code will have rotated
to a new ensemble.

All three firms are sufficiently confident in their technology to
offer a free beta test version of the software for Windows XP, Vista
32 and Vista 64-bit systems:

http://downloads.turbocrypt.com

http://www.cyprotect.com
This article is featured in:
Identity and Access Management  • Internet and Network Security

 

Comment on this article

You must be registered and logged in to leave a comment about this article.