International Journal of Computer Application ISSN 2250-1797 Available online on https://rspublication.com/ijca/ijca_index.htm Volume 15 Number. 6, 2025 DOI: 10.5281/zenodo.17674324 Original Article ©2025 RS Publication, rspublicati[email protected] 71 ADVANCED KEYLOGGER FOR SYSTEM MONITORING A Modular, Ethical Framework for Cybersecurity Education and Behavioral Analysis Ms. N. Sri Thejas¹, Rakshanaa B², Megala S³, Vasanthan Y⁴, Vaishnavan S⁵ Department of Computer Science and Engineering (Cybersecurity) Sri Shakthi Institute of Engineering and Technology Coimbatore, Tamil Nadu, India Email:
[email protected] [email protected] [email protected] [email protected] [email protected] International Journal of Computer Application https://rspublication.com/ijca/ijca_index.htm ISSN 2250-1797 ARTICLE INFO ABSTRACT ©2025 RS Publication Paper ID: IJCA691849787EE75 Received: 2025-10-22 Published: 2025-11-21 DOI: https://dx.doi.org/ 10.5281/zenodo.1767 4324 Page No: 71-79 This study introduces a controlled and ethically governed investigation into an Advanced Keylogger and Secure Monitoring Framework developed for use in isolated cybersecurity laboratory environments. The project centers on a modular Pythonbased architecture that employs libraries such as pynput, pyautogui, and AES encryption to record keystroke data, secure it through cryptographic methods, and present activity metrics using a tkinter-driven graphical interface. The system is designed to act as a research-oriented monitoring tool that addresses the transparency and security shortcomings of conventional keyloggers. Emphasis is placed on ethical compliance, data protection, and the educational value of the platform. The framework enables cybersecurity students and analysts to safely examine key logging behavior, evaluate detection strategies, and strengthen defensive programming capabilities within a sandboxed environment. Comprehensive documentation of the system’s structure, implementation process, and controlled experimental evaluation is provided to demonstrate its utility as a bridge between conceptual cybersecurity instruction and practical threat emulation. Keywords Advanced Keylogger, Modular architecture, AES encryption, CBC mode, pynput, pyautogui, sandboxed environment, secure monitoring, cybersecurity education. Cite This Paper: Ms Sri Thejas N Rakshanaa B, Megala S, Vasanthan Y and Vaishnavan S (2025). " ADVANCED KEYLOGGER FOR SYSTEM MONITORING". INTERNATIONAL JOURNAL OF COMPUTER APPLICATION (IJCA), vol. 15, no. 6, 2025, pp. 71-79. DOI: https://dx.doi.org/10.5281/zenodo.17674324
International Journal of Computer Application ISSN 2250-1797 Available online on https://rspublication.com/ijca/ijca_index.htm Volume 15 Number. 6, 2025 DOI: 10.5281/zenodo.17674324 Original Article ©2025 RS Publication, rspublicati[email protected] 72 I . INTRODUCTION: Key logging technologies are frequently associated with unethical activities such as digital surveillance and unauthorized data collection. Nonetheless, when implemented under strict ethical protocols and monitored laboratory conditions, these same mechanisms can serve as powerful instruments for advancing cybersecurity education, system evaluation, and digital forensics. The present research repositions key logging from its traditional role as a malicious tool to a regulated, transparent, and secure platform designed for controlled experimentation and academic investigation. A. Motivation and Problem Statement Traditional keyloggers are primarily engineered for stealth operations, often omitting essential elements such as data security, transparency, and configurability. Many of these tools store information in unprotected text files, leaving sensitive logs open to unauthorized access and exploitation. Their lack of modularity also restricts their usefulness for research and analysis. These shortcomings pose major challenges in academic or laboratory contexts, where preserving data integrity, ensuring confidentiality, and tailoring monitoring parameters are critical requirements. The proposed Advanced Keylogger and Secure Monitoring Framework is designed to mitigate these weaknesses through several key innovations: Encrypted data capture: All input data is immediately secured using Advanced Encryption Standard (AES) algorithms to prevent exposure or tampering. Flexible modular design: Researchers can enable or disable specific components— such as keystroke logging, screenshot collection, or process monitoring—depending on the experimental goals. Administrator-controlled dashboard: A secure management interface provides centralized oversight for log access, monitoring, and configuration. Figure 1: Work Flow of Web Application
International Journal of Computer Application ISSN 2250-1797 Available online on https://rspublication.com/ijca/ijca_index.htm Volume 15 Number. 6, 2025 DOI: 10.5281/zenodo.17674324 Original Article ©2025 RS Publication, rspublicati[email protected] 73 II. LITERATURE REVIEW The development of this system is grounded in a review of existing work in system monitoring, malware analysis, and cryptographic security A. The Evolution of Keylogging Early generations of keyloggers operated through relatively simple polling or APIhooking methods to capture user input. In contrast, contemporary implementations— such as those discussed by Bhuvanesh J. (2024)—exhibit far greater sophistication and stealth. Continued research into these mechanisms is essential, since comprehending the structure and behavior of covert monitoring tools forms the foundation for developing effective defensive technologies. Modern keyloggers typically employ multiple interception strategies, including: Hardware-level interception: Physical devices installed between the keyboard and the host computer to record keystrokes directly. Software-level interception: Techniques such as system API hooking, kernelmode drivers, or event-based listeners—approaches that form the primary focus of this research. B. Security and Data Integrity in Monitoring A notable shortcoming in most conventional keylogger implementations is the absence of internal mechanisms to protect the confidentiality of captured data. The proposed framework resolves this issue by incorporating the Advanced Encryption Standard (AES) as an integral component of its architecture. AES, recognized as the benchmark for both governmental and commercial encryption, guarantees that any extracted log data remains computationally unreadable without possession of the authorized decryption key. This design choice reflects adherence to current ethical and technical standards emphasized in Ethical Hacking and Cybersecurity Research Guidelines (2025), ensuring that data handling within the system aligns with modern cybersecurity best practices. III. METHODOLOGY AND SYSTEM ARCHITECTURE The system’s architecture follows a modular and transparent design philosophy, structured as an independent framework that operates strictly within a sandboxed and isolated network environment to ensure safe experimentation and controlled evaluation. The entire implementation is developed in Python, chosen for its flexibility, rapid development cycle, and the broad range of open-source libraries that support efficient integration of monitoring, encryption, and visualization functionalities.
International Journal of Computer Application ISSN 2250-1797 Available online on https://rspublication.com/ijca/ijca_index.htm Volume 15 Number. 6, 2025 DOI: 10.5281/zenodo.17674324 Original Article ©2025 RS Publication, rspublicati[email protected] 74 A. Core Modules Implementation 1) Keylogger Module (keylogger.py) Core library: Uses pynput to obtain cross-platform access to input devices. A nonblocking Listener instance captures keystroke events without interfering with normal system operation. Data handling: Raw keystroke events — including modifier and special keys (e.g., Shift, Enter) — are forwarded directly to an in-memory encryption queue rather than written to disk in clear text. To balance granularity and performance, the module employs a thresholded logging policy: captured data is packaged and forwarded for encryption only after a configurable number of events or a configurable time interval elapses. 2) Encryption Module (encrypt.py) Algorithm: Applies the Advanced Encryption Standard (AES) in Cipher Block Chaining (CBC) mode to protect all captured artifacts. CBC is used here to avoid weaknesses associated with simpler block modes. Implementation details (design level): Each encryption operation uses a securely generated initialization vector (IV) and a project-managed private key that is never embedded as plaintext in publicly distributed code. Raw data is padded according to a deterministic padding scheme, encrypted, and persisted as binary ciphertext. This design ensures that no unencrypted log material is ever committed to disk within the sandbox. 3) Surveillance Module (screenshot.py) Functionality: Periodically captures desktop images to create visual context for keystroke data, enabling behavioral and situational analysis by correlating input events with on-screen activity. Design choices: Screen captures are compressed and then encrypted with the same AES/CBC pipeline before storage. Capture frequency and compression settings are configurable via the administration interface, so researchers can tune temporal resolution and storage overhead for each experiment. 4) Dashboard and Control Module (dashboard.py) GUI Development: The dashboard is built with a Flask-based web interface, making it easy to open in any browser. This keeps the system simple to use, quick to deploy, and accessible from different devices—without needing any heavy desktop applications. Core functionality: Serving as the centralized command and visualization hub, the dashboard grants authorized researchers complete control over the system’s operation. Key features included.
International Journal of Computer Application ISSN 2250-1797 Available online on https://rspublication.com/ijca/ijca_index.htm Volume 15 Number. 6, 2025 DOI: 10.5281/zenodo.17674324 Original Article ©2025 RS Publication, rspublicati[email protected] 75 Service management: Initiating or terminating all monitoring components (key logging, encryption, and screenshot capture) from a unified control panel. Parameter configuration: Adjusting core variables such as screenshot capture frequency, keystroke logging thresholds, and encryption settings in real time. Log visualization: Providing summary metrics and status indicators to monitor data flow, encryption progress, and system health without exposing any sensitive content 5) Synchronization Module (sync.py) Purpose: The synchronization module reproduces the exfiltration stage of an attack within a fully controlled environment. Its intent is educational and forensic: to close the loop on the simulated threat lifecycle, so researchers can practice secure transfer, chain-of-custody handling, and offline analysis without exposing live networks to risk. Mechanism (design): Bundling: Encrypted log artifacts (ciphertext files and encrypted screenshots) are batched according to configurable policies (e.g., size, time window, or manual trigger). Simulated transfer: Rather than transmitting data to an uncontrolled external endpoint, the module emulates cloud upload behavior by securely moving bundles to a designated, air-gapped forensic analysis server or isolated storage within the lab network. Transfer operations use authenticated channels (e.g., mutually authenticated TLS or equivalent local secure transport) appropriate for the laboratory environment. Integrity & provenance: Each bundle is accompanied by metadata (timestamp, originating module, bundle identifier) and an integrity checksum or HMAC to preserve provenance and to detect tampering during transit and storage. Audit & rollback: Transfer status and any errors are logged (as ciphertext or metadata only) and surfaced to the administrator dashboard. Instructors can replay or roll back transfers to reproduce scenarios for teaching or validation. Safety considerations: All synchronization activity is restricted to preapproved, isolated infrastructure; no external internet endpoints are contacted. The module enforces strict access control for the forensic store and logs all synchronization actions for audit purposes, ensuring the simulation remains ethically and operationally safe. IV. RESULTS AND PERFORMANCE EVALUATION The prototype was successfully deployed and tested within a dedicated virtual machine (VM) operating in a sandboxed network environment. While the primary evaluation was conducted on a Linux-based system, the framework is designed to remain cross-platform and can be adapted for use on other operating systems with minimal modification. The system demonstrated consistent and reliable end-to-end performance across all modules:
International Journal of Computer Application ISSN 2250-1797 Available online on https://rspublication.com/ijca/ijca_index.htm Volume 15 Number. 6, 2025 DOI: 10.5281/zenodo.17674324 Original Article ©2025 RS Publication, rspublicati[email protected] 76 Keystroke Capture: Accurate detection and recording of standard, numeric, and special key combinations were verified through multiple test sessions. Encryption Integrity: Inspection of the generated log files confirmed that all recorded data appeared as unreadable binary content, verifying that AES encryption was successfully applied. Controlled decryption through the dashboard module restored the original text without loss, validating both encryption and key management functionality. Usability: The Flask-based API and web dashboard made the system easy to use, giving researchers a simple browser interface to start or stop monitoring, tweak settings, and watch encrypted data flow in real time—without needing any local software. A. Resource Consumption Analysis Evaluating the system’s resource footprint is essential to ensure that monitoring operations do not interfere with host performance. To assess this, CPU and memory utilization were measured during sustained key logging activity, simulating continuous typing over a 60-minute observation period. Throughout the test, system load remained within acceptable limits, indicating that the framework operates efficiently even during prolonged execution. Temporary spikes were observed during simultaneous screenshot capture and AES encryption processes; however, these increases were brief and quickly stabilized. The overall results confirm that the system maintains consistent nonintrusive site. Figure 2: Capture of Keystrokes after execution Module State CPU Usage (%) Memory Footprint (MB) Idle (Listener Active) 0.5% - 1.2% 15–20 Sustained Typing 1.5% - 2.5% 20–30 Screenshot + Encryption 3.0% - 5.5% (Peak) 35 – 50 (Peak)
International Journal of Computer Application ISSN 2250-1797 Available online on https://rspublication.com/ijca/ijca_index.htm Volume 15 Number. 6, 2025 DOI: 10.5281/zenodo.17674324 Original Article ©2025 RS Publication, rspublicati[email protected] 77 Figure 3: Command execution captured during system testing. V. DISCUSSION: ETHICAL IMPLEMENTATION AND CONTRIBUTION This project’s contribution is twofold: *technical innovation* through a modular architecture and *ethical leadership* in cybersecurity research. A. Fostering Ethical Cybersecurity Research The system was developed in direct response to the growing need for ethically governed tools in malware analysis and cybersecurity training. By enforcing operation within a sandboxed and isolated environment, maintaining complete transparency through the administrative dashboard, and embedding strong encryption mechanisms for all captured data, the project redefines the study of key logging technologies. Its emphasis moves away from the creation of covert surveillance tools toward the secure, transparent, and responsible exploration of their functionality for defensive and educational purposes. The framework provides students and researchers with an applied learning platform that supports the following objectives: 1. Deconstruct Attack Logic: Participants can examine the internal structure of the code, study the use of pynput hooks, and observe how keystroke interception functions at the process and event-handling levels. 2. Develop IDS Countermeasures: The system serves as a safe, interactive target for designing and evaluating Intrusion Detection System (IDS) algorithms. For instance, researchers can detect atypical I/O operations generated by the listener module or identify predictable CPU spikes associated with pyautogui activity. 3. Practice Secure Programming: The integration of AES encryption provides an
International Journal of Computer Application ISSN 2250-1797 Available online on https://rspublication.com/ijca/ijca_index.htm Volume 15 Number. 6, 2025 DOI: 10.5281/zenodo.17674324 Original Article ©2025 RS Publication, rspublicati[email protected] 78 essential, real-world example of how data confidentiality must be maintained—even within experimental or contained environments—thereby reinforcing best practices in secure software development. B. Advantages of Modular Architecture The system’s modular architecture—dividing functionality into discrete components such as keylogger, encryption, screenshot capture, and dashboard— offers several important advantages for research and development. This separation of concerns greatly improves maintainability and facilitates targeted testing, as each module can be evaluated or modified independently without disrupting the operation of the overall framework. Such design flexibility is particularly valuable in an academic or experimental context, where researchers frequently extend or refine system capabilities. New modules, such as a webcam capture interface or a network traffic sniffer, can be integrated seamlessly into the framework. Similarly, core algorithms and standards can be upgraded as technology evolves—for instance, transitioning from AES-CBC to a more advanced encryption mode like AES-GCM—without requiring major architectural changes. VI. CONCLUSION AND FUTURE WORK The Advanced Keylogger and Secure Monitoring System successfully bridges the divide between theoretical cybersecurity principles and their ethical, real-world application in digital surveillance research. It delivers a secure, stable, and resource-efficient framework for educational use, fostering awareness of potential misuse while supporting the development of sophisticated defensive strategies through safe, simulated environments. The modular, Pythonbased design makes the platform, an adaptable and valuable resource for any cybersecurity research laboratory. 1. Future work will advance the system in three principal directions: 2. AI-Driven Anomaly Detection: Integration of machine learning models to analyze keystroke dynamics—including typing cadence, rhythm, and behavioral signatures— to automatically detect activity patterns that deviate from established baselines. 3. Expanded Event Logging: Extension of monitoring capabilities to include network packet capture and system-level event tracking (e.g., file access, process creation) for a more comprehensive view of host activity beyond keystrokes and screenshots. 4. Web Dashboard: Secure Flask interface for easy browser access. REFERENCE 1. Bhat, P., Namratha, H. J., & Mohana. (2023). Cyber security testbed: Keyloggers and data visualization on keyloggers – A case study. International Conference on Sustainable Communication Networks and Application (ICSCNA). 2. Bejo, S. P., Kumar, B., Banerjee, P., Jha, P., Singh, A. N., & Dehury, M. K. (2023). Design, analysis and implementation of an advanced keylogger to defend cyber threats. 2023 8th International Conference on Advanced Computing and Communication Systems (ICACCS).
International Journal of Computer Application ISSN 2250-1797 Available online on https://rspublication.com/ijca/ijca_index.htm Volume 15 Number. 6, 2025 DOI: 10.5281/zenodo.17674324 Original Article ©2025 RS Publication, rspublicati[email protected] 79 3. Bhuvanesh, J. (2024). Enhancing system monitoring capabilities through the implementation of stealthy software–based keylogger: A technical exploration. International Journal of Emerging Technologies and Innovative Research (JETIR). https://www.jetir.org 4. Srikanth Reddy, S., Praveen, C., Marla, N., & Burchu, L. (2025). Keylogger and screenlogger tools for robust cybersecurity and ethical user activity monitoring. 5. Kataria, D., Shah, M. K., Bharath Raj, S., & Priya, G. (2020). Real-time working of keylogger malware analysis. International Journal of Engineering Research & Technology (IJERT). http://www.ijert.org 6. Malla, A., Manjeera, J. G., & Pravallika, M. V. L. (2023). Preventing malicious use of keyloggers using anti-keyloggers. arXiv:2312.10445. 7. Zolkipli. (2023). Keylogger: The unsung hacking weapon. Borneo International Journal, c(1), 33– 43. 8. Kapare, R., Gawade, A., Kamble, A., & Tembhurnikar, P. (2024). Enhancing digital security with advanced keylogger project. International Journal of Creative Research Thoughts (IJCRT). http://www.ijcrt.org 9. Iqbal, M., Huzaifa, M. M., Sumbal, U., Butt, A. S., Hussain, M. Z., & Hasan, M. Z. (2025). Unveiling Python-based keylogger malware behavioral analysis, architecture and mitigation strategies. Spectrum of Engineering and Management Science, 3(8). 10. Rai, S., Choubey, V., Suryansh, & Garg, P. (2022). A systematic review of encryption and keylogging for computer system security. Fifth International Conference on Computational Intelligence and Communication Technologies (CCICT). 11. Yadav, S., Mahajan, A., Prasad, M., & Kumar, A. (2020). Advanced keylogger for ethical hacking. International Journal of Engineering Applied Sciences and Technology (IJEAST). 12. Samsoni, D. Z., Basir, Pamungkas, B. A., Prayogi, H. E., Muhammad, R., Wahyudi, S., & Samudra, W. (2023). Detecting phishing, keystroke and keylogger attacks on computing resources. International Journal of Integrative Sciences (IJIS). https://journal.formosapublisher.org/index.php/ijis 13. Wyciślik, Ł., et al. (2024). Improved biometric identification using keystroke analysis. Sensors. 14. Chinchalkar, S. P., & Somkunwar, R. K. (2024). Keylogger detection system using machine learning algorithms. IIETA Research in Applied Computing. 15. Shadman, R., et al. (2023). Keystroke dynamics: Concepts, techniques, and applications – A review. Sensors.