A simple activity monitor with /dev/random

Today I was performing some tests in the random number generators of some browsers and found, by chance, this mail sent to Bugtraq by Michal Zalewsky called “Unix entropy source can be used for keystroke timing attacks”. While the idea of Michal is very good, I failed to find a reliable way of doing it in my house computer after some time (well, honestly, after just 1 hour…). However, a more simpler idea come to my mind: if /dev/random blocks when the entropy pool is empty and most of the events are generated when mouse or keyboard events happens, at least, I can write quite easily an activity monitor based on /dev/random.

A simple activity monitor

The idea is very simple: read all available data in /dev/random and then, depending on the intervals new data is available, try to determine if the mouse or keyboard is being used. For this I created the following simple Python script:

  2. import time
  3. import select
  8. def wait_for_activity():
  9.   """ Returns (0, time) for mouse and (1, time) for keyboard activity.
  10.      Note, however, that the metrics are just a guess. """
  11.   started = True
  13.   f = open("/dev/random", "rb")
  14.   f.seek(2, 0)
  16.   keyboard = 0
  17.   mouse = 0
  18.   ret = None
  20.   while ret is None:
  21.     t = time.time()
  23.     select.select([f], [], [])        
  24.     f.read(8)
  26.     t = time.time()-t
  27.     if started:
  28.        started = False
  29.        continue
  31.     if t <= 1:
  32.       if mouse >= 1:
  33.           ret = (0, t)
  34.       else:
  35.         mouse += 1
  36.         keyboard -= 1
  37.     elif t <= 5:
  38.       if keyboard >= 1:
  39.           ret = (1, t)
  40.       else:
  41.         keyboard += 1
  42.         mouse -= 1
  43.     else:
  44.       keyboard = mouse = 0
  46.   f.close()
  47.   return ret
  49. def main():
  50.   while 1:
  51.     act = wait_for_activity()
  52.     if act[0] == ACTIVITY_MOUSE:
  53.       print "MOUSE ACTIVITY DETECTED", act[1]
  54.     else:
  55.       print "KEYBOARD ACTIVITY DETECTED", act[1]
  57. if __name__ == "__main__":
  58.   main()

Execute this script and see if it works for you. In my case, for reading 8 bytes it typically takes 1 second or less when mouse events happens (normal stuff: browsing, reading mail, etc…) and 5 seconds or less for keystrokes. Some of the problems I noticed are, for example, that often the script thinks that when I’m writing mouse events are happening, when they are not (I think I type too fast for my script). In any case, more or less (in my home computer, at least) it’s working.

For next posts, hopefully, I’ll be able to write a working program for the (old) idea of Michal Zalewsky but, meanwhile, this is what I have working. I hope you find it interesting or useful. Bye!


4 thoughts on “A simple activity monitor with /dev/random

  1. René Romero

    I guess in my case it’s just randomly claiming mouse / keyboard activity, but interesting though.

  2. joxean Post author

    The problem is that the metrics I used were took in my computer and very probably you need to adjust to your computer. Try changing the 1 second/5 seconds limit to see what happens. The “if t <= 1″ and “elif t <= 5″.

Leave a Reply

Your email address will not be published. Required fields are marked *

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <s> <strike> <strong>