2.5 Basic Operating Principles of Rootkit Technologies . . . . . . . . . . 165
2.5.1 What Is a Rootkit Technology? . . . . . . . . . . . . . . . . . . . 165
2.5.2 Methods of Intercepting API Functions
in User Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 165
2.5.3 Methods of Interception of Rootkit Functions
in Kernel Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 169
2.5.4 Main Methods of Rootkit Detection in the System . . . . . 170
2.5.5 Typical Mechanism of Penetration of Rootkit Trojans
into the System . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 171
2.6 Cookies Spyware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 174
2.6.1 Main Functions of Cookies . . . . . . . . . . . . . . . . . . . . . . 174
2.6.2 Cookies Storage Method . . . . . . . . . . . . . . . . . . . . . . . . 176
2.6.3 Other Types of Cookies . . . . . . . . . . . . . . . . . . . . . . . . 176
2.6.4 Data Leakage Paths and Hazards Created
by Cookies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 177
2.6.5 Methods for Setting Parameters of Work
with Cookies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 179
2.6.6 Regin Spyware Program . . . . . . . . . . . . . . . . . . . . . . . . 183
2.7 Example of Injection of a Software . . . . . . . . . . . . . . . . . . . . . . 184
2.7.1 Purpose and Structure of PE Files . . . . . . . . . . . . . . . . . 184
2.7.2 Main Methods of Injecting Software Trojans
into PE Files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 188
2.7.3 Solution to the Problem of Finding Available Space
for the Trojan Code . . . . . . . . . . . . . . . . . . . . . . . . . . . 190
2.7.4 Interception of the Current Execution Thread . . . . . . . . . 195
2.7.5 Introduction of a Hardware Trojan Code . . . . . . . . . . . . 198
2.7.6 Execution Thread Recovery . . . . . . . . . . . . . . . . . . . . . 200
2.8 Specifics of Organization of Data Protection When Working
with Cryptocurrencies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 203
References . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 206
3 Hardware Trojans in Electronic Devices . . . . . . . . . . . . . . . . . . . . . . 209
3.1 Hardware Trojan Programs in Telecommunication Systems . . . . . 209
3.1.1 Trojans in Network Equipment . . . . . . . . . . . . . . . . . . . 209
3.1.2 Trojans in Routers . . . . . . . . . . . . . . . . . . . . . . . . . . . . 211
3.1.3 Firewalls . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 213
3.1.4 Wireless Networks . . . . . . . . . . . . . . . . . . . . . . . . . . . . 214
3.1.5 Trojans in Working Servers . . . . . . . . . . . . . . . . . . . . . 214
3.1.6 Trojans in Equipment of Workplaces
of Telecommunication System Operators . . . . . . . . . . . . 215
3.2 Hardware Trojans in Computers . . . . . . . . . . . . . . . . . . . . . . . . 216
3.2.1 Hardware Trojans in the System Unit . . . . . . . . . . . . . . 216
3.2.2 Hardware Trojans for USB Connection . . . . . . . . . . . . . 217
Contents
xv
2.5.1 What Is a Rootkit Technology? . . . . . . . . . . . . . . . . . . . 165
2.5.2 Methods of Intercepting API Functions
in User Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 165
2.5.3 Methods of Interception of Rootkit Functions
in Kernel Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 169
2.5.4 Main Methods of Rootkit Detection in the System . . . . . 170
2.5.5 Typical Mechanism of Penetration of Rootkit Trojans
into the System . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 171
2.6 Cookies Spyware . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 174
2.6.1 Main Functions of Cookies . . . . . . . . . . . . . . . . . . . . . . 174
2.6.2 Cookies Storage Method . . . . . . . . . . . . . . . . . . . . . . . . 176
2.6.3 Other Types of Cookies . . . . . . . . . . . . . . . . . . . . . . . . 176
2.6.4 Data Leakage Paths and Hazards Created
by Cookies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 177
2.6.5 Methods for Setting Parameters of Work
with Cookies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 179
2.6.6 Regin Spyware Program . . . . . . . . . . . . . . . . . . . . . . . . 183
2.7 Example of Injection of a Software . . . . . . . . . . . . . . . . . . . . . . 184
2.7.1 Purpose and Structure of PE Files . . . . . . . . . . . . . . . . . 184
2.7.2 Main Methods of Injecting Software Trojans
into PE Files . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 188
2.7.3 Solution to the Problem of Finding Available Space
for the Trojan Code . . . . . . . . . . . . . . . . . . . . . . . . . . . 190
2.7.4 Interception of the Current Execution Thread . . . . . . . . . 195
2.7.5 Introduction of a Hardware Trojan Code . . . . . . . . . . . . 198
2.7.6 Execution Thread Recovery . . . . . . . . . . . . . . . . . . . . . 200
2.8 Specifics of Organization of Data Protection When Working
with Cryptocurrencies . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 203
References . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 206
3 Hardware Trojans in Electronic Devices . . . . . . . . . . . . . . . . . . . . . . 209
3.1 Hardware Trojan Programs in Telecommunication Systems . . . . . 209
3.1.1 Trojans in Network Equipment . . . . . . . . . . . . . . . . . . . 209
3.1.2 Trojans in Routers . . . . . . . . . . . . . . . . . . . . . . . . . . . . 211
3.1.3 Firewalls . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 213
3.1.4 Wireless Networks . . . . . . . . . . . . . . . . . . . . . . . . . . . . 214
3.1.5 Trojans in Working Servers . . . . . . . . . . . . . . . . . . . . . 214
3.1.6 Trojans in Equipment of Workplaces
of Telecommunication System Operators . . . . . . . . . . . . 215
3.2 Hardware Trojans in Computers . . . . . . . . . . . . . . . . . . . . . . . . 216
3.2.1 Hardware Trojans in the System Unit . . . . . . . . . . . . . . 216
3.2.2 Hardware Trojans for USB Connection . . . . . . . . . . . . . 217
Contents
xv
