126
2 Computer Viruses, Malicious Logic, and Spyware
to apply more complex and sophisticated protection measures. Windows NT can be
used as an example of an operating system in which such measures are practically
implemented to a sufficient extent.
The WinLogon system process, which is responsible for authenticating users in the
Windows NT operating system, has its own desktop—a set of windows that are simultaneously displayed on the screen. This set of windows is called the authentication
desktop. All other processes, including imitators, have no access to the authentication
desktop and cannot place their windows on it.
After Windows NT is launched, the computer screen shows the so-called authentication desktop start screen prompting the user to press++ on the
keyboard. The notification of pressing these buttons is sent only to the system process
WinLogon; for other processes, in particular, for all applications, this pressing is absolutely invisible. After that, the user is redirected to another window—the so-called
registration window of the authentication desktop. This window prompts the user to
enter username and password, which will be received and verified by WinLogon.
For interception of the user password, an imitator embedded in Windows NT
must be able to process pressing of the++ buttons by the user.
Otherwise, the screen will switch to the registration window of the authentication
desktop; the imitator will become inactive and lose the ability to intercept anything,
since all password symbols input by the user will bypass the imitator and only
belong to the WinLogon system process. As stated above, the registration procedure
in Windows NT is designed in such manner that++ pressing will
remain untraceable for all processes except for WinLogon; therefore, it will receive
the user password.
Of course, an imitator can attempt to reproduce not the start window of the authentication desktop (prompting the user to press++), but the registration window (prompting the user to enter the identification name and password).
However, if there are no imitators in the system, the registration window will be
automatically replaced with the start window after a short period of time (it can last
for a period of 30–60 s depending on the Windows NT version), if the user does not
attempt to register in the system during this period. Therefore, the very fact of excessively long time spent on the registration window screen shall alert the Windows
NT user and make them check their computer system carefully for the presence of
software implants.
So to sum up, we can say that the level of protection of Windows NT from imitators
is fairly high. Examination of protective mechanisms implemented in this operating
system helps form two necessary conditions, the compliance with which is necessary
to ensure reliable protection from imitators:
• The system process, which receives the user name and password during the system
login operation, shall have its own desktop inaccessible to other processes;
• The switch to the registration window of the authentication desktop has to be absolutely untraceable for application programs that also can’t influence the switch in
any way (forbid it, for example).
2 Computer Viruses, Malicious Logic, and Spyware
to apply more complex and sophisticated protection measures. Windows NT can be
used as an example of an operating system in which such measures are practically
implemented to a sufficient extent.
The WinLogon system process, which is responsible for authenticating users in the
Windows NT operating system, has its own desktop—a set of windows that are simultaneously displayed on the screen. This set of windows is called the authentication
desktop. All other processes, including imitators, have no access to the authentication
desktop and cannot place their windows on it.
After Windows NT is launched, the computer screen shows the so-called authentication desktop start screen prompting the user to press
keyboard. The notification of pressing these buttons is sent only to the system process
WinLogon; for other processes, in particular, for all applications, this pressing is absolutely invisible. After that, the user is redirected to another window—the so-called
registration window of the authentication desktop. This window prompts the user to
enter username and password, which will be received and verified by WinLogon.
For interception of the user password, an imitator embedded in Windows NT
must be able to process pressing of the
Otherwise, the screen will switch to the registration window of the authentication
desktop; the imitator will become inactive and lose the ability to intercept anything,
since all password symbols input by the user will bypass the imitator and only
belong to the WinLogon system process. As stated above, the registration procedure
in Windows NT is designed in such manner that
remain untraceable for all processes except for WinLogon; therefore, it will receive
the user password.
Of course, an imitator can attempt to reproduce not the start window of the authentication desktop (prompting the user to press
However, if there are no imitators in the system, the registration window will be
automatically replaced with the start window after a short period of time (it can last
for a period of 30–60 s depending on the Windows NT version), if the user does not
attempt to register in the system during this period. Therefore, the very fact of excessively long time spent on the registration window screen shall alert the Windows
NT user and make them check their computer system carefully for the presence of
software implants.
So to sum up, we can say that the level of protection of Windows NT from imitators
is fairly high. Examination of protective mechanisms implemented in this operating
system helps form two necessary conditions, the compliance with which is necessary
to ensure reliable protection from imitators:
• The system process, which receives the user name and password during the system
login operation, shall have its own desktop inaccessible to other processes;
• The switch to the registration window of the authentication desktop has to be absolutely untraceable for application programs that also can’t influence the switch in
any way (forbid it, for example).
