128
2 Computer Viruses, Malicious Logic, and Spyware
Compliance with the first of these conditions for operating systems localized for
Russia is impossible in principle. The problem is that the means of creating user
accounts in Russian is an integral part of such systems. Only the English language
versions of Windows NT and UNIX are fitted with the abilities that allow to maintain
the level of security with which all of the three above conditions are met.
2.2.4.4 Proxies
Proxies fully or partially replace program modules of the operating system responsible for user authentication. Such keyloggers can be created for operation in the environment of nearly any multi-user operating system. Labor intensity required to write
a proxy is determined by the complexity of algorithms implemented by the authentication subsystem and interfaces between its separate modules. When assessing labor
intensity required, it is also necessary to consider how well the subsystem is documented. In general, it can be said that creation of a proxy is much more difficult
than creation of an imitator or a filter. Therefore, no cases of using such implants
by intruders have been registered. However, due to the fact that the Windows NT
operating system, equipped with powerful means of protection from imitators and
filters, is becoming more and more popular, we should soon expect hackers to use
proxies more actively in order to gain unauthorized access to computer systems.
Since proxies assume the functions of the authentication system, before intercepting user passwords, they need to carry out the following actions:
• Penetrate one or several system files like a computer virus;
• Use interface connections between software modules of the authentication system
to embed themselves in the chain of processing of the password input by the user.
In order to protect a system from implementation of a proxy, its administrators
need to strictly follow the security policy. Especially important is that the authentication subsystem has to be one of the most protected elements of the operating
system. However, practice shows that administrators, like other people, are prone to
mistakes. Therefore, compliance with an adequate security policy for an unlimited
period of time is an impossible task. Moreover, as soon as proxy enters a computer
system, any measures of protection from introduction of software implants cease to
be adequate; therefore, it is necessary to provide for the possibility of using effective means of detection and removal of introduced keyboard spies. This means that
the administrator must carefully monitor integrity of the executed system files and
interface functions used by the authentication system to solve its tasks.
However, this measure also can be insufficiently effective. This is because the
machine code of a proxy is executed within the context of an operating system;
therefore, the proxy can take special measures to make its detection as difficult
as possible. For example, it can intercept system calls used by the administrator to
identify implants in order to substitute the returned information, or filter the messages
registered by the audit subsystem to exclude the ones indicating its presence on the
computer.
Précédent

- 149/839

Suivant