2.2 Implants: Types, Ways of Injection, and Methods of Protection
129
2.2.4.5 Trojan Programs: Types and Behavior Features
Unlike the worms and viruses examined above, Trojan programs don’t create their
own copies. They enter a computer, for example, with e-mails or via an Internet
browser, when the user visits and “infected” page. Trojans are injected with the help
of the user and activate after the computer is switched on. Different Trojan programs
implement different tasks depending on the design of their creators.
The main functions of Trojans are to block, alter, or destroy information and impair
operation of computers and computer networks. In addition, Trojans can receive or
send files, execute them, display various messages on screen, independently call web
pages, download and install other programs, reboot the computer at the intruder’s
command, etc.
Intruders often use combinations of different Trojans.
Table 2.2 contains the main types of Trojans with brief description of their
functioning in infected devices.
2.2.4.6 Main Ways of Implant Implementation
In most cases, after the intruder becomes aware of the system control takeover, they
install a special implant in the victim’s system in order to gain unlimited access in
the future.
One of the most widely used ways of implant installation consists in using various
versions of ActiveX software. As soon as the user visits a site, built-in ActiveX can
automatically run in this system. Most websites on the Internet indicate ActiveX
launch in the form of real-time voice information exchange, loading applications,
or checking the user. At the same time, a number of applications are often used to
improve capabilities of sites (for example, Java applications), which have limited
access to the system; however, ActiveX provides the intruder with complete control
over the machine executing such ActiveX.
Microsoft has officially announced the implementation of security policy
measures to protect the system from this fraud many times. For example, ActiveX
developers must sign their published ActiveX files with valid signatures. If a user
wants to run ActiveX without a valid signature, the browser displays a warning indicating safety problem that may take place after ActiveX launch. Unfortunately, most
users disregard such warnings and run any ActiveX built-in for viewing of a site
page. One should remember that running ActiveX from an unknown source without
a valid signature can be very dangerous.
2.2.4.7 Mechanisms of Undetectable Control Organization
Intruders usually use various mechanisms to make their implants undetectable and
untraceable. If a system administrator notices unusual behavior of the system, they
can understand that such behavior can be caused by a virus or an implant; therefore,
Précédent

- 150/839

Suivant