2.2 Implants: Types, Ways of Injection, and Methods of Protection
133
system, transparent for system administrator during monitoring of network traffic
and behavior.
In most cases, there is no necessity to use an original encryption method, since
the intruder usually uses only standard encoding algorithms to hide data during
transmission. If the intruder is using an extremely powerful method (like RSA), it
can cause increased loading of the CPU of the user’s machine, and the transmission
time will be prolonged.
In such cases, intruders usually use the so-called symmetric encryption methods
AES. Sarpent is one of such popular methods used with the help of implants. Even
though Sarpent is extremely powerful, it can still be reflected using an XSL attack;
however, it is much more powerful than other AES methods, and intruders use it, as
they believe that XSL can be used to destroy an effective algorithm like Serpent.
Other algorithms (SSH or VPN) are standard encryption methods used by
intruders to encrypt traffic. Sending packets using VPN or SSH is undetectable by
means of a firewall and administrator, and the intruder can use standard services that
are already installed on the network to encrypt packets controlled by the implant.
Using Rootkits
Even though software implants can be extremely hazardous, they work as normal
applications and thus can be easily detected. An implant can be seen while looking
at the list of system tasks with the help of services or system register. An experienced
intruder uses more powerful implants known as rootkits. Rootkits work as a part of
the operating system and don’t let the user see real tasks or services. In this case, the
operating system will be fully controlled by the intruder able to hide anything at all
in the system. Rootkits, in turn, are subdivided into two main groups with different
architectures: classic rootkits and kernel rootkits.
Classic Rootkits
Classic rootkits are focused on UNIX-based operating systems, such as Linux and
SunOS. Intruders usually replace the file /bin/login in these rootkits with another
version that allows the intruder to use their own name and password to enter the
system. In this situation, if the system administrator changes the root password or
limits access of the root user for remote registration in the system, the intruder can
register using their own password. They can also use it to save passwords of other
users in the intruder’s database.
Sometimes, classic rootkits change the command ifconfig to hide network map
flags from the administrator. If they don’t change the classic ifconfig file during
sniffing, the administrator can see the flag PROMISC and realize that a sniffer is
running.
It is also possible to specify other UNIX commands that are usually changed
under the influence of classic disguise rootkits—du, find, is, netstat, and ps.
Kernel Rootkits
Kernel rootkits replace themselves with the so-called kernel (core) of the operating
system. In this case, after application start-up, the operating system communicates the
133
system, transparent for system administrator during monitoring of network traffic
and behavior.
In most cases, there is no necessity to use an original encryption method, since
the intruder usually uses only standard encoding algorithms to hide data during
transmission. If the intruder is using an extremely powerful method (like RSA), it
can cause increased loading of the CPU of the user’s machine, and the transmission
time will be prolonged.
In such cases, intruders usually use the so-called symmetric encryption methods
AES. Sarpent is one of such popular methods used with the help of implants. Even
though Sarpent is extremely powerful, it can still be reflected using an XSL attack;
however, it is much more powerful than other AES methods, and intruders use it, as
they believe that XSL can be used to destroy an effective algorithm like Serpent.
Other algorithms (SSH or VPN) are standard encryption methods used by
intruders to encrypt traffic. Sending packets using VPN or SSH is undetectable by
means of a firewall and administrator, and the intruder can use standard services that
are already installed on the network to encrypt packets controlled by the implant.
Using Rootkits
Even though software implants can be extremely hazardous, they work as normal
applications and thus can be easily detected. An implant can be seen while looking
at the list of system tasks with the help of services or system register. An experienced
intruder uses more powerful implants known as rootkits. Rootkits work as a part of
the operating system and don’t let the user see real tasks or services. In this case, the
operating system will be fully controlled by the intruder able to hide anything at all
in the system. Rootkits, in turn, are subdivided into two main groups with different
architectures: classic rootkits and kernel rootkits.
Classic Rootkits
Classic rootkits are focused on UNIX-based operating systems, such as Linux and
SunOS. Intruders usually replace the file /bin/login in these rootkits with another
version that allows the intruder to use their own name and password to enter the
system. In this situation, if the system administrator changes the root password or
limits access of the root user for remote registration in the system, the intruder can
register using their own password. They can also use it to save passwords of other
users in the intruder’s database.
Sometimes, classic rootkits change the command ifconfig to hide network map
flags from the administrator. If they don’t change the classic ifconfig file during
sniffing, the administrator can see the flag PROMISC and realize that a sniffer is
running.
It is also possible to specify other UNIX commands that are usually changed
under the influence of classic disguise rootkits—du, find, is, netstat, and ps.
Kernel Rootkits
Kernel rootkits replace themselves with the so-called kernel (core) of the operating
system. In this case, after application start-up, the operating system communicates the
