134
2 Computer Viruses, Malicious Logic, and Spyware
results required by the intruder. With kernel rootkits, all processes, tasks, network
configurations, port numbers, file contents, etc. can disguise themselves, and the
intruder can force the operating system to provide false information in relation to
everything that the user or administrator could want to know.
If kernel rootkits are used, detection and tracking of implants becomes extremely
difficult, since they can even stop the antivirus or system monitors. This is the most
powerful method of introducing implants.
Using Various Protocols and Port Numbers
The intruder can use a random port number instead of standard ports for operation of
service programs and the victim’s machine. Unexpected operation of the SSH service
on port 22, which is always controlled by the administrator, can cause the system
administrator to track the attack. Therefore, most intruders use other port numbers
to make detection of the intruder’s operating services more difficult.
Some implants operate in a more professional way. They change port numbers,
using protocol during the attack. For example, a smart implant can change the communication protocol, replacing TCP with UDP or even ICMP. If the system administrator
blocks a port or a protocol on the gateway, the implant can automatically switch to
another protocol or port number and allow the intruder to connect to the system.
Reverse Control
Most firewalls or administrators block some of your connections with the outside
world. They can let a local user browse sites and do nothing else. This can be even
stricter with a NAT system; giving private IP addresses, the intruder loses the ability
to connect with the system implemented in a private LAN.
Implants can use a different strategy in such cases. For example, the intruder runs
their own server on a specific IP address, and the implant tries to connect to the server
inside the firewall and request commands to be performed on the victim’s machine
from the intruder’s server. An implant can also use a standard HTTP protocol to
connect to the intruder’s server, and the server will send commands in the HTTP
format. For the firewall or administrator, it looks like web browsing. Such strategy
can prove ineffective due to the huge structure of a firewall and is actually difficult
to detect.
The only way to detect such connections consists in monitoring of the number of
requests sent by the hardware system to the special IP address. Sometimes, intruders
combine multiple servers at different IP addresses into a chain in order to ensure
random connection to the victim’s system. Protection from this method is even more
difficult.
Temporary Sequence of Implant Implementation
There are multiple servers used to update systems during downtime. Cron command
on UNIX machines or Schedule tasks on Windows machines are examples of such
services.
Intruders can use them to implement implants at given time. For example, using
a Cron table of a UNIX machine, the implant can start working at 4 AM and let
2 Computer Viruses, Malicious Logic, and Spyware
results required by the intruder. With kernel rootkits, all processes, tasks, network
configurations, port numbers, file contents, etc. can disguise themselves, and the
intruder can force the operating system to provide false information in relation to
everything that the user or administrator could want to know.
If kernel rootkits are used, detection and tracking of implants becomes extremely
difficult, since they can even stop the antivirus or system monitors. This is the most
powerful method of introducing implants.
Using Various Protocols and Port Numbers
The intruder can use a random port number instead of standard ports for operation of
service programs and the victim’s machine. Unexpected operation of the SSH service
on port 22, which is always controlled by the administrator, can cause the system
administrator to track the attack. Therefore, most intruders use other port numbers
to make detection of the intruder’s operating services more difficult.
Some implants operate in a more professional way. They change port numbers,
using protocol during the attack. For example, a smart implant can change the communication protocol, replacing TCP with UDP or even ICMP. If the system administrator
blocks a port or a protocol on the gateway, the implant can automatically switch to
another protocol or port number and allow the intruder to connect to the system.
Reverse Control
Most firewalls or administrators block some of your connections with the outside
world. They can let a local user browse sites and do nothing else. This can be even
stricter with a NAT system; giving private IP addresses, the intruder loses the ability
to connect with the system implemented in a private LAN.
Implants can use a different strategy in such cases. For example, the intruder runs
their own server on a specific IP address, and the implant tries to connect to the server
inside the firewall and request commands to be performed on the victim’s machine
from the intruder’s server. An implant can also use a standard HTTP protocol to
connect to the intruder’s server, and the server will send commands in the HTTP
format. For the firewall or administrator, it looks like web browsing. Such strategy
can prove ineffective due to the huge structure of a firewall and is actually difficult
to detect.
The only way to detect such connections consists in monitoring of the number of
requests sent by the hardware system to the special IP address. Sometimes, intruders
combine multiple servers at different IP addresses into a chain in order to ensure
random connection to the victim’s system. Protection from this method is even more
difficult.
Temporary Sequence of Implant Implementation
There are multiple servers used to update systems during downtime. Cron command
on UNIX machines or Schedule tasks on Windows machines are examples of such
services.
Intruders can use them to implement implants at given time. For example, using
a Cron table of a UNIX machine, the implant can start working at 4 AM and let
