2.2 Implants: Types, Ways of Injection, and Methods of Protection
137
FinSpy is a backdoor that allows a remote intruder to download and run any
file from the Internet. The parasite decreases overall security of the system by
changing default parameters of the Windows Firewall and initiates other system
changes. FinSpy relies on files using random names; due to this fact, it is fairly
difficult to find its loophole and delete it from the system. This backdoor automatically launches during every Windows launch and can only be stopped using updated
anti-spy software.
Tixanbot is another extremely dangerous software backdoor, which gives the
hacker full access to the infected computer. The intruder can control the entire
system and files, download and install any applications, update the backdoor, change
home page settings of Internet Explorer, attack remote hosts, and obtain any system
information. Tixanbot stops operation and processes of the main services of the
system and security programs, closes active removers of spy programs, and deletes
the register records related to firewalls, antivirus, and anti-spy software in order to
prevent them from launching during windows start-up. This parasite also fully blocks
access to authoritative resources associated with security. Tixanbot can distribute
itself, sending messages with certain links to all MSN contacts. The user clicks on
such download link, and the backdoor is installed automatically.
Briba is a backdoor that gives the hacker remote unauthorized access to the
infected computer system. This parasite runs the hidden FTP server, which can be
used to download, update, or launch malware. Briba actions can cause significant loss
of stability, failures during operation of the computer, and confidentiality violations.
Software backdoors are extremely dangerous parasites that need to be removed
from the system. It is hardly possible to find and delete backdoor manually; therefore,
users are advised to use the automatic removal feature. There are a lot of programs
for backdoor removal. However, the most reliable one today is Reimage, as well as
Plumbytes Anti-Malware used as an alternative security tool.
2.2.4.9 Examples of Verified Hardware Implants
Let us consider some of the most well-known and documentarily verified facts of
detection of program backdoors in modern algorithms.
1. Vulnerability of the pseudo-random sequence generator DUAL_EC_DRBG
This generator was designed in the National Security Agency of the USA (NSA)
and standardized as cryptographically resistant pseudo-random number generator
by the National Institute of Standards and Technology of the USA (NIST) in 2006.
However, the next year independent researches suggested that the algorithm could
contain a backdoor (Fig. 2.10).
This algorithm uses elliptic curves. P is a generator of a group of points on an
elliptic curve, Q is a point on an elliptic curve—a constant defined by the standard;
Précédent

- 158/839

Suivant