142
2 Computer Viruses, Malicious Logic, and Spyware
system is launched in a normal manner. The undoubted advantage for the intruder
is the fact that the modified firmware itself contains no malicious code, and bootkits
are hard to detect.
2.2.4.10 Main Methods of Protection from Trojans and Implants
After studying how implants work in general, we can protect our systems and resist
these types of attacks using simple methods.
The following reliable classic methods can be used for such protection.
Antiviruses
Launch of updated antiviruses in all client systems with real-time protection can
be a good method of protection against popular implants and Trojan programs.
Antiviruses can easily find implants and Trojans before their launch in the system;
however, it is important to keep antiviruses updated. If the intruder uses a new implant
or Trojan, which don’t exist in the antivirus base, they can be easily injected into the
victim’s machine.
Signatures
Before using software, it is necessary to verify reliability of the application you’re
going to run. For example, many developers use the MD5 algorithm to obtain a
“chopped” string from the final application. After downloading an application and
before launching it, it is possible to calculate the chopped spring of the executed
application and compare it to the reference chopped string presented on the developer’s website. If such chopped string is the same, it means that no changes were
introduced in the launched file and that it can be executed.
There are numerous third-party companies like Verisign that provide certain keys
for application signing to developers. If an application contains this signature, you
can be sure that the company is trustworthy, and the application is valid and can be
safely executed. If the information about companies verifying software is insufficient,
one can contact a reliable third-party company that will verify guarantees of the
programmer.
Training
It is essential to teach users the main safety rules that can be implemented throughout
the system. In most cases, intruders use social media to trick users. Therefore, regular
users (secret services already know their trade well) need to know what they should
or shouldn’t do. Even if one user does something wrong, the entire corporation the
user works in can become accessible for an intruder.
Let us consider Back Orifice 2000 as an example of operation of such software
implants in the system. Back Orifice 2000 (also known as Bo2k) is one of the oldest
well-known implants widely used for training of security specialists working on
Windows machines.
Précédent

- 163/839

Suivant