2.3 Models of Influence of Software Implants on Computers …
147
Table 2.3 lists several scenarios that can lead to implementation of malicious
hazards and subsequently to violation of process security of information during
various stages of software lifecycle.
Typical scenario for all stages is supply and introduction of information technologies or their elements containing software, hardware, or firmware implants.
Table 2.3 Scenarios of introduction of software implants during stages of software lifecycle
Stages
Scenarios
Design stage
Penetration of intruders into teams of developers of hardware
and most critical software elements.
Infiltration of intruders, who are perfectly aware of weak spots
and features of the utilized technologies
Coding stage
Organization of dynamically formed commands or parallel
computing processes.
Organization of command addresses modification, recording of
malicious information in memory cells used by the information
system or other programs. Formation of an implant affecting
other parts of the program environment or altering its structure.
Organization of disguised trigger of the implant
Testing and debugging phase Introduction of the implant both into separate subprograms and
into the controlling program.
Formation of an implant with dynamically formed commands.
Formation of a set of test data preventing detection of the
software implant.
Formation of a software implant, which cannot be detected
using the applied object model due to its difference from the
described object
Control
Formation of the trigger mechanism of the software implant,
which doesn’t activate it during security control.
Masking of the implant by means of introducing false
“unintended” defects into the software environment.
Formation of software implant in branches of the software
environment that are not checked during control.
Formation of viral programs preventing identification of their
penetration into the software environment by means of
checksumming.
Operation
Infiltration of the controlling department by intruders.
Recruitment of employees of the controlling department.
Collection of information about the tested software system.
Development of new software implants during modification of
the program environment
147
Table 2.3 lists several scenarios that can lead to implementation of malicious
hazards and subsequently to violation of process security of information during
various stages of software lifecycle.
Typical scenario for all stages is supply and introduction of information technologies or their elements containing software, hardware, or firmware implants.
Table 2.3 Scenarios of introduction of software implants during stages of software lifecycle
Stages
Scenarios
Design stage
Penetration of intruders into teams of developers of hardware
and most critical software elements.
Infiltration of intruders, who are perfectly aware of weak spots
and features of the utilized technologies
Coding stage
Organization of dynamically formed commands or parallel
computing processes.
Organization of command addresses modification, recording of
malicious information in memory cells used by the information
system or other programs. Formation of an implant affecting
other parts of the program environment or altering its structure.
Organization of disguised trigger of the implant
Testing and debugging phase Introduction of the implant both into separate subprograms and
into the controlling program.
Formation of an implant with dynamically formed commands.
Formation of a set of test data preventing detection of the
software implant.
Formation of a software implant, which cannot be detected
using the applied object model due to its difference from the
described object
Control
Formation of the trigger mechanism of the software implant,
which doesn’t activate it during security control.
Masking of the implant by means of introducing false
“unintended” defects into the software environment.
Formation of software implant in branches of the software
environment that are not checked during control.
Formation of viral programs preventing identification of their
penetration into the software environment by means of
checksumming.
Operation
Infiltration of the controlling department by intruders.
Recruitment of employees of the controlling department.
Collection of information about the tested software system.
Development of new software implants during modification of
the program environment
