2.3 Models of Influence of Software Implants on Computers …
151
• Verified programs cannot be launched in any conditions other than described
above, i.e., outside an isolated computer.
Multi-level control system can be used to determine the degree of isolation of a
computer. First, BIOS is checked for any changes. After that, if the check results are
satisfactory, the boot sector of the disk and the operating system drivers are read,
which are in turn also analyzed for the presence of unauthorized changes. Finally,
using the operating system, the program call control driver is started, which ensures
that only verified programs are started on the computer.
An interesting method of combating introduction of implants can be used in an
information bank system used for circulation of document files exclusively. In order
to prevent penetration of an implant through communication channels, no executable
codes are accepted in this system. Recognition of events “Executable code received”
and “File document received” is accompanied by the control over the presence of
illegal characters in the file: a file is recognized as containing executable code if it
includes symbols that are never found in document files.
2.3.4.5 Methods of Identification of an Introduced Implant
Identification of an introduced (embedded) implant code consists in detecting the
signs of its presence in the computer system. This signs can be divided into the
following two classes:
• Qualitative and visual;
• Detectable by test and diagnostics means.
Qualitative and visual signs include feelings and observations of the user of a
computer system, who notes certain deviations in operation of the system (composition and length of files change, old files disappear and new files appear, programs start
working slower or end their work too quickly or even stop launching). Even though
judgements on the presence of such signs seem too subjective, they nevertheless often
indicate malfunction of a computer system, in particular—the need to perform additional checks for the presence of software implants. For example, Russian users of the
encryption and digital signature package “Cryptocenter” noticed some time ago that
the process of signing documents started to take too little time. The study conducted
by the specialists of the Russian Federal Agency for Government Communications
and Information revealed the presence of a software implant, the operation of which
was based on imposing a file length. In another case, alarm was raised by users of the
encryption and digital signature package “Crypton”, who noticed in surprise that the
speed of encryption using the GOST 28147-89 cryptographic algorithm suddenly
increased 30 times. In the third case, an implant discovered itself in the keyboard
input program due to the fact that the infected program stopped working properly.
The features identified with the help of test and diagnostics means are characteristic for implants and computer vehicles alike. For example, loading implants are
151
• Verified programs cannot be launched in any conditions other than described
above, i.e., outside an isolated computer.
Multi-level control system can be used to determine the degree of isolation of a
computer. First, BIOS is checked for any changes. After that, if the check results are
satisfactory, the boot sector of the disk and the operating system drivers are read,
which are in turn also analyzed for the presence of unauthorized changes. Finally,
using the operating system, the program call control driver is started, which ensures
that only verified programs are started on the computer.
An interesting method of combating introduction of implants can be used in an
information bank system used for circulation of document files exclusively. In order
to prevent penetration of an implant through communication channels, no executable
codes are accepted in this system. Recognition of events “Executable code received”
and “File document received” is accompanied by the control over the presence of
illegal characters in the file: a file is recognized as containing executable code if it
includes symbols that are never found in document files.
2.3.4.5 Methods of Identification of an Introduced Implant
Identification of an introduced (embedded) implant code consists in detecting the
signs of its presence in the computer system. This signs can be divided into the
following two classes:
• Qualitative and visual;
• Detectable by test and diagnostics means.
Qualitative and visual signs include feelings and observations of the user of a
computer system, who notes certain deviations in operation of the system (composition and length of files change, old files disappear and new files appear, programs start
working slower or end their work too quickly or even stop launching). Even though
judgements on the presence of such signs seem too subjective, they nevertheless often
indicate malfunction of a computer system, in particular—the need to perform additional checks for the presence of software implants. For example, Russian users of the
encryption and digital signature package “Cryptocenter” noticed some time ago that
the process of signing documents started to take too little time. The study conducted
by the specialists of the Russian Federal Agency for Government Communications
and Information revealed the presence of a software implant, the operation of which
was based on imposing a file length. In another case, alarm was raised by users of the
encryption and digital signature package “Crypton”, who noticed in surprise that the
speed of encryption using the GOST 28147-89 cryptographic algorithm suddenly
increased 30 times. In the third case, an implant discovered itself in the keyboard
input program due to the fact that the infected program stopped working properly.
The features identified with the help of test and diagnostics means are characteristic for implants and computer vehicles alike. For example, loading implants are
