152
2 Computer Viruses, Malicious Logic, and Spyware
successfully identified by antivirus programs, which indicate the presence of suspicious code in the boot sector of the disk. Initiation of static error on the disk can be
easily handled by DiskDoctor, which is included in the popular NortonUtilities utility
package. Means of checking integrity of disk data (like Adinf) help easily identify the
changes introduced into files by software implants. In addition, an effective method
consists in finding code of software implants based on characteristic sequences of
ones and zeros (signatures), as well as permission to execute programs with known
signatures only.
2.3.4.6 Deletion of an Identified Software Implant
Specific method of deletion of an introduced implant depends on the method used
to introduce it in the system. If it is a firmware implant, it is necessary to reprogram
the computer’s ROM. If this is a disguised loading, driver or application implant,
or an imitator, it can be replaced with the corresponding boot record, driver, utility,
application, or service program received from a trusted source. Finally, if this is an
executable software module, the user can attempt to acquire its source text, remove
the detected implants or suspicious fragments, and compile it once again.
2.3.4.7 Means of Creating False Objects in the Information Space
Today, a lot of attention in protection of information systems is given to the issues of
detecting and neutralizing vulnerabilities included in the software of such systems.
Currently, all main methods of solving this task are based on application of a prohibition strategy. For this purpose, the software of the information system is manually
or automatically checked for vulnerabilities that are described in public or private
databases. After detection, the vulnerability is neutralized either by means of a to
software update of by using information protection means, such as firewalls, intrusion detection systems, antivirus protection means, etc., which make exploitation of
this “vulnerability” for organization of unauthorized access impossible [9].
However, practice shows that this strategy often proves ineffective against zeroday vulnerabilities. This is due to the fact that a significant amount of time usually
passes between software release and emergence of information about the vulnerability, let alone its elimination by developers; during this time, the system remains
vulnerable. Regardless of the fact that properly tuned means of protection make
exploitation of some of such vulnerabilities impossible, there is always a possibility
of undetected vulnerabilities, as well as vulnerabilities in software of the protection
means themselves [9].
In this connection, the use of the “deception strategy” or distraction of the information weapon attack with a false information resource is becoming more relevant
today. The studies [10] demonstrate that by implementing the strategy of deception
of the attacking system and distracting the system with a false information resource,
it is possible not only to prevent unauthorized access to the protected information,
Précédent

- 173/839

Suivant