174
2 Computer Viruses, Malicious Logic, and Spyware
is to prohibit user programs from directly interacting with each other and allow
interaction only with the help of an intermediary—an operating system.
2.6 Cookies Spyware
2.6.1 Main Functions of Cookies
The cookies technology has been watched by information security specialists for
a long time, since many anti-spy programs contain means for searching malicious
cookies and impressive signature bases for implementation of such search. The use of
cookies as one of the forms of spyware, in turn, causes users to ask many questions:
Is it dangerous? Is it necessary to use special protection measures? In the paper [1],
we have examined the cookies technology, potential threats posed by it, and analysis
and counteraction methods.
First of all, cookies are small bits of text information saved on the user’s computer
following a request from a web server and transferred to it during subsequent visits.
The main purposes of cookies are as follows:
(1) Organization of sessions during user’s work with online shops, message boards,
and other interactive systems with web interface—for example, workflow
systems, or mailing services with web interface. In this case, cookies store
certain session parameters—for example, its unique identifier;
(2) Storage of various user parameters. Cookies often store not the actual data, but
a certain identifier that helps server software to identify the user;
(3) User identification in rating systems, counters, banner display systems, and
online polls. Often used as an element of protection from driving up the numbers
of visitation counters.
There are three methods of creating cookies.
Using the field in the HTTP response header. In this case, the server includes one
or several fields Set-Cookie: in the HTTP response. Example of
the header of HTTP response from the server:
HTTP/1.0 200 OK
Date: Thu, 22 Dec 2005 06:41:30 GMT Expires: Thu, 01 Jan 1970 00:00:01 GMT
Content-type: image/gif
Set-Cookie: ruid = AjkABppKqkPzAAAAAZEAnFyrv; path =/; domain =
.rambler.ru; expires = Sun, 20-Dec-15 06:41:30 GMT
Using the META tag in the header of an HTML page. The tag has the form HTTP-EQUIV = ”Set-Cookie” CONTENT = ”definition of cookies”; one page can
contain several such tags. This tag is equivalent to the Set-Cookie field in the HTTP
response header
Using scripts of an HTML page. JavaScript, for example, is provided with the
document.cookie property for access to cookies. Let us consider a basic script that
2 Computer Viruses, Malicious Logic, and Spyware
is to prohibit user programs from directly interacting with each other and allow
interaction only with the help of an intermediary—an operating system.
2.6 Cookies Spyware
2.6.1 Main Functions of Cookies
The cookies technology has been watched by information security specialists for
a long time, since many anti-spy programs contain means for searching malicious
cookies and impressive signature bases for implementation of such search. The use of
cookies as one of the forms of spyware, in turn, causes users to ask many questions:
Is it dangerous? Is it necessary to use special protection measures? In the paper [1],
we have examined the cookies technology, potential threats posed by it, and analysis
and counteraction methods.
First of all, cookies are small bits of text information saved on the user’s computer
following a request from a web server and transferred to it during subsequent visits.
The main purposes of cookies are as follows:
(1) Organization of sessions during user’s work with online shops, message boards,
and other interactive systems with web interface—for example, workflow
systems, or mailing services with web interface. In this case, cookies store
certain session parameters—for example, its unique identifier;
(2) Storage of various user parameters. Cookies often store not the actual data, but
a certain identifier that helps server software to identify the user;
(3) User identification in rating systems, counters, banner display systems, and
online polls. Often used as an element of protection from driving up the numbers
of visitation counters.
There are three methods of creating cookies.
Using the field in the HTTP response header. In this case, the server includes one
or several fields Set-Cookie:
the header of HTTP response from the server:
HTTP/1.0 200 OK
Date: Thu, 22 Dec 2005 06:41:30 GMT Expires: Thu, 01 Jan 1970 00:00:01 GMT
Content-type: image/gif
Set-Cookie: ruid = AjkABppKqkPzAAAAAZEAnFyrv; path =/; domain =
.rambler.ru; expires = Sun, 20-Dec-15 06:41:30 GMT
Using the META tag in the header of an HTML page. The tag has the form HTTP-EQUIV = ”Set-Cookie” CONTENT = ”definition of cookies”; one page can
contain several such tags. This tag is equivalent to the Set-Cookie field in the HTTP
response header
Using scripts of an HTML page. JavaScript, for example, is provided with the
document.cookie property for access to cookies. Let us consider a basic script that
