2.7 Example of Injection of a Software
203
full permissions for sections, unless the programmer has set up special settings. In
particular, data sections .data ˆrdata must have no execution privileges. Moreover,
code sections (such as .text) must have no write rights. Such anomalies related to
alteration of privileges shall be considered suspicious.
Presence of Non-standard Sections
If a programmer does not alter the configuration, compilers usually create about 5–6
standard types of sections. The mechanism for detection of non-standard and suspicious sections must be embedded in all security-related products. This mechanism
shall monitor entropy and data deskewing inside sections. If a section contains high
entropy and irregularly ordered information, it causes more grounds for suspicion.
Signature Verification
Even though this technique is nearly as old as the world itself, it is very effective for
verification of files downloaded from the Internet. shal signature verification is one
of the most reliable ways to avoid infection of the system.
Checking the File Checksum
If there is a difference between the checksum inside the image header and the current
checksum of the file, it means that the file has been checked. Security systems need
to employ the mechanism for verification of the file authenticity by comparing the
current checksum and the checksum of the image header.
2.8 Specifics of Organization of Data Protection When
Working with Cryptocurrencies
The reader needs to get at least a general idea of the concept of another problematic
issue, which seems indirectly related to the main subject of research of this book—the
problem of the so-called cryptocurrency. In late 2017, this currency skyrocketed to
the level previously unimaginable—20 thousand dollars (!). Of course, the exchange
rate of the Bitcoin started falling just as rapidly, but the level of reduction (10 thousand
dollars) causes the consumers to ask a number of new questions. Moreover, there
were other cryptocurrencies before the Bitcoin, and their value dropped even lower.
In this section, we would like to draw attention of concerned readers to the emergence and rapid development of another concept that is not entirely clear to regular
citizens: the concept of browser miner, the point of which is to acquire cryptocurrency without knowledge of law-abiding users of this type of banking operations.
That is, an intruder uses the computer of a regular user for his own lucrative purposes;
however, no one can tell citizens how to protect from such cyberattacks, which are
already referred to as hidden mining.
Mining is the term describing acquisition of cryptocurrency as a result of implementation of an extremely complex sequence of information processes that cannot
203
full permissions for sections, unless the programmer has set up special settings. In
particular, data sections .data ˆrdata must have no execution privileges. Moreover,
code sections (such as .text) must have no write rights. Such anomalies related to
alteration of privileges shall be considered suspicious.
Presence of Non-standard Sections
If a programmer does not alter the configuration, compilers usually create about 5–6
standard types of sections. The mechanism for detection of non-standard and suspicious sections must be embedded in all security-related products. This mechanism
shall monitor entropy and data deskewing inside sections. If a section contains high
entropy and irregularly ordered information, it causes more grounds for suspicion.
Signature Verification
Even though this technique is nearly as old as the world itself, it is very effective for
verification of files downloaded from the Internet. shal signature verification is one
of the most reliable ways to avoid infection of the system.
Checking the File Checksum
If there is a difference between the checksum inside the image header and the current
checksum of the file, it means that the file has been checked. Security systems need
to employ the mechanism for verification of the file authenticity by comparing the
current checksum and the checksum of the image header.
2.8 Specifics of Organization of Data Protection When
Working with Cryptocurrencies
The reader needs to get at least a general idea of the concept of another problematic
issue, which seems indirectly related to the main subject of research of this book—the
problem of the so-called cryptocurrency. In late 2017, this currency skyrocketed to
the level previously unimaginable—20 thousand dollars (!). Of course, the exchange
rate of the Bitcoin started falling just as rapidly, but the level of reduction (10 thousand
dollars) causes the consumers to ask a number of new questions. Moreover, there
were other cryptocurrencies before the Bitcoin, and their value dropped even lower.
In this section, we would like to draw attention of concerned readers to the emergence and rapid development of another concept that is not entirely clear to regular
citizens: the concept of browser miner, the point of which is to acquire cryptocurrency without knowledge of law-abiding users of this type of banking operations.
That is, an intruder uses the computer of a regular user for his own lucrative purposes;
however, no one can tell citizens how to protect from such cyberattacks, which are
already referred to as hidden mining.
Mining is the term describing acquisition of cryptocurrency as a result of implementation of an extremely complex sequence of information processes that cannot
