3.1 Hardware Trojan Programs in Telecommunication Systems
215
are installed during the stage of delivery of equipment to a specific customer by
means of interception and manipulation; installation of Trojans by NSA specialist in
this case takes only several minutes.
HP DL380 G5 is a fifth-generation data storage server. It is used in corporate data
processing centers.
IRONCHEF Trojan is based on BIOS altering and usually used to establish
connection of the “chef” with the specific NAS agent via hidden hardware means.
This Trojan was designed for Proliant servers manufactured by Hewlett Packard.
Dell PowerEdge server is a storage server designed to be used in corporate data
processing centers.
DEITYBOUNCE Trojan is based on BIOS altering; this Trojan is used to establish
connection with the National Security Agency (NSA) infrastructure using hidden
hardware means.
In conclusion, it can be said that BIOS is the most vulnerable mechanism to
penetration of Trojans in network equipment. After a special operation of a platform
reflashing, it becomes possible both to install software implants of the second level
and ensure their constant presence. The most evident means to control the BIOS
image is using the trusted load module. Possible enhancement of this control mechanism consists in using the unified signature of the certification center for all BIOS,
as well as mandatory presence of the possibility of calculation and viewing of BIOS
and OS checksums in the software.
Special attention shall be paid to the systematic approach of US secret services
to covering the target infrastructure with various implants. It turns out that nearly
all potential channels of active interaction with the malicious code are found in the
cited [1] catalog: they include external firewalls, trunking equipment, and wireless
communication.
The greatest potential, in particular, in the development of reliable communication
equipment (router, firewall, wireless technologies support) is possible only on the
basis of a secure element-component base (ECB), which will be discussed in the
following chapters of this book.
3.1.6 Trojans in Equipment of Workplaces
of Telecommunication System Operators
As we know [A.I. Beloyc, B.A. Colodyxa, C.B. Xvedov. Ocnovy
konctpyipovanii vycokockopoctnyx lektponnyx yctpoctv. Kpatkii
kypc « Belo magii » . — M.: Texnocfepa, 2017], in terms of structure, means
of telecommunication systems can be divided into two groups:
(1) Infrastructure means including connections to external channels, local
computing networks, wireless access devices, working servers, etc.;
(2) Equipment of user workplaces including workstations, cellular communication,
etc.
215
are installed during the stage of delivery of equipment to a specific customer by
means of interception and manipulation; installation of Trojans by NSA specialist in
this case takes only several minutes.
HP DL380 G5 is a fifth-generation data storage server. It is used in corporate data
processing centers.
IRONCHEF Trojan is based on BIOS altering and usually used to establish
connection of the “chef” with the specific NAS agent via hidden hardware means.
This Trojan was designed for Proliant servers manufactured by Hewlett Packard.
Dell PowerEdge server is a storage server designed to be used in corporate data
processing centers.
DEITYBOUNCE Trojan is based on BIOS altering; this Trojan is used to establish
connection with the National Security Agency (NSA) infrastructure using hidden
hardware means.
In conclusion, it can be said that BIOS is the most vulnerable mechanism to
penetration of Trojans in network equipment. After a special operation of a platform
reflashing, it becomes possible both to install software implants of the second level
and ensure their constant presence. The most evident means to control the BIOS
image is using the trusted load module. Possible enhancement of this control mechanism consists in using the unified signature of the certification center for all BIOS,
as well as mandatory presence of the possibility of calculation and viewing of BIOS
and OS checksums in the software.
Special attention shall be paid to the systematic approach of US secret services
to covering the target infrastructure with various implants. It turns out that nearly
all potential channels of active interaction with the malicious code are found in the
cited [1] catalog: they include external firewalls, trunking equipment, and wireless
communication.
The greatest potential, in particular, in the development of reliable communication
equipment (router, firewall, wireless technologies support) is possible only on the
basis of a secure element-component base (ECB), which will be discussed in the
following chapters of this book.
3.1.6 Trojans in Equipment of Workplaces
of Telecommunication System Operators
As we know [A.I. Beloyc, B.A. Colodyxa, C.B. Xvedov. Ocnovy
konctpyipovanii vycokockopoctnyx lektponnyx yctpoctv. Kpatkii
kypc « Belo magii » . — M.: Texnocfepa, 2017], in terms of structure, means
of telecommunication systems can be divided into two groups:
(1) Infrastructure means including connections to external channels, local
computing networks, wireless access devices, working servers, etc.;
(2) Equipment of user workplaces including workstations, cellular communication,
etc.
