3.2 Hardware Trojans in Computers
225
little computer in itself. The program of this chip is called firmware, and hard drive
manufacturers sometimes wish to update it in order to correct some of their mistakes
or improve the operating speed of the drive.
The hackers have learned to effectively exploit this exact mechanism, loading their
own firmware into hard drives of 12 different categories (manufacturers/models). It
has to be said that the functions of modified firmware remain a mystery at the moment
of publication of this book; however, such firmware actually allows the malware
installed in the computer to read data and write them to a special section of the hard
drive. At the moment, experts only suppose that this section becomes completely
hidden from the operating system and special analytical programs working with the
disk on a low level. Therefore, data in this area can even survive the disk formatting
procedure!
Moreover, this problem theoretically is able to re-infect the bootstrap area of the
hard drive, infecting even a newly installed operating system. The problem is further
complicated by the paradoxical fact that the firmware is responsible for checking its
own state and updating itself. Therefore, no computer programs today are capable of
reliably checking the integrity of the firmware code or update it with a reliable result.
In other words, firmware infected once is nearly impossible to detect or destroy.
Clearly, the cheaper and simpler solution is to throw a suspicious hard drive away
and buy a new one.
However, according to the experts, average users are not currently endangered by
this extremely powerful infestation possibility.
Any computer equipment specialist knows that reprogramming a hard drive is
much more difficult than, say, writing a program for Windows. Each hard drive
model is unique in itself, and developing alternative hardware for all of them would
require a lot of time and money. For this, the hacker would need to acquire internal
documentation of the manufacturer (which is already extremely difficult), buy several
hard drives of the exact same model, and test the required functionality, as well as
squeeze it in the limited free space of the firmware while preserving all the source
functions.
Specialists understand that this is an extremely high-level and professional work
that requires many months of development and at least millions of investments.
Therefore, it is pointless to use this type of technologies in criminal malware or even
most targeted attacks. Moreover, development of such firmwares suggests boutique
approach to hacking, which is difficult to deploy on a large scale. Hard drive manufacturers produce new hard drives and firmwares for them nearly every month, and
hacking each of them is difficult and pointless.
The practical conclusion from this is simple. Malicious software programs
infecting hard drives are not a legend anymore; nevertheless, there is no danger
for an average user. Do not break your hard drive with a hammer—unless you’re
working on the Iranian, Korean, or Russian missile development program. More
attention shall be paid to less impressive but much more possible risks like hacking
due to a weak password or outdated antivirus software described above.
Therefore, this type of hacker attack is designed only to be used in special cyberoperations under strict secret control of governments and designed for implementation
Précédent

- 245/839

Suivant