8
1 Information Weapon: Concepts, Means, Methods …
public key infrastructure (PKI), etc. Even traditional means of protection change
under the influence of the network scale and are complemented by new functions—
integration with the network management systems, effective event visualization,
advanced report generation, hierarchical and role-based management, etc.
Thus, the choice of protective information technologies depends on four main
factors—the popularity and prevalence of the protected technology; the type of hacker
attacks; the communication field; and the scale of information network. A change in
any of these factors leads to a change in both the protection technologies and the way
they are used. Considering the above, let us describe the most common protection
technologies in the modern digital world.
1.1.5.1 Antiviruses
One of the first technologies, which is still in high demand (by both corporate and
home users) is antivirus protection, which appeared in the mid-80s. It was then, after
the first timid attempts of virus writers, that the first virus scanners, phages, and
monitors began to appear. But if in the early days of active development of computer
networks, antiviruses that detected and treated traditional file and boot viruses spread
through diskettes and BBS, now there are practically no such viruses. Nowadays other
classes of malicious software top the virus charts—Trojans and worms that do not
spread from file to file, but from computer to computer. We shall take a closer look
at these software in one of the chapters below. Virus outbreaks have become real
epidemics and pandemics, and the damage from them is measured in tens of billions
of dollars.
The first antiviruses protected only stand-alone computers. Network protection
and centralized management were out of the question, which inevitably rendered
difficult the use of these solutions in the corporate market. Unfortunately, today the
state of affairs in this matter is also far from perfect, since modern antivirus companies
are not giving this aspect due attention, concentrating mainly on expanding virus
signature database. The exceptions are some foreign firms (TrendMicro, Symantec,
Sophos, etc.) that care about the corporate user. Russian manufacturers, who are just
as good as their foreign colleagues in terms of the quality and quantity of viruses
detected, are losing out to them in terms of centralized management.
1.1.5.2 Network Firewalls
In the late 1980s—early 1990s, as a result of the widespread development of computer
networks, the problem of their protection arose, which was solved with the help of
firewalls installed between the protected and unprotected networks. Starting from
conventional packet filters, these solutions have become multifunctional complexes
aimed at solving a multitude of tasks—from firewalling and load balance to controlling bandwidth and managing dynamic addresses. Also, a firewall may have a built-in
1 Information Weapon: Concepts, Means, Methods …
public key infrastructure (PKI), etc. Even traditional means of protection change
under the influence of the network scale and are complemented by new functions—
integration with the network management systems, effective event visualization,
advanced report generation, hierarchical and role-based management, etc.
Thus, the choice of protective information technologies depends on four main
factors—the popularity and prevalence of the protected technology; the type of hacker
attacks; the communication field; and the scale of information network. A change in
any of these factors leads to a change in both the protection technologies and the way
they are used. Considering the above, let us describe the most common protection
technologies in the modern digital world.
1.1.5.1 Antiviruses
One of the first technologies, which is still in high demand (by both corporate and
home users) is antivirus protection, which appeared in the mid-80s. It was then, after
the first timid attempts of virus writers, that the first virus scanners, phages, and
monitors began to appear. But if in the early days of active development of computer
networks, antiviruses that detected and treated traditional file and boot viruses spread
through diskettes and BBS, now there are practically no such viruses. Nowadays other
classes of malicious software top the virus charts—Trojans and worms that do not
spread from file to file, but from computer to computer. We shall take a closer look
at these software in one of the chapters below. Virus outbreaks have become real
epidemics and pandemics, and the damage from them is measured in tens of billions
of dollars.
The first antiviruses protected only stand-alone computers. Network protection
and centralized management were out of the question, which inevitably rendered
difficult the use of these solutions in the corporate market. Unfortunately, today the
state of affairs in this matter is also far from perfect, since modern antivirus companies
are not giving this aspect due attention, concentrating mainly on expanding virus
signature database. The exceptions are some foreign firms (TrendMicro, Symantec,
Sophos, etc.) that care about the corporate user. Russian manufacturers, who are just
as good as their foreign colleagues in terms of the quality and quantity of viruses
detected, are losing out to them in terms of centralized management.
1.1.5.2 Network Firewalls
In the late 1980s—early 1990s, as a result of the widespread development of computer
networks, the problem of their protection arose, which was solved with the help of
firewalls installed between the protected and unprotected networks. Starting from
conventional packet filters, these solutions have become multifunctional complexes
aimed at solving a multitude of tasks—from firewalling and load balance to controlling bandwidth and managing dynamic addresses. Also, a firewall may have a built-in
