4.1 Basis of Designing Safe Electronic …
283
the growth in the level of complexity and the relative frequency of observations of
various kinds of attacks on existing network and local banking management systems,
industrial production management systems, data channels, social networks, etc. over
time.
Of course, such visualization of this process is extremely conventional. In this
fairly primitive picture, the analyst attempted to present a graphic solution to the
problem of determining interconnection between the security level of modern information and telecommunication devices and the list of various sophisticated attacks
attempted by various intruders over more than 30 years of observation or, to be
precise, between 1980 and 2008.
If at the beginning of this criminal era, simplest hacker attacks started with simply
guessing passwords and then hacking passwords, just a couple years later they came
to the process that was absolutely unimaginable at the time—interception of communication sections, introduction of standard (as far as the users believed) diagnostics
into network management; later, generation of malicious automatic text messages
appeared together with targeted and distributed attacks in social media, etc.
As can be seen from the picture, 1980 marked the emergence of denial-of-service
(DoS) hacker attacks and so-called distributed and targeted attacks in social media;
thus, experts in security of microelectronic devices and critical systems based on
these devices clearly realize that all of them undoubtedly were in the zone of risk,
and that this zone is constantly expanding.
It is 2008 that can be considered the year when researches first openly spoke about
future hazards of a new type based not on software implants, viruses, and worms
described in Chap. 2 or other software means known at the moment, but on hardware
Trojans as specially implemented malicious circuits introduced into systems and
their components.
The same year, the competition called Embedded Systems Challenge was organized in the NYU Polytechnic University within the framework of the conference
Computer Security Awareness Week (CSAW). Dozens of student teams taking part
in this challenge tried to play the part of such intruder who needs to solve all his
malicious tasks (downloading or replacing secret keys and data, altering functions of
the device, destroying the device, etc.) by means of introducing a hardware Trojan
into the designed military-purpose device.
The results of this seemingly usual student research turned out to be so unexpected
for special services (who were actually the initiators of the challenge), and it was
decided not to conduct similar open contests in such format.
To sum the main results of this challenge up, almost all teams hacked the protection
of the military device with relative ease, developed deeply hidden hardware Trojans,
and embedded them into the device, which actually meant that the enemy got full
control over the control system of the US military units with the expected results.
In particular, as far as we believe, this fact was also used by the administration of
the North Korean in adoption of the final decision to create a special department of
cyberoperations in the structure of the ministry of defence, which at the moment of
publication of this book already included four to six (according to different sources)
283
the growth in the level of complexity and the relative frequency of observations of
various kinds of attacks on existing network and local banking management systems,
industrial production management systems, data channels, social networks, etc. over
time.
Of course, such visualization of this process is extremely conventional. In this
fairly primitive picture, the analyst attempted to present a graphic solution to the
problem of determining interconnection between the security level of modern information and telecommunication devices and the list of various sophisticated attacks
attempted by various intruders over more than 30 years of observation or, to be
precise, between 1980 and 2008.
If at the beginning of this criminal era, simplest hacker attacks started with simply
guessing passwords and then hacking passwords, just a couple years later they came
to the process that was absolutely unimaginable at the time—interception of communication sections, introduction of standard (as far as the users believed) diagnostics
into network management; later, generation of malicious automatic text messages
appeared together with targeted and distributed attacks in social media, etc.
As can be seen from the picture, 1980 marked the emergence of denial-of-service
(DoS) hacker attacks and so-called distributed and targeted attacks in social media;
thus, experts in security of microelectronic devices and critical systems based on
these devices clearly realize that all of them undoubtedly were in the zone of risk,
and that this zone is constantly expanding.
It is 2008 that can be considered the year when researches first openly spoke about
future hazards of a new type based not on software implants, viruses, and worms
described in Chap. 2 or other software means known at the moment, but on hardware
Trojans as specially implemented malicious circuits introduced into systems and
their components.
The same year, the competition called Embedded Systems Challenge was organized in the NYU Polytechnic University within the framework of the conference
Computer Security Awareness Week (CSAW). Dozens of student teams taking part
in this challenge tried to play the part of such intruder who needs to solve all his
malicious tasks (downloading or replacing secret keys and data, altering functions of
the device, destroying the device, etc.) by means of introducing a hardware Trojan
into the designed military-purpose device.
The results of this seemingly usual student research turned out to be so unexpected
for special services (who were actually the initiators of the challenge), and it was
decided not to conduct similar open contests in such format.
To sum the main results of this challenge up, almost all teams hacked the protection
of the military device with relative ease, developed deeply hidden hardware Trojans,
and embedded them into the device, which actually meant that the enemy got full
control over the control system of the US military units with the expected results.
In particular, as far as we believe, this fact was also used by the administration of
the North Korean in adoption of the final decision to create a special department of
cyberoperations in the structure of the ministry of defence, which at the moment of
publication of this book already included four to six (according to different sources)
