10
1 Information Weapon: Concepts, Means, Methods …
known as hybrid attacks and include all the recent high-profile epidemics—Code
Red, Nimda, SQL Slammer, Blaster, MyDoom, etc. Attack detection technology is
designed as a means of protection. However, the history of this technology began
much earlier—in 1980, when James Anderson suggested using event logs to detect
unauthorized actions. It took another 10 years to move from the analysis of event
logs to the analysis of network traffic for signs of attacks.
Over time, the situation has changed somewhat: it was necessary not only to
detect attacks, but also to block them before they reached their goal. Thus, attack
detection systems made a logical step forward and, combining the familiar firewall
technologies, began to pass all network traffic (to protect a network segment) or
system calls (to protect an individual node), which made it possible to completely
block the detected attacks.
Then the history repeated itself: personal systems were designed to protect workstations and mobile computers, and a natural merger of personal firewalls, attack
detection systems, and antiviruses became almost an ideal solution for computer
protection.
1.1.5.5 Security Scanners
It is a known fact that a fire is easier to prevent than to put out. The same is true
about information security: instead of fighting attacks, it’s much better to eliminate
the vulnerabilities prone to them. In other words, it is necessary to detect all vulnerabilities and fix them before the attackers discover them. This is achieved through
security scanners (also called security analysis systems), which work both at the
network level and at the level of an individual node. The first scanner looking for
“holes” in the UNIX operating system was COPS, developed by Eugene Spafford
in 1991, and the first network scanner was Internet Scanner, created by Christopher
Klaus in 1993.
Currently, there is a gradual integration of attack detection systems and security
scanners, which makes it possible to detect and block attacks completely automatically, focusing the operator’s attention on more important activities. The integration
consists in the following: the scanner that detects the hole commands the detection
sensor to track the corresponding attack, and vice versa; the sensor that detects the
attack issues a command to scan the attacked node.
Internet Security Systems, Cisco Systems, and Symantec are the market leaders
in attack detection and security scanners. There are Russian developers, who have
decided to challenge their more eminent foreign colleagues. One of them is Positive
Technologies, which released the first Russian security scanner—XSpider.
Précédent

- 32/839

Suivant