20
1 Information Weapon: Concepts, Means, Methods …
Successful use of the means to penetrate security systems provides for effective
impacts on the information stored, processed, and transmitted in the system using
offensive information technology weapons.
Although this has nothing to do with the subject of the book, it is worth mentioning
the means of information support to conduct operations in other areas. Such means
are represented not by automated control systems and various types of automation
systems, but by different kinds of complexes for combat simulation widely used by
the military all over the world, which make it possible to find an optimal composition
of forces and means, as well as an optimal strategy for any plausible action scenario
of the adversary, using multiple simulation runs.
Offensive information weapons are weapons that produce an effect on the information stored, processed, and transmitted in the system, violating the information
technologies used in this system [7].
In turn, there are four main types of offensive information weapons [7]:
– Means of violating information confidentiality;
– Means of violating information integrity;
– Means of violating information accessibility;
– Psychological effects on the information system users.
The use of offensive information weapons is aimed at disrupting the implementation of the information system’s target tasks.
Generally, offensive information weapons comprise the following components
forming a single system [11]:
– Means of weapons delivery;
– Means of entering the subsystem of the attacked system;
– Actual load.
By way of implementation, information weapons can be divided into the following
classes [7, 12]:
– Algorithmic;
– Software;
– Hardware;
– Physical.
Information weapons belonging to different classes can be used simultaneously.
Algorithmic information weapons include [7] as follows:
– Algorithms using a combination of authorized actions and authorized (legal)
software to produce an unauthorized effect on information resources;
– Algorithms using unauthorized means (of other information technology
weapons—software, hardware, physical) to produce an unauthorized effect on
information resources;
– Combined algorithms consisting of different algorithms of the previous two types.
An exploit is a type of algorithmic weapon—a potentially non-malicious data set
(for instance, an authorized sequence of commands, a graphic file or a non-standard
1 Information Weapon: Concepts, Means, Methods …
Successful use of the means to penetrate security systems provides for effective
impacts on the information stored, processed, and transmitted in the system using
offensive information technology weapons.
Although this has nothing to do with the subject of the book, it is worth mentioning
the means of information support to conduct operations in other areas. Such means
are represented not by automated control systems and various types of automation
systems, but by different kinds of complexes for combat simulation widely used by
the military all over the world, which make it possible to find an optimal composition
of forces and means, as well as an optimal strategy for any plausible action scenario
of the adversary, using multiple simulation runs.
Offensive information weapons are weapons that produce an effect on the information stored, processed, and transmitted in the system, violating the information
technologies used in this system [7].
In turn, there are four main types of offensive information weapons [7]:
– Means of violating information confidentiality;
– Means of violating information integrity;
– Means of violating information accessibility;
– Psychological effects on the information system users.
The use of offensive information weapons is aimed at disrupting the implementation of the information system’s target tasks.
Generally, offensive information weapons comprise the following components
forming a single system [11]:
– Means of weapons delivery;
– Means of entering the subsystem of the attacked system;
– Actual load.
By way of implementation, information weapons can be divided into the following
classes [7, 12]:
– Algorithmic;
– Software;
– Hardware;
– Physical.
Information weapons belonging to different classes can be used simultaneously.
Algorithmic information weapons include [7] as follows:
– Algorithms using a combination of authorized actions and authorized (legal)
software to produce an unauthorized effect on information resources;
– Algorithms using unauthorized means (of other information technology
weapons—software, hardware, physical) to produce an unauthorized effect on
information resources;
– Combined algorithms consisting of different algorithms of the previous two types.
An exploit is a type of algorithmic weapon—a potentially non-malicious data set
(for instance, an authorized sequence of commands, a graphic file or a non-standard
