1.3 Definition and Classification of Information Technology Impacts
25
– Means of cryptographic protection;
– Means of creating false objects and resources in the information space under
protection.
In relation to the latest developments of offensive information weapons, the
most developed are special software and mathematical algorithms combining the
capabilities of algorithmic and software information weapons.
Special software and mathematical algorithms are generally represented by a
software system capable of performing any subset of the following basic functions
[7, 14]:
– Hide their presence in the hardware and software environment of the information
system;
– Destroy (distort) program codes in the information system memory;
– Self-copy, associate themselves with other programs, and/or transfer their
fragments to other areas of the RAM or external memory;
– Suppress information exchange in telecommunications networks, falsify information transmitted through control channels;
– Save fragments of information from the information system memory in a certain
area of external direct access memory (local or remote);
– Distort, block, and/or replace the array of information removed to the external
storage device or communication channel, appearing as a result of the operation
of application programs (or data arrays that are already on the external storage
device);
– Counteract the operation of tests and information resource protection systems.
The main means of ITI classified by way of implementation include as follows.
(1) Algorithmic (offensive) means of impact:
– Exploits targeting an information system management program (operating
system nucleus or modules, drivers, BIOS);
– Exploits aimed at getting an information system or a technological system
managed by it into abnormal or technologically dangerous modes of operation (for instance, the Stuxnet virus implemented in the uranium enrichment
process automated control system, due to interception and modification of
commands);
– Exploits targeting information system applications (user applications, server
applications, network applications, browsers);
– Exploits targeting information system network protocols;
(2) Software means of impact:
– Offensive:
Computer viruses;
Malicious logic;
Neutralizers of tests and code analysis software;
Précédent

- 47/839

Suivant