1.3 Definition and Classification of Information Technology Impacts
29
This cyberattack had several active phases at random intervals of time, which led to
the breakdown of a considerable number of centrifuges.
To handle emergencies, Iranian specialists, who associated them with the
poor quality of centrifuges, replaced some operators and all equipment at the
Natanz uranium enrichment facility, reequipping it with new generation centrifuges.
However, the Americans and the Israelis developed a new version of the Stuxnet
worm, which was introduced into the laptop of an Iranian nuclear physicist. When
connected to the computer network of the facility, it spread on the centrifuge
controllers. Later on, when the physicist connected his laptop to the Internet, the
newly modified Stuxnet worm “broke free” and began to reproduce itself in other
computers all over the world. And when it found Siemens controllers in a computer
network, it activated and cybersabotaged their operation.
During 2010–2013, this worm infected many computers using the WINDOWS
operating system in different countries of the world, until its activity was limited by
the joint efforts of experts.
1.4 Most Common Means of Information Technology
Impact
1.4.1 Remote Network Attacks
1.4.1.1 Definition and Classification of Remote Network Attacks
Taking into account the definition and classification of remote impacts on distributed
systems given in [6, 16], this type of impact can be defined as follows.
A remote network attack is a destructive or destabilizing ITI carried out through
communication channels by a subject located at a distance from the system under
attack and characteristic of structurally and spatially distributed information systems.
Remote network attacks are possible due to the “vulnerabilities” in existing data
exchange protocols and in the protection subsystems of the distributed information
systems. At the same time, the main known “vulnerabilities” of information systems
allowing for successful remote network attacks are [15, 16] as follows:
– Untimely tracking and implementation of recommendations of experts on the
protection and analysis of intrusion cases to eliminate exploits and software errors;
– Information system openness, free access to the information on networking
cooperation, methods of protection used in the system;
– Errors in operating systems, application software, network communication
protocols;
– The used software is unsuitable for the operating system;
– System configuration and protection errors;
– Low quality safety-related systems (or absence of such).
Précédent

- 51/839

Suivant