30
1 Information Weapon: Concepts, Means, Methods …
Fig. 1.6 Classification of remote network attacks [6]
Based on various criteria, remote network attacks can be classified as follows
(Fig. 1.6) [1].
1. By nature of the impact, all attacks can be divided into two categories [15, 16]:
– Passive impact;
– Active impact.
Passive ITI does not directly affect the operation of an information system,
remaining largely hidden, but may violate its security policy. It is the absence of
a direct impact on the functioning of the information system under attack that makes
passive network attacks extremely difficult to detect. A textbook example of a passive
remote network attack is communication channel monitoring.
Active impact directly concerns the functioning of an information system (system
configuration change, malfunction, etc.) and violates its security policy.
Almost all known types of remote network attacks are active. An obvious feature
of active impact, as opposed to the passive one, is the fundamental possibility of its
detection. As a result of its implementation, certain destructive changes occur in the
information system.
2. By impact on the information security properties [15, 16]:
– Interception of information—breach of confidentiality of the system information resources;
– Distortion of information—violation of integrity of the system information
resources;
– System malfunction—information resources accessibility violation.
1 Information Weapon: Concepts, Means, Methods …
Fig. 1.6 Classification of remote network attacks [6]
Based on various criteria, remote network attacks can be classified as follows
(Fig. 1.6) [1].
1. By nature of the impact, all attacks can be divided into two categories [15, 16]:
– Passive impact;
– Active impact.
Passive ITI does not directly affect the operation of an information system,
remaining largely hidden, but may violate its security policy. It is the absence of
a direct impact on the functioning of the information system under attack that makes
passive network attacks extremely difficult to detect. A textbook example of a passive
remote network attack is communication channel monitoring.
Active impact directly concerns the functioning of an information system (system
configuration change, malfunction, etc.) and violates its security policy.
Almost all known types of remote network attacks are active. An obvious feature
of active impact, as opposed to the passive one, is the fundamental possibility of its
detection. As a result of its implementation, certain destructive changes occur in the
information system.
2. By impact on the information security properties [15, 16]:
– Interception of information—breach of confidentiality of the system information resources;
– Distortion of information—violation of integrity of the system information
resources;
– System malfunction—information resources accessibility violation.
