1.4 Most Common Means of Information Technology Impact
31
Interception of information means getting access to it, but usually there is no
possibility of its modification. Consequently, interception of information leads to a
violation of its confidentiality: an unauthorized access to information is provided
without the possibility of its distortion. It is clear that a breach of confidentiality
is a passive network attack. An example of an attack related to the interception of
information is network channel monitoring (video and audio).
Distortion of information means either complete control over the information
flow between elements of a distributed system, or the ability to transmit messages
on behalf of another person. In any case, such distortion of information leads to
a violation of the integrity of the system information resources. An example of a
remote network attack, aimed at violating the integrity of information resources, can
be an attack related to the introduction of a false network object into the system, for
instance, a false DNS server.
As a rule, an attacker aiming at the system malfunction does not plan to obtain
unauthorized access to information. The goal is to ensure the failure of the elements of
a distributed information system on the target object. As a result, access to information
resources of the target object would be impossible for the entire system. An example
of a remote attack aimed at the system malfunction is a DoS attack.
3. By conditions of beginning of impact [15, 16]:
– Attack at the request of the target object;
– Attack upon occurrence of an expected event on the target object;
– Ultimate attack.
In the event of an attack at the request of the target object, the attacker expects
a corresponding request, which is a necessary condition for the start of operation.
DNS and ARP requests are examples of such requests. It is important to note that
remote attacks of this type are most characteristic of distributed network information
systems.
When attacking upon occurrence of an expected event, the attacker monitors the
state of the target information system. Upon occurrence of an expected event the
system must be attacked at once. As in the previous case, the system under attack
is the initiator of the attack. Such network attacks are quite common. One of them
is an attack related to unauthorized access to information resources of a computer
over the network following its infection with a backdoor—a virus creating additional
“vulnerabilities” in the protection subsystem.
An ultimate attack is carried out immediately and irrespective of the state of the
information system and that of the target object. Therefore, in this case, the attacker
is the initiator of the launch of attack.
4. By presence/absence of a feedback channel with the target object [15, 16]:
– With feedback;
– Without any feedback (forward only attack).
A remote network attack with feedback from the target object means that the
attacker shall receive replies to some of the requests sent to the target object.
31
Interception of information means getting access to it, but usually there is no
possibility of its modification. Consequently, interception of information leads to a
violation of its confidentiality: an unauthorized access to information is provided
without the possibility of its distortion. It is clear that a breach of confidentiality
is a passive network attack. An example of an attack related to the interception of
information is network channel monitoring (video and audio).
Distortion of information means either complete control over the information
flow between elements of a distributed system, or the ability to transmit messages
on behalf of another person. In any case, such distortion of information leads to
a violation of the integrity of the system information resources. An example of a
remote network attack, aimed at violating the integrity of information resources, can
be an attack related to the introduction of a false network object into the system, for
instance, a false DNS server.
As a rule, an attacker aiming at the system malfunction does not plan to obtain
unauthorized access to information. The goal is to ensure the failure of the elements of
a distributed information system on the target object. As a result, access to information
resources of the target object would be impossible for the entire system. An example
of a remote attack aimed at the system malfunction is a DoS attack.
3. By conditions of beginning of impact [15, 16]:
– Attack at the request of the target object;
– Attack upon occurrence of an expected event on the target object;
– Ultimate attack.
In the event of an attack at the request of the target object, the attacker expects
a corresponding request, which is a necessary condition for the start of operation.
DNS and ARP requests are examples of such requests. It is important to note that
remote attacks of this type are most characteristic of distributed network information
systems.
When attacking upon occurrence of an expected event, the attacker monitors the
state of the target information system. Upon occurrence of an expected event the
system must be attacked at once. As in the previous case, the system under attack
is the initiator of the attack. Such network attacks are quite common. One of them
is an attack related to unauthorized access to information resources of a computer
over the network following its infection with a backdoor—a virus creating additional
“vulnerabilities” in the protection subsystem.
An ultimate attack is carried out immediately and irrespective of the state of the
information system and that of the target object. Therefore, in this case, the attacker
is the initiator of the launch of attack.
4. By presence/absence of a feedback channel with the target object [15, 16]:
– With feedback;
– Without any feedback (forward only attack).
A remote network attack with feedback from the target object means that the
attacker shall receive replies to some of the requests sent to the target object.
