34
1 Information Weapon: Concepts, Means, Methods …
– DoS attacks are divided into the following types:
Denial-of-service attack (DoS attack);
Distributed denial-of-service attack (DDoS attack);
Request processing looping.
1.4.2.1 Network Traffic Analysis
The main feature of the network information system is that its elements are distributed
in space and the connection between them is established over the network. Thus,
messages and data are transmitted between different elements of the information
system via communication channels in the form of packets. This feature led to the
emergence of a remote impact characteristic of a network information system, which
consists in communication channel monitoring. This impact is known as network
traffic analysis.
Based on the results of the network traffic analysis, the attacker can [1].
– Study the logic of the network information system, i.e., obtain a one-to-one correspondence between events occurring in the system, commands, and data transmitted using the system elements at the moment of their occurrence. This is
achieved by intercepting and analyzing network traffic packets. Knowledge of
the logic of the information system allows one to simulate and implement other
remote network attacks;
– Intercept the flow of data between the elements of the network information system.
Thus, this attack consists in receiving unauthorized access to the remote object
information, which is exchanged between two network subscribers. Note that
in this case there is no possibility for traffic modification, while the analysis
is possible only within one network segment. Username and password sent in
unencrypted form over the network are examples of information intercepted using
a typical remote attack.
In accordance with the above classification, network traffic analysis is a passive
impact. Carried out without feedback, this attack leads to a breach of information
confidentiality within a single network segment at the data link and network layers.
Moreover, the beginning of an attack is unconditional in relation to its target [15, 16].
1.4.2.2 Substitution of a Trusted Entity of the Information System
One of the security problems of a network information system is inadequate identification and authentication of its objects located at a distance from each other. The
main difficulty consists in the unambiguous identification of messages transmitted
between subjects and objects of interaction. As a rule, this problem of network
information systems is solved as follows: by creating a logical circuit, system entities exchange certain information uniquely identifying this circuit. However, this
exchange is not mandatory. When transmitting proprietary and address information
Précédent

- 56/839

Suivant