1.4 Most Common Means of Information Technology Impact
35
on the network, single messages not requiring confirmation are often used. Since it
is easy to fake a network address, it can be used to virtually substitute a trusted entity
of the information system. Thus, when unstable algorithms are used in the network
to identify remote entities, a remote attack, namely, replacing a trusted entity of the
information system, consisting in transmitting messages over the network on behalf
of an arbitrary entity of the information system, may be carried out.
There are two types of this network attack, depending on the information
security policy adopted in the system and the approach to protecting network
connections [1]:
– Attack when an established virtual circuit;
– Attack without a virtual circuit.
If virtual circuits are established in a network for a data exchange session, the
attack will consist in assigning the rights of a trusted entity of network interaction
legally connected to the system object. This will enable the attacker to conduct
a session with the information system object on behalf of the trusted entity. Such
remote attacks generally consist in the transfer of exchange packets from the attacking
object to the target object on behalf of the trusted entity facilitating interaction (the
transmitted messages will be perceived by the system as correct). However, to carry
out an attack of this type, one should penetrate into the system of network message
identification and authentication.
An attack on an information system without a virtual circuit consists in the transmission of signal messages on behalf of network control devices, such as routers. In
this case, it is possible to fake the sender’s network address. For instance, a remote
attack is carried out through imposition of a false route by sending fake address
messages [15, 16]. This type of attack can be classified as an active impact upon
occurrence of an expected event on the target object. Its goal is to violate the confidentiality and integrity of information. Such remote attack can be both intranet and
Internet, with or without feedback to the target object. It is carried out at the network
and transport layers of the OSI model.
1.4.2.3 Introduction of a False Object in the Information System
Generally, in a distributed information system, problems of identifying network
control devices (for instance, routers) are not fully solved, in case of their interaction with the information system objects. In this case, such a distributed system
may be subject to a network attack related to a change in routing parameters and an
introduction of a false object into the network. If the network settings provide for the
interaction of objects using remote node search algorithms, the same settings can be
used to inject a false object into the system.
There are two fundamentally different ways of conducting an attack by “inserting
a false object into the information system”:
35
on the network, single messages not requiring confirmation are often used. Since it
is easy to fake a network address, it can be used to virtually substitute a trusted entity
of the information system. Thus, when unstable algorithms are used in the network
to identify remote entities, a remote attack, namely, replacing a trusted entity of the
information system, consisting in transmitting messages over the network on behalf
of an arbitrary entity of the information system, may be carried out.
There are two types of this network attack, depending on the information
security policy adopted in the system and the approach to protecting network
connections [1]:
– Attack when an established virtual circuit;
– Attack without a virtual circuit.
If virtual circuits are established in a network for a data exchange session, the
attack will consist in assigning the rights of a trusted entity of network interaction
legally connected to the system object. This will enable the attacker to conduct
a session with the information system object on behalf of the trusted entity. Such
remote attacks generally consist in the transfer of exchange packets from the attacking
object to the target object on behalf of the trusted entity facilitating interaction (the
transmitted messages will be perceived by the system as correct). However, to carry
out an attack of this type, one should penetrate into the system of network message
identification and authentication.
An attack on an information system without a virtual circuit consists in the transmission of signal messages on behalf of network control devices, such as routers. In
this case, it is possible to fake the sender’s network address. For instance, a remote
attack is carried out through imposition of a false route by sending fake address
messages [15, 16]. This type of attack can be classified as an active impact upon
occurrence of an expected event on the target object. Its goal is to violate the confidentiality and integrity of information. Such remote attack can be both intranet and
Internet, with or without feedback to the target object. It is carried out at the network
and transport layers of the OSI model.
1.4.2.3 Introduction of a False Object in the Information System
Generally, in a distributed information system, problems of identifying network
control devices (for instance, routers) are not fully solved, in case of their interaction with the information system objects. In this case, such a distributed system
may be subject to a network attack related to a change in routing parameters and an
introduction of a false object into the network. If the network settings provide for the
interaction of objects using remote node search algorithms, the same settings can be
used to inject a false object into the system.
There are two fundamentally different ways of conducting an attack by “inserting
a false object into the information system”:
