36
1 Information Weapon: Concepts, Means, Methods …
– Introduction of a false object by imposing a false network route;
– Introduction of a false object using faults of addressing algorithms and remotely
searching for hosts:
By intercepting and forming a false response to the host address request;
By forming a flow of false responses with no requests from hosts.
Modern global networks are a collection of network segments that are interconnected through nodes and routers. Each router has a special routing table, where an
optimal route is indicated for each pair of destination stations. The main purpose of
the attack related to the introduction of a false object by imposing a false route is to
change the original routing of the NIS object so that the new route passes through the
false network object—the attacker’s node. The attack consists in an unauthorized use
of network management protocols to modify the original routing tables. This attack
is carried out in two stages.
1. The attacker shall send special signal messages over the network using network
controllers (for instance, routers), which will lead to rerouting. As a result
of successful rerouting, the attacker gains complete control over the flow of
information passing through the corresponding node.
2. Thus, the attacker increases the amount of traffic redirected through the node and
now can receive, analyze, and send messages transmitted over the network.
The introduction of a false object by imposing a false network route is an active
impact, unconditional with respect to the target object. This remote attack can be
carried out both within a single network segment and by means of Internetworking
with/without a feedback channel between the attacker and the target object at the
network, transport, and application layers.
As is often the case in a distributed information system, its remote objects initially
do not have enough information necessary to address the transmitted messages. As
a rule, such information is represented by hardware and logical addresses of the
system objects. To obtain such information, distributed systems use various remote
search algorithms, which consist in transmitting special search requests over the
network. The requesting subject of the system, who has received a response to the
request, has all the necessary data for addressing. Guided by the obtained information
about the object of interest, the requesting subject of the system starts information
transmission. ARP and DNS requests on the Internet are examples of such requests,
which serve as the basis for remote search algorithms.
If remote search engines are used in a distributed information system, there
is a possibility for the attacker to intercept the request and send a false reply to
it, containing the data whose use will lead to forwarding to the attacker’s false
node. Further, the entire flow of information between the subject and the object
of interaction will pass through this false object of the information system.
Another option for introducing a false object into the distributed information
system uses the disadvantages of the remote network search algorithm and consists
in sending a previously prepared false response to the target object from time to
time, without a search query. Moreover, the attacker can provoke the target object to
Précédent

- 58/839

Suivant