1.4 Most Common Means of Information Technology Impact
37
send a search query, and then his false response will be immediately accepted and
processed. This remote attack is extremely common in global networks, when an
attacker simply cannot intercept a search query being in another network segment in
relation to the target object.
Introduction of a false object by using the disadvantages of the addressing algorithms and remote search for nodes in the network is an active impact aimed at
violating the confidentiality and integrity of information, which can be an attack at
the request of the target object, as well as an ultimate attack. This remote attack can
be both intranet and Internet, with a feedback channel between the attacker and the
target object. It is carried out on the data link, network, and application layers of the
OSI model [1].
1.4.3 Using a False Object to Organize a Remote Attack
After introducing a false object into the network and gaining control over the information flow through the network, the false object can be used to make different
impacts on the intercepted information. There are the following main impacts on
information intercepted by a false object [1]:
– Selection of information with its subsequent saving on a false network object;
Modification of information passing through a false network object;
Substitution of information passing through a false network object.
Selection of information with its subsequent saving on a false network object is a
passive network attack similar to the “network traffic analysis” attack with a dynamic
semantic analysis performed on a false object. However, the possibility of using a
false object to modify or replace information is the most interesting.
There are two main types of information modification [1]:
– Transmitted data modification;
– Transmitted code modification:
Introduction of viruses in the transmitted code;
Change in the logic of the executable code.
To modify the transmitted data on the introduced object, selected analysis of
the intercepted information flow is carried out. In this case, the type of transferred
files (executable file or data file) can be recognized. When a data file is detected,
these data can be modified when they pass through the false object. Moreover, if
data modification is a standard impact, modifications of the transmitted code require
special attention.
A false object, conducting a semantic analysis of information passing through it,
can distinguish files containing executable code in the flow. To determine whether a
code or data is being transmitted over a network, it is necessary to recognize certain
Précédent

- 59/839

Suivant