38
1 Information Weapon: Concepts, Means, Methods …
features inherent in specific types of executable files. In this case, two different types
of code modification by purpose are distinguished [1]:
– Introduction of viruses in the transmitted code;
– Change in the logic of the executable code.
When viruses are introduced into the transmitted code, the virus body is added to
the executable file, and the starting point of the code execution changes to indicate
the beginning of the embedded virus code. The described method is essentially the
same as the standard infection of an executable file with a virus, except that the file
is infected with a virus at the time of its transmission over the network! This is only
possible in case of “false object introduction.”
A similar modification of the executable code occurs when the logic of the
executable file is changed at the time of its transfer over the network. However,
its goal is an algorithmic impact aimed at the introduction of malicious logic, adding
additional vulnerabilities or exploits to the executable file. The complexity of this
impact is that, as a rule, it requires a preliminary study of the logic of the executable
file [1].
Introduction of a false object, along with modifications, provides for a possibility
to replace the information intercepted by it. If a certain event occurs on the network
controlled by a false object, previously prepared misinformation is sent to one of the
participants of the exchange. At the same time, depending on the monitored event,
such misinformation can be either an executable code or data.
1.4.3.1 Denial-of-Service Attack
In general, each NIS subject shall be able to connect to any object in the system and
receive, in accordance with their rights, remote access to its information resources.
As a rule, the possibility of providing remote access in network information systems
is implemented as follows: a number of server programs (for instance, an FTP server,
a WWW server, etc.) are launched, providing remote access to the resources of the
corresponding system object. If a connection request is received, the server shall, if
possible, send a response to the requesting object, either allowing the connection or
not. Obviously, the server is able to respond to a limited number of requests. These
restrictions depend on the parameters of the information system, the capacity of its
network and the speed of the computer, where it operates.
The denial-of-service attack is aimed at blocking access to an object by sending
a large number of requests, exhausting its resources.
1 Information Weapon: Concepts, Means, Methods …
features inherent in specific types of executable files. In this case, two different types
of code modification by purpose are distinguished [1]:
– Introduction of viruses in the transmitted code;
– Change in the logic of the executable code.
When viruses are introduced into the transmitted code, the virus body is added to
the executable file, and the starting point of the code execution changes to indicate
the beginning of the embedded virus code. The described method is essentially the
same as the standard infection of an executable file with a virus, except that the file
is infected with a virus at the time of its transmission over the network! This is only
possible in case of “false object introduction.”
A similar modification of the executable code occurs when the logic of the
executable file is changed at the time of its transfer over the network. However,
its goal is an algorithmic impact aimed at the introduction of malicious logic, adding
additional vulnerabilities or exploits to the executable file. The complexity of this
impact is that, as a rule, it requires a preliminary study of the logic of the executable
file [1].
Introduction of a false object, along with modifications, provides for a possibility
to replace the information intercepted by it. If a certain event occurs on the network
controlled by a false object, previously prepared misinformation is sent to one of the
participants of the exchange. At the same time, depending on the monitored event,
such misinformation can be either an executable code or data.
1.4.3.1 Denial-of-Service Attack
In general, each NIS subject shall be able to connect to any object in the system and
receive, in accordance with their rights, remote access to its information resources.
As a rule, the possibility of providing remote access in network information systems
is implemented as follows: a number of server programs (for instance, an FTP server,
a WWW server, etc.) are launched, providing remote access to the resources of the
corresponding system object. If a connection request is received, the server shall, if
possible, send a response to the requesting object, either allowing the connection or
not. Obviously, the server is able to respond to a limited number of requests. These
restrictions depend on the parameters of the information system, the capacity of its
network and the speed of the computer, where it operates.
The denial-of-service attack is aimed at blocking access to an object by sending
a large number of requests, exhausting its resources.
