1.4 Most Common Means of Information Technology Impact
39
There are three types of remote attacks like this.
1. Denial-of-service attack (DoS attack)—sending as many requests to the target
object from the same address as the bandwidth communication channel is able to
transfer. In this case, if there are no rules limiting the number of requests received
from one object (address) of the system, the result of this attack may be either a
request queue overflow and a failure of one of the telecommunications services,
or a complete blocking of the object, due to the system overload preventing it
from fulfilling other tasks except for query processing.
2. Distributed denial-of-service attack (DDoS attack)—sending an infinite number
of connection requests from several system objects to the target object, on their
behalf or not. The result of applying this remote attack is malfunction of the
corresponding remote access service on the target object, i.e., inability to obtain
remote access from other objects of the network information system.
3. Request processing looping—sending an incorrect, specially selected request to
the target object. In this case, if there are errors in the remote system, a buffer
overflow with subsequent system hang may occur.
Remote network DoS attack is classified as an active impact, implemented in
order to disrupt the system, unconditional in relation to its target object. This attack
is a forward only, either intranet or Internet. It is carried out at the transport and
application layers of the OSI model [1].
The most common means to launch a denial-of-service attack are as follows
(Fig. 1.8).
1. Means based on the system bandwidth saturation—attacks are associated with a
large number of meaningless requests or requests made in the wrong format
Fig. 1.8 The most common means to launch a denial-of-service attack
Précédent

- 61/839

Suivant