40
1 Information Weapon: Concepts, Means, Methods …
and sent to the information system or its network equipment, to ensure the
system failure because of the exhaustion of its resources (CPU time, memory,
communication channel capacity). The most common means include [17]:
– HTTP flood, ping flood attacks and the like;
– Smurf attack (ICMP flood);
– TCP connection SYN flood attacks.
2. Methods based on the lack of system resources—attacks related to the capture or
excessive use of information system resources. The most common means include
[17]:
– Sending “heavy” or “complex” packages;
– Server overflow with log files;
– Use of vulnerabilities of improperly configured subsystem for resource quota
management;
– Use of insufficient verification of data authenticity vulnerability;
– Attacks causing false response to the information system protection
subsystem.
3. Means based on remote unauthorized access due to the use of exploits in the
software of the system under attack. The most common means include [17]:
– Remote use of “vulnerabilities” in the program code of the operating system
and application software of the information system;
– Remote use of program buffer overflow;
– Remote use of errors in memory sharing in the OS protective mode.
4. Means based on the use of network protocol exploits of the system under attack.
The most common means include:
– DoS attacks using vulnerabilities in DNS server software;
– DDoS attacks targeting DNS servers.
Denial-of-service attacks are not only the most common, but also the most
dangerous impacts. Thus, in November 2002, a global DDoS attack on root DNS
servers was conducted in order to completely block the public Internet segment. As
a result, the attackers managed to disable 7 of the 13 root DNS servers.
1.5 Technical Channels of Information Leakage
1.5.1 Classification and Principles of Operation
In general, information is understood as various data (messages, facts) regardless of
representation.
1 Information Weapon: Concepts, Means, Methods …
and sent to the information system or its network equipment, to ensure the
system failure because of the exhaustion of its resources (CPU time, memory,
communication channel capacity). The most common means include [17]:
– HTTP flood, ping flood attacks and the like;
– Smurf attack (ICMP flood);
– TCP connection SYN flood attacks.
2. Methods based on the lack of system resources—attacks related to the capture or
excessive use of information system resources. The most common means include
[17]:
– Sending “heavy” or “complex” packages;
– Server overflow with log files;
– Use of vulnerabilities of improperly configured subsystem for resource quota
management;
– Use of insufficient verification of data authenticity vulnerability;
– Attacks causing false response to the information system protection
subsystem.
3. Means based on remote unauthorized access due to the use of exploits in the
software of the system under attack. The most common means include [17]:
– Remote use of “vulnerabilities” in the program code of the operating system
and application software of the information system;
– Remote use of program buffer overflow;
– Remote use of errors in memory sharing in the OS protective mode.
4. Means based on the use of network protocol exploits of the system under attack.
The most common means include:
– DoS attacks using vulnerabilities in DNS server software;
– DDoS attacks targeting DNS servers.
Denial-of-service attacks are not only the most common, but also the most
dangerous impacts. Thus, in November 2002, a global DDoS attack on root DNS
servers was conducted in order to completely block the public Internet segment. As
a result, the attackers managed to disable 7 of the 13 root DNS servers.
1.5 Technical Channels of Information Leakage
1.5.1 Classification and Principles of Operation
In general, information is understood as various data (messages, facts) regardless of
representation.
