68
1 Information Weapon: Concepts, Means, Methods …
the H.O.P.E. server, a bug of the D.I.R.T. system is automatically generated and
provided with a unique code for identifying and locating the client. All bug movements are recorded in the server log. Thus, it is difficult to predict the scope of
D.I.R.T. distribution.
Even network firewalls do not interfere with D.I.R.T. Bypass protection is achieved
through the use of AntiSec technology. AntiSec is designed to search for all known
firewalls and their invisible neutralization.
1.6.3 Ways to Detect Trojans
Most software tools designed to protect against Trojans use the so-called object
matching to a varying degree. In this case, files and directories appear as objects, and
matching is a way to find out if they have changed since the last check. In the course
of matching, the characteristics of objects are compared with the characteristics
they had before. For example, an archive copy of a system file and its attributes are
compared with the attributes of the file, which is currently on the hard drive. If no
changes have been made to the operating system but the attributes are different, then
the computer is most certainly infected.
One of the attributes of any file is its last modification timestamp: whenever a file is
opened, modified, and saved on a drive, the corresponding changed are automatically
made. However, it cannot serve as a reliable indicator of the presence of a Trojan in
the system. The thing is that timestamps are easily manipulated. The system clock
can be adjusted to show earlier time and set back to normal after making changes to
the file. The file modification timestamp will remain unchanged.
The same concerns the file size. The size of a text file that originally occupied
8 KB of the disk space often remains unchanged after editing and saving. Binary files
behave somewhat differently. It is not easy to insert a piece of your own code into
someone else’s software so that its working capacity and size remained unchanged
after compilation. Therefore, file size is a more reliable indicator of the most recent
changes to it as compared to timestamp.
To introduce a Trojan into the system, an attacker usually tries to make it part of
the system file. Such files are included in the operating system distribution, and their
presence on any computer where this operating system is installed does not raise
suspicions. However, any system file has a certain length. If this attribute is modified
in any way, it will alarm the user.
Knowing this, the attacker will try to get the source code of the corresponding
program and carefully analyze it for redundant elements that can be removed without
any appreciable damage.
Then he will replace the detected redundant elements with a Trojan and perform
a recompilation. If the resulting binary file is smaller or larger than the original one,
the attacker will repeat the procedure. And so on until the final file is obtained, whose
size is the closest to the original one (if the source file is large enough, this process
may take several days).
Précédent

- 90/839

Suivant