1.6 Typical Examples of Viruses and Trojans
69
So, in the fight against Trojans, relying on the file modification timestamp and file
size is unreasonable, since they can be easily faked. The so-called file checksum is
more reliable in this respect. To calculate it, elements of a file are summed up, and
the resulting number is declared its checksum. For example, the SunOS operating
system has a special utility sum, which sends the checksum of the files listed in the
utility argument string to the standard output device (STDOUT).
However, checksums are generally quite easy to fake, too. Therefore, a special
kind of checksum calculation algorithm, called one-way hashing, is used to verify
the integrity of the computer file system.
A hashing function is called one-sided if the task of finding two arguments for
which its values coincide is difficult to solve. It follows that this function can be used
to track changes made by the attacker to the computer file system, since the attacker
cannot modify a file so that the value obtained by one-way hashing of this file would
remain unchanged.
Historically, the majority of utilities that make it possible to combat the penetration
of Trojans into a computer system by one-way hashing were created for UNIX-like
operating systems. TripWire utility is among the most convenient and efficient ones.
One-way hashing is performed using several algorithms. The found hash values of
files are stored in a special database, which, in principle, is the most vulnerable
component of the TripWire utility. Therefore, TripWire users are required to take
additional security measures in order to prevent the attacker from accessing this
database (for example, to save it on a read-only portable data storage device).
Anti-Trojan tools in the Windows operating systems (95/98/NT) traditionally
constitute a part of their antivirus software.
Logic Bombs
Logic bomb is a piece of code secretly inserted in the system, which is activated
when a certain event occurs (most often at a certain time).
For instance, a dismissed worker may leave a logic bomb on a computer that will
erase the entire contents of the disk a month after he leaves.
As a rule, such malicious logic has a destructive impact on the attacked system
up to its complete failure. Unlike viruses, logical bombs do not multiply at all or
multiply in limited amounts.
Logic bombs are always designed to attack a specific computer system. After the
system is damaged, the logical bomb is usually destroyed.
Sometimes a special class of logical bombs is distinguished—temporary bombs,
for which the trigger condition is to reach a certain point of time.
A characteristic feature of logical bombs is that their negative impacts on the
attacked system are solely of a destructive nature. Logic bombs, as a rule, are not
used for unauthorized access to the system resources. Their only task is the complete
or partial destruction of the system.
Monitors
Monitors are malicious logic intercepting certain data flows ongoing in the attacked
system. In particular, monitors include second-type password interceptors.
69
So, in the fight against Trojans, relying on the file modification timestamp and file
size is unreasonable, since they can be easily faked. The so-called file checksum is
more reliable in this respect. To calculate it, elements of a file are summed up, and
the resulting number is declared its checksum. For example, the SunOS operating
system has a special utility sum, which sends the checksum of the files listed in the
utility argument string to the standard output device (STDOUT).
However, checksums are generally quite easy to fake, too. Therefore, a special
kind of checksum calculation algorithm, called one-way hashing, is used to verify
the integrity of the computer file system.
A hashing function is called one-sided if the task of finding two arguments for
which its values coincide is difficult to solve. It follows that this function can be used
to track changes made by the attacker to the computer file system, since the attacker
cannot modify a file so that the value obtained by one-way hashing of this file would
remain unchanged.
Historically, the majority of utilities that make it possible to combat the penetration
of Trojans into a computer system by one-way hashing were created for UNIX-like
operating systems. TripWire utility is among the most convenient and efficient ones.
One-way hashing is performed using several algorithms. The found hash values of
files are stored in a special database, which, in principle, is the most vulnerable
component of the TripWire utility. Therefore, TripWire users are required to take
additional security measures in order to prevent the attacker from accessing this
database (for example, to save it on a read-only portable data storage device).
Anti-Trojan tools in the Windows operating systems (95/98/NT) traditionally
constitute a part of their antivirus software.
Logic Bombs
Logic bomb is a piece of code secretly inserted in the system, which is activated
when a certain event occurs (most often at a certain time).
For instance, a dismissed worker may leave a logic bomb on a computer that will
erase the entire contents of the disk a month after he leaves.
As a rule, such malicious logic has a destructive impact on the attacked system
up to its complete failure. Unlike viruses, logical bombs do not multiply at all or
multiply in limited amounts.
Logic bombs are always designed to attack a specific computer system. After the
system is damaged, the logical bomb is usually destroyed.
Sometimes a special class of logical bombs is distinguished—temporary bombs,
for which the trigger condition is to reach a certain point of time.
A characteristic feature of logical bombs is that their negative impacts on the
attacked system are solely of a destructive nature. Logic bombs, as a rule, are not
used for unauthorized access to the system resources. Their only task is the complete
or partial destruction of the system.
Monitors
Monitors are malicious logic intercepting certain data flows ongoing in the attacked
system. In particular, monitors include second-type password interceptors.
