72
1 Information Weapon: Concepts, Means, Methods …
Certification tests and case studies are conducted by way of [33, 35]:
– Software functional test for compliance with regulatory and procedural documents;
– Structural (static and dynamic) analysis of software for the absence of undocumented features.
At the same time, experts in the field of testing can use additional methods and
techniques for code checking, for instance, code inspection, use of static analyzers,
study of security bulletins, stress-testing practices, etc.
In the absence of source codes of programs, reverse-engineering approaches and
functional methods (according to the black box principle) are used. The former will
be discussed in more detail in subsequent chapters.
Reverse engineering can be performed as follows [33]:
• Relaying/disassembling, run in the debug mode—for machine and procedural
languages;
• High-quality decompilation—for languages with an intermediate code.
The complexity and size of modern programs are such that special complex test
programs and code analyzers are used for certification of information system security
specialists. As a rule, they conduct dynamic analysis of software while it is running
on a real (or virtual) processor, recording the control trace and all generated data
flows.
If an adversary uses offensive weapons (for instance, malicious logic), it is necessary to ensure effective concealment. In this case, special support tools are commonly
used—the so-called neutralizers of tests and code analysis software. Their goal is
to complicate the program execution path analysis and hide the fact that malicious
software is present.
These special means of neutralizing tests and code analysis software are used
either at the stage of machine code compilation from source code or during program
execution.
The main means of test programs neutralization include (Fig. 1.36) [35–37]:
– Code obfuscation;
– Polymorphism (self-modifying code);
Fig. 1.36 Classification of the main means of test programs neutralization
1 Information Weapon: Concepts, Means, Methods …
Certification tests and case studies are conducted by way of [33, 35]:
– Software functional test for compliance with regulatory and procedural documents;
– Structural (static and dynamic) analysis of software for the absence of undocumented features.
At the same time, experts in the field of testing can use additional methods and
techniques for code checking, for instance, code inspection, use of static analyzers,
study of security bulletins, stress-testing practices, etc.
In the absence of source codes of programs, reverse-engineering approaches and
functional methods (according to the black box principle) are used. The former will
be discussed in more detail in subsequent chapters.
Reverse engineering can be performed as follows [33]:
• Relaying/disassembling, run in the debug mode—for machine and procedural
languages;
• High-quality decompilation—for languages with an intermediate code.
The complexity and size of modern programs are such that special complex test
programs and code analyzers are used for certification of information system security
specialists. As a rule, they conduct dynamic analysis of software while it is running
on a real (or virtual) processor, recording the control trace and all generated data
flows.
If an adversary uses offensive weapons (for instance, malicious logic), it is necessary to ensure effective concealment. In this case, special support tools are commonly
used—the so-called neutralizers of tests and code analysis software. Their goal is
to complicate the program execution path analysis and hide the fact that malicious
software is present.
These special means of neutralizing tests and code analysis software are used
either at the stage of machine code compilation from source code or during program
execution.
The main means of test programs neutralization include (Fig. 1.36) [35–37]:
– Code obfuscation;
– Polymorphism (self-modifying code);
Fig. 1.36 Classification of the main means of test programs neutralization
