Connexion
Connexion

Penetrating the information space .. and ways to confront it ..

Penetrating the information space .. and ways to confront it ..

By / Hosny Abdel Hafez


In light of the increasing dependence on the use of information and communication technology, in most fields, information penetration has become the greatest danger that threatens the security and safety of data and information in cyberspace..

Western intelligence reports had warned of the seriousness of attacks that could be launched by individuals or groups possessing high technical capabilities on websites of an extremely sensitive nature. The British House of Commons had seen a document leading to the possibility of targeting economic, defense and scientific sites, and that more care and extreme caution should be taken in dealing with data, software, and activities that raise suspicion and doubt, spread across cyberspace, where there are those waiting for the opportunity to access sites and mine them with viruses, worms and the like.

So who are the hackers of the information space..?

What are their means..?

And how can they be confronted..?

Nature of Information Penetration

In its simplest definition, information penetration is illegal entry and remote control, which can only take place in the presence of two main factors: the first is a control program, known as the Client, and the second is the Server, which facilitates the process of self-penetration. More clearly, a program must be available on both the hacker's device and the victim's device. On the victim's device there is the server program, and on the hacker's device there is the client program.

Methods of hacking devices and systems differ according to the tools used in penetration, which we will mention later, but they all depend on the idea of the availability of a remote connection.. from the perspective of the method used, penetration is classified into three sections:

ــ Hacking servers, or main devices for companies and institutions or vernment agencies, and this is often done using what is known as Spoofing, a term used for the process of impersonation to enter the system, where the (IP) usually contains the addresses of the sender and receiver.. these addresses are seen as acceptable and equal in effect by programs and network devices.

ــ Hacking personal devices and tampering with the information they contain, which is the most common method.

ــ Interfering with data during its transfer, and identifying its code, if it is encrypted.

Information Hackers

In points, the hackers who possess tools and means through which they can access information space can be classified as follows:

- First / Hacker :

They are not one type, but three types. The first is called White Hat Hackers, and they are the most numerous among hacker cateries. Thanks to their intelligence and ability to adapt software, they participate in protecting computers and networks, and in discovering vulnerabilities, or preventing unauthorized entry to the system or network, through the skills, tactics and detailed knowledge they have. They are builders, not destroyers, as they have principles and ethics.. As for the second type of hackers, called Black Hat Hackers, they perform harmful, unethical, or illegal acts.. and the third type is called Grey Hat Hackers, and these are people whose behavior is shrouded in mystery.

- Second / Guru :

This is the person who is considered to have great knowledge, wisdom and authority in a certain area or a certain specialty, and his greatest benefit is directing others.. and the word is common in Hinduism and Buddhism, and has a religious use in these languages, as it is widely used in India and Indonesia to mean (teacher in school). As for the field of information technology security, this word is given to the person who is characterized by great knowledge of computers, especially those that run the "Unix" operating system, and possesses great experience in solving problems. If this person refines his knowledge and experience and develops it well, he becomes qualified to become a hacker, either from white hats or black hats.

- Third / Cracker :

The linguistic meaning of the word is "the one who solves the code", especially those related to protecting computer programs from copying and imitation. In light of this, this person's work is illegal, as he hacks computers and networks for the purpose of spreading malware, or seizing important information, or causing damage in general.

- Fourth / Script Kiddy : 

It is a term used in the colloquial literature of information systems for those who are in their teens, and have limited experience with computers, information systems and networks, and their leisure time is wide, and they exploit this limited experience and that wide time in obtaining ready-made programs,

that help them attack systems and networks, and distort sites on the Internet, and they often lack the appropriate skill to write the programs necessary to carry out the hacking process themselves.. in the context of this definition, they can be considered the "early emergence of black hat hackers", as the main motive for most of this catery can be considered to be obtaining the admiration of their peers or friends for what they carry out, or obtaining the trust of black hat communities.

- Fifth / Lamer : 

It is a term derived linguistically from the word "lame", and in the colloquial language of information and communication systems, it is a description applied to people who enter information space and mess in it without knowing or understanding what they are doing, and they are viewed with contempt in the hacking community.

- Sixth / Malware Designers :

They are people who have the skill to create tools and software specifically designed to cause damage or disrupt a system.

The causes and motives of information penetration vary, and they can be identified within three main cateries:

1- Commercial motive:

Where most institutions and companies that have websites live in the heart of a hidden battle from hackers, and in a recent study on this matter, it was mentioned that a number of the major commercial companies around the world face more than fifty hack attempts to their networks every day.

2- Political and military motive:

As scientific and technical development led to almost full dependence on computing systems in most technical and information needs, so dependence became total on the computer.. and through it penetration in order to obtain political, military, economic and scientific information became accessible to information penetration professionals.

3- Individual motive:

The first attempts or beginnings for this penetration were made by students of some American universities, as a matter of boasting about the ability to hack personal devices of their friends and acquaintances, and that phenomenon soon turned into a challenge among them to hack systems in institutions and companies, then Internet sites.

Penetration tools and means

Penetration tools and means multiply, the most dangerous of which are:

Usually a programmed tool, attached to another program, or embedded in a topic within it, and when the program starts working, the work of the virus starts immediately, reproducing itself and spreading to other files or other hard disks, and in this way it doubles itself in record time.

In their reproduction and doubling of their numbers, they are similar to viruses, but the difference is that they do not need a host program to move through, but spread through networks.. worms do not work unless there is a possibility in the system that allows an external source to send the tool carrying them to the system, i.e., a connection to the external or local network is required.

: Trojan Horses - 

The name came from being similar in its method of deception to the means used by the Greeks in storming Troy, when they put inside a large wooden horse a group of soldiers, and when it entered the city, the soldiers came out to seize the vital installations. Like the wooden Trojan horse, the electronic Trojan horse may come in the form of an innocent-looking program but carrying an evil tool inside it, and performing harmful tasks unexpectedly.

Beside these most dangerous penetration means, there are many other means, including deception tools or Hoax, Spyware, Popup pages, Keystroke Loggers, Phishing Scams, and other tools and malicious software that spread in the victim's device through three main mechanisms:

ــ Replication Mechanism .

ــ Stealth Mechanism (The protection Mechanism) .

ــ Activation Mechanism Activate Mechanism .


Penetrating the information space .. and ways to confront it ..
Ehsan Logo