Kimmo Huosionmaa
When we are talking about intruders of data systems, we must know that those intruders might be people who have spent years in the system, before they begin to leak information. This kind of intruder is harmful and hard to remove because he or she had become a member of the team. And that's why those sleepers are very hard to locate and isolate. Many people noticed that is written with spy term, what is in John Lé Carre's novels.
Those methods are used in everyday life of industrial spying and information stealers world. A methodology of this kind of operation is, that when spying organization will get one person to the certain position of the system, he or she can make very much harm to that system. An agent might use harassment as a weapon with fumigate other workers out of their job and replace them with people like him or herself. That's why in systems must use offensive security, where security workers work undercover that they see what really is going on in their system.
That real-life sleeper is an agent who is put in the system, and that way make very much trouble to his or her clients. The best place to put that sleeper is some antivirus software company's coder, where that person can pollute many systems with malware code. Agent means a hostile operator, who works against companies interests. Normally those agents are very social and people want to believe their stories about how fine workers they are. But when we are talking about agents, we must realize that those persons are more often normal criminals that some governmental workers.
They might work for some criminal organization, what is led by organized crime, whose interests are stealing money from banks with hacking. Those operators might want to steal money from many bank accounts, what means that crime might stay out of security personnel's eye. That kind of criminals might steal the only couple of euros from millions of bank accounts, and because the transfer is so little, some people won't even notice, that their account is missing one or two euros.
And using this "cheese slider" methodology, those gangsters might take a couple of transfers in the same bank. If those people are clever, and use port accounts in many banks, to collect that stolen money in data form. Many gangsters make that kind of mistake, that they steal too much. If somebody realizes suddenly that his or her account is empty, that person normally calls to police. And that makes those money transfers easily to track. Where those people need an agent? They need that person to put their malware program to the server.
That kind of operations must be done outside from building because if all actions will happen inside from house, will data tracked immediately. But when gangsters will make them transfers with remote using the computer, they need access card and another kind of stuff, that they can accomplish the mission. But the problem is that bank's central computer will collect data of those transfers, and if gangsters have done that kind of operation they must destroy that database, that bank can't track them from the net. And that action must be done by malware because if that action is done by the agent the all actions will be uncovered by inner circle job.
But how an agent will rise to that kind of place, where that person make unlimited actions inside that network? Normally the agent will make him needful and helpful actor in the system. That rises he or she social rank in other person eyes. And what makes computer security team suspect that there is an agent inside the system, is that there is more so-called "little mistakes or errors" in system. How can data projector cut communication to the computer if cables are untouchable? Answer in machine or component called router.
Some operator must only disband that data port, and after that computer can't get the connection to the projector. Normally that happens by giving router orders to shut down that gate what allows communication between data-projector and computer. After that even the best ICT-specialists can't get computer's screen to data-projector. What makes people harass other. One answer is that they do it for money, that somebody can replace some workers with the new one.
Comments
Post a Comment