Cybersecurity guide for developing countries
Generally, routing attacks involve confusing routers, gateways and addressees by providing them with
false addressing information so that data can be misdirected.
By using certain optional IP features which serve to define the route, in other words, to specify the
addresses of the intermediary systems through which the packet must pass, and by falsifying these
addresses, attackers can easily redirect packets towards a destination of their choice.
Attackers know how to exploit not only operational features of communications protocols, but also the
characteristics of the various operating systems and the ways they work. Thus, by overloading certain
buffers (buffer overflow attack), it is possible to provoke a serious malfunction or system crash. The
targets of this type of attack are, of course, those systems that provide an important service, either in
data transfer (for example, routers) or in the management of names and addresses, for example
nameservers. Most attacks on websites aim to shut them down by exploiting flaws in the operating
system.
II.2.6
Attacks against critical infrastructure
The vulnerability of the essential infrastructures of a society (power supply, water, transportation, food
logistics, telecommunication, banking and finance, medical services, government functions, etc.) is
increased as the use of internet technologies takes root and they become accessible via the “network of
networks”.
Particular emphasis needs to be placed on the vulnerability of electrical power generation and
distribution systems, which are essential to the operation of most of the national infrastructure, and
hence of vital importance. The complexity and distributed nature of the relations between the various
critical infrastructures is part of their strength and, at the same time a source of vulnerability.
It is essential that the gateways between the networks used to operate these infrastructures and the
internet be made secure, and that regional or national bodies be set up to oversee the protection of
critical infrastructures. Their first task must be to coordinate the design and maintenance of plans for
the protection of each of the infrastructures. Coordinated, consistent plans and security solutions are
essential in case of emergencies striking several infrastructures simultaneously.
II.2.7
Phases in a cyberattack
Figure II.6 shows the different phases in a cyberattack21.
The object of the first phase is to gather information and explore potential vulnerabilities in the target
system, in order to gain the maximum information for future exploitation. This involves studying the
mechanisms and levels of security used for identification, authentication, access control, encryption
and surveillance, and identifying technical, organizational and human weaknesses in the environment.
The attacker often attempts to coax naïve or credulous users into revealing information that can be
used to design an attack (this is called social engineering).
21 Illustration taken from Sécurité informatique et télécoms: cours et exercices corrigés by S. Ghernaouti-Hélie (Dunod
2006).
46
Cyberattacks