Problems in the context of ascription of software to malicious software tools
Banner en_US
PDF (Українська)

Keywords

Problems in the context of ascription of software to malicious software tools

How to Cite

Nizovtsev, I. (2016). Problems in the context of ascription of software to malicious software tools. Criminalistics and Forensics, (61), 347-355. Retrieved from https://digest.kndise.gov.ua/index.php/KISE/article/view/926

Abstract

In the course of the research, many scientists dedicated their papers to the issue of combating cybercrime, including the investigation of crimes involving the use of malicious software. At the same time, the role and potential of forensic examination in the domain of ascription of software to malicious software tools remain unexplored.

For several reasons, the author considers that determination of the "harmfulness" of the software, studying nothing but technicality, is dubious and disputed. For example, a harmful action can be performed by a useful computer program due to code error or incorrect launch parameters.

It is also worth noting that there is no direct link between the original purpose of the program and its functionality. The same software (function of the program) can be used both with good intentions and with unlawful purposes. Programs that have the same function can have different basic principles of operation and functionality, and vice versa, programs of different object matter can have similar functions.

In addition, the attribution of the software to malware for snooping and tampering requires the ascertainment of the fact of the author’s intention to create a computer program for this purpose, and also it requires determination of such criteria as "unauthorized," which is legal. The solutions of the legal problems by experts are forbidden by the Criminal Procedural Code of Ukraine (paragraph № 242).

Experience has proven that the initiator of the expert examination usually requires a simple answer of the expert: whether the program is a malicious software tool or not.

According to the author’s judgment, such an approach is fundamentally wrong. Firstly, the expert does not have sufficient capacity to ascertain malicious intent of the software developer, since it requires certain investigation actions (interrogations, etc.). Secondly, addressing both technical and legal issues, the expert actually gives a complete legal evaluation of the offense, thereby assuming part of the investigator’s authority.

In accordance with the author’s opinion, the attribution of software to malicious software (malware) is impossible to implement merely within the framework of forensic investigation. This process demands efforts of both an expert, who explores the technical aspects of the software, and an investigator, who establishes legal points. These legal points concern the possibility, identified by the expert, to apply functionality of software with a purpose of tampering, and also the software developer’s criminal intent to produce a computer program specifically for these actions.

PDF (Українська)

References

Kryminalʹnyy kodeks Ukrayiny [Elektronnyy resurs]. Rezhym dostupu: http://zakon5.rada.gov.ua/laws/show/2341-14

Kasperskyy E. V. Kompʹyuternye vyrusy: chto éto takoe y kak s nymy borotʹsya. Moskva, 1998. 288 s.

«ANTYVYRUS KASPERSKOHO» prynyal za vyrus systemniy fayl TCPIP.SYS / zhurnal «Khaker» [Elektronnyy resurs]. Rezhym dostupu: https://xakep.ru/2013/10/27/61498/

AVG incorrectly flags user32.dll in Windows XP SP2/SP3 [Elektronnyy resurs]. Rezhym dostupu: http://arstechnica.com/information-technology/2008/11/avg-incorrectly-flags-user32-dll-in-windows-xp-sp2sp3/

Microsoft prynyala brauzer Google za vyrus [Elektronnyy resurs]. Rezhym dostupu: http://www.cnews.ru/news/top/microsoft_prinyala_brauzer_google_za_virus

ping(8) - Linux man page [Elektronnyy resurs]. Rezhym dostupu: http://linux.die.net/man/8/ping

FreeBSD Man Pages [Elektronnyy resurs]. Rezhym dostupu: http://www.freebsd.org/cgi/man.cgi?query=ping&sektion=8&manpath=FreeBSD+4.3-RELEASE

DDOS standartnymy sredstvamy vyndy [Elektronnyy resurs]. Rezhym dostupu: https://forum.xeksec.com/f17/t829/

Étychnyy vzlom po shaham: kolonka Yuryya Holʹtseva / zhurnal «Khaker» [Elektronnyy resurs]. Rezhym dostupu: https://xakep.ru/2015/04/09/195-goltsev/

Ploshchadka dlya vzloma: holovolomky dlya khakera / zhurnal «Khaker» [Elektronnyy resurs]. Rezhym dostupu: https://xakep.ru/2010/06/03/52289/

HOST 34.602-89. Ynformatsyonnaya tekhnolohyya. Kompleks standartov na avtomatyzyrovannye systemy. Tekhnycheskoe zadanye na sozdanye avtomatyzyrovannoy systemy [Elektronnyy resurs]. Rezhym dostupu: http://tzi.com.ua/downloads/34.602-89.pdf

Tracert vs Traceroute [Elektronnyy resurs]. Rezhym dostupu: https://habrahabr.ru/post/281272/

Internet Control Message Protocol (ICMP). Basics / Microsoft Support [Elektronnyy resurs]. Rezhym dostupu: https://support.microsoft.com/en-us/kb/170292

Internet Control Message Protocol (ICMP) Parameters / Internet Assigned Numbers Authority (IANA) [Elektronnyy resurs]. Rezhym dostupu: www.iana.org/assignments/icmp-parameters/icmp-parameters.xhtml

Rivni modeli OSI / Kompʺyuterni merezhi [Elektronnyy resurs]. Rezhym dostupu: http://comp-net.at.ua/index/rivni_modeli_osi/0-10

RFC 768. User Datagram Protocol (UDP) / Internet Engineering Task Force (IETF) [Elektronnyy resurs]. Rezhym dostupu: https://tools.ietf.org/html/rfc768

Service Name and Transport Protocol Port Number Registry / Internet Assigned Numbers Authority (IANA) [Elektronnyy resurs]. Rezhym dostupu: http://www.iana.org/assignments/service-names-port-numbers/service-names-port-numbers.xhtml

Naukovo-metodychni rekomendatsiyi z pytanʹ pidhotovky ta pryznachennya sudovykh ekspertyz ta ekspertnykh doslidzhenʹ, zatverdzheni nakazom Ministerstva yustytsiyi Ukrayiny vid 08.10.1998 № 53/5 «Pro zatverdzhennya Instruktsiyi pro pryznachennya ta provedennya sudovykh ekspertyz ta ekspertnykh doslidzhenʹ ta Naukovo-metodychnykh rekomendatsiy z pytanʹ pidhotovky ta pryznachennya sudovykh ekspertyz ta ekspertnykh doslidzhenʹ» [Elektronnyy resurs]. Rezhym dostupu: http://zakon5.rada.gov.ua/laws/show/z0705-98

Kryminalʹnyy protsesualʹnyy kodeks Ukrayiny [Elektronnyy resurs]. Rezhym dostupu: http://zakon3.rada.gov.ua/laws/show/4651-17

Slovnyk ukrayinsʹkoyi movy: v 11 tt. / AN URSR. In-t movoznavstva; za red. I. K. Bilodida. Kyyiv, 1970. T. 9. 1980. S. 54.

Yudin O. K. Informatsiyna bezpeka: normatyvno-pravove zabezpechennya. Kyyiv, 2010. 708 s. il.

Pro zakhyst informatsiyi v informatsiyno-telekomunikatsiynykh systemakh: zakon Ukrayiny [Elektronnyy resurs]. Rezhym dostupu: http://zakon5.rada.gov.ua/laws/show/80/94-vr

Bilousov A. S. Kryminalistychnyy analiz obʺyektiv kompʺyuternykh zlochyniv: dys. … kand. nauk: 12.00.09 / Klasychnyy pryvatnyy universytet. Zaporizhzhya, 2008. 245 s.