Backdoor (computing)

A backdoor is a typically covert method of bypassing normal authentication or encryption in a computer, product, embedded device (e.g. a home router), or its embodiment (e.g. part of a cryptosystem, algorithm, chipset, or even a "homunculus computer"—a tiny computer-within-a-computer such as that found in Intel's AMT technology).[1][2] Backdoors are most often used for securing remote access to a computer, or obtaining access to plaintext in cryptosystems. From there it may be used to gain access to privileged information like passwords, corrupt or delete data on hard drives, or transfer information within autoschediastic networks.

A backdoor may take the form of a hidden part of a program,[3] a separate program (e.g. Back Orifice may subvert the system through a rootkit), code in the firmware of the hardware,[4] or parts of an operating system such as Windows.[5][6][7] Trojan horses can be used to create vulnerabilities in a device. A Trojan horse may appear to be an entirely legitimate program, but when executed, it triggers an activity that may install a backdoor.[8] Although some are secretly installed, other backdoors are deliberate and widely known. These kinds of backdoors have "legitimate" uses such as providing the manufacturer with a way to restore user passwords.

Many systems that store information within the cloud fail to create accurate security measures. If many systems are connected within the cloud, hackers can gain access to all other platforms through the most vulnerable system.[9] Default passwords (or other default credentials) can function as backdoors if they are not changed by the user. Some debugging features can also act as backdoors if they are not removed in the release version.[10] In 1993, the United States government attempted to deploy an encryption system, the Clipper chip, with an explicit backdoor for law enforcement and national security access. The chip was unsuccessful.[11]

Recent proposals to counter backdoors include creating a database of backdoors' triggers and then using neural networks to detect them.[12]

  1. ^ Cite error: The named reference Eckersley-2017 was invoked but never defined (see the help page).
  2. ^ Cite error: The named reference Hoffman-2017 was invoked but never defined (see the help page).
  3. ^ Cite error: The named reference Wysopal-Eng was invoked but never defined (see the help page).
  4. ^ Cite error: The named reference Zetter-2013 was invoked but never defined (see the help page).
  5. ^ Cite error: The named reference Ashok-2017 was invoked but never defined (see the help page).
  6. ^ Cite error: The named reference Microsoft-Back-Doors was invoked but never defined (see the help page).
  7. ^ Cite error: The named reference Ars-Technica-2017 was invoked but never defined (see the help page).
  8. ^ Cite error: The named reference Backdoors-and-Trojan-Horses was invoked but never defined (see the help page).
  9. ^ Cite error: The named reference Linthicum was invoked but never defined (see the help page).
  10. ^ Cite error: The named reference Bogus-story was invoked but never defined (see the help page).
  11. ^ Cite error: The named reference Clipper-a-failure was invoked but never defined (see the help page).
  12. ^ Cite error: The named reference Menisov-2022 was invoked but never defined (see the help page).

© MMXXIII Rich X Search. We shall prevail. All rights reserved. Rich X Search