Soru

Zorluk: OrtaCommon Network Attack Types and Vectors

A network security administrator is organizing a training module to help tier-1 analysts identify malicious activity across different network layers. Match each network attack type on the left with its corresponding operational mechanism or technical signature on the right.

  • ICMP Redirect AttackInjecting forged control messages to alter a host's local routing table and divert outbound gateway traffic.
  • Slowloris AttackOpening multiple HTTP connections and sending incomplete headers at periodic intervals to exhaust server thread pools.
  • RF JammingEmitting high-power electromagnetic signals across frequency channels to degrade SNR and disrupt 802.11 frames.
  • MAC Address SpoofingModifying the physical interface hardware address in frame headers to bypass port security rules or filters.

Cevap

ICMP Redirect Attack matches with altering a host's local routing table via control messages; Slowloris Attack matches with sending incomplete HTTP headers to exhaust server thread pools; RF Jamming matches with emitting electromagnetic signals to disrupt 802.11 wireless frames; MAC Address Spoofing matches with altering physical hardware addresses in frame headers to bypass filtering.
Each attack vector is paired with its specific network layer operational signature: ICMP Redirect manipulates host IP routing tables via ICMP control messages; Slowloris maintains unclosed Layer 7 HTTP header requests to consume web server sockets; RF Jamming causes Layer 1 physical wireless radio frequency interference; and MAC Address Spoofing modifies Layer 2 physical frame headers.

Adım Adım Çözüm

1
Analyze the ICMP Redirect attack mechanism.
ICMP Type 5 packets are gateway control messages designed to update host routing paths; forged ICMP redirects alter target routing tables to intercept traffic.
This establishes the link between ICMP control packets and host route manipulation.
2
Analyze the Slowloris attack mechanism.
Slowloris sends partial HTTP request headers over open TCP connections at slow rates to tie up concurrent web server worker threads.
This differentiates application-layer slow HTTP DoS attacks from volumetric network floods.
3
Analyze the RF Jamming mechanism.
RF Jamming operates at the physical layer by generating deliberate radio frequency noise on active wireless bands to lower the Signal-to-Noise Ratio (SNR).
This identifies physical wireless signal interference as the cause of frame corruption and channel blockage.
4
Analyze the MAC Address Spoofing mechanism.
MAC spoofing overrides a network card's media access control address in frame headers to match an authorized MAC address.
This links layer 2 hardware addressing manipulation with bypassing MAC filtering security controls.

Anahtar Kavram

Common Network Attack Types and Vectors
Bu soruyu puanla