Soru

Zorluk: OrtaCommon Network Attack Types and Vectors

Match each network attack type to the technical indicator or mechanism that best characterizes its execution.

  • VLAN Hopping (Double Tagging)Transmits forged Layer 2 frames with nested 802.1Q headers to traverse switch boundaries.
  • ARP Cache PoisoningSends unsolicited gratuitous ARP replies to associate an attacker MAC address with a target IP address.
  • DNS AmplificationLeverages open recursive resolvers and spoofed UDP source addresses to flood a target with inflated responses.
  • Deauthentication AttackBroadcasts unencrypted wireless 802.11 management frames to force client disassociation.

Cevap

VLAN Hopping (Double Tagging) pairs with transmitting nested 802.1Q headers; ARP Cache Poisoning pairs with sending unsolicited gratuitous ARP replies; DNS Amplification pairs with leveraging open recursive resolvers and spoofed UDP source addresses; Deauthentication Attack pairs with broadcasting unencrypted wireless 802.11 management frames.
Each attack type matches its distinct operational layer and technique: VLAN Hopping uses double 802.1Q tags over Ethernet switches; ARP Poisoning updates host caches using forged Layer 2 gratuitous messages; DNS Amplification leverages UDP spoofing to reflect enlarged DNS payloads; and Deauthentication relies on spoofed 802.11 wireless management disassociation frames.

Adım Adım Çözüm

1
Analyze VLAN Hopping mechanisms
Identified double tagging using stacked 802.1Q tags to send traffic across isolated VLAN boundaries.
Switches strip the outer native tag, allowing the secondary tag to be forwarded to a target VLAN.
2
Analyze ARP Cache Poisoning mechanisms
Identified gratuitous ARP packet generation mapping targeted IPv4 addresses to malicious MAC addresses.
Hosts accept unsolicited ARP replies and update their local cache without verifying existing mappings.
3
Analyze DNS Amplification mechanisms
Identified reflection and payload magnification using spoofed UDP requests targeting open recursive DNS servers.
UDP lacks handshakes, allowing source IP spoofing, and large DNS lookup records return significantly larger payloads to the victim.
4
Analyze Deauthentication Attack mechanisms
Identified spoofed 802.11 management disassociation frames.
Legacy 802.11 management frames are sent unencrypted and without authentication, allowing attackers to disconnect station clients.

Anahtar Kavram

Classification of Common Network Attack Types and Vectors
Bu soruyu puanla