Soru

Zorluk: ZorNetwork and Wireless Attack Indicators

During an incident investigation on an enterprise wired subnet, a security analyst reviews endpoint logs and network traffic captures. The log entries reveal that the MAC address bound to the default gateway IP address (10.20.1.110.20.1.1) is rapidly oscillating between the legitimate router physical address (00:11:22:33:44:5500:11:22:33:44:55) and an unknown physical address (00:AA:BB:CC:DD:EE00:AA:BB:CC:DD:EE). This address flipping is accompanied by a continuous flood of unsolicited Gratuitous ARP reply packets broadcast across the local segment. Which of the following network attacks is currently taking place?

  1. ARP cache poisoningCevap
  2. B
    MAC flooding
  3. C
    DNS cache poisoning
  4. D
    Rogue IPv6 router advertisement

Cevap

ARP cache poisoning is occurring because unsolicited Gratuitous ARP reply packets are corrupting the Layer 2 resolution tables of hosts by repeatedly re-mapping the gateway IP to an unauthorized MAC address.
The correct answer identifies ARP cache poisoning. In an ARP cache poisoning (ARP spoofing) attack, an adversary sends forged, unsolicited Gratuitous ARP reply messages across a local area network. Neighboring endpoints parse these replies and update their local ARP caches, overwriting the legitimate default gateway MAC address (00:11:22:33:44:5500:11:22:33:44:55) with the attacker's MAC address (00:AA:BB:CC:DD:EE00:AA:BB:CC:DD:EE). This enables an On-Path (Man-in-the-Middle) attack by routing all external client traffic through the attacker's host.

Adım Adım Çözüm

1
Analyze the observed log indicators and traffic patterns
Identified rapid flipping of the MAC address assigned to gateway IP 10.20.1.110.20.1.1 alongside an influx of unsolicited Gratuitous ARP replies.
The Address Resolution Protocol (ARP) translates Layer 3 IP addresses into Layer 2 physical MAC addresses for local subnet delivery.
2
Correlate packet activity with specific attack mechanisms
Recognized that Gratuitous ARP replies cause receiving hosts to update their ARP cache tables immediately without having sent a preceding ARP request.
Attackers exploit this protocol feature to overwrite existing ARP cache entries and intercept outbound subnet traffic.
3
Differentiate the attack from related network threats
Confirmed that the primary indicator (ARP table mapping corruption via Gratuitous ARP) uniquely defines ARP cache poisoning (ARP spoofing).
MAC flooding targets switch infrastructure memory tables, while DNS poisoning alters domain-name-to-IP lookup services.

Anahtar Kavram

ARP Cache Poisoning and Gratuitous ARP Indicators
Bu soruyu puanla