An enterprise security operations team investigates anomalous traffic patterns within a corporate dual-stack subnetwork. Network monitoring alerts indicate that multiple workstations have dynamically updated their default gateway settings to route external traffic through an unapproved link-local address. Packet captures reveal continuous, unsolicited ICMPv6 Type 134 messages being broadcast across the segment with a high router preference flag enabled. Which of the following attack types is indicated by these findings?
- Rogue IPv6 Router Advertisement (RA) attackCevap
- BAddress Resolution Protocol (ARP) poisoning attack
- CDomain Name System (DNS) amplification attack
- DVirtual Local Area Network (VLAN) hopping attack
Cevap
Rogue IPv6 Router Advertisement (RA) attack
The scenario describes unsolicited ICMPv6 Type 134 messages (Router Advertisements) with high preference flags, which alter host routing tables on dual-stack subnetworks to direct traffic to an attacker's rogue gateway. This is the classic signature of a Rogue IPv6 Router Advertisement attack.
Adım Adım Çözüm
Anahtar Kavram
IPv6 Neighbor Discovery Protocol (NDP) Vulnerabilities and Rogue Router Advertisements