AP® Cybersecurity review sheet from Aim for Five (aimforfive.com/cybersecurity/units/3/3-1)
Unit 3 · Topic 3.1
3.1 Network Vulnerabilities and Attacks
Networks move data between devices, and every hop is a chance for an adversary to listen in, impersonate a device or knock a service offline. This topic covers four classic network attacks (ARP poisoning, MAC flooding, DNS poisoning and smurf attacks), the weak spots that make them possible, and how to rate network risks.
Key terms
- ARP poisoning
- MAC spoofing
- MAC flooding
- on-path (man-in-the-middle) attack
- DNS poisoning
- denial of service (DoS/DDoS)
Impersonating a device: ARP poisoning
Every device on a local network has an IP address (its network address, like 198.51.100.23) and a MAC address (a hardware ID built into its network card, like 00:00:5e:00:53:17). The address resolution protocol (ARP) builds a table that pairs each IP address with a MAC address, so the default gateway (the router that connects the local network to other networks) knows where to deliver traffic.
In ARP poisoning, an adversary sends fake ARP messages that link the target's IP address to the adversary's own MAC address. Traffic meant for the target now goes to the adversary. A related trick, making a device claim a MAC address that isn't really its own, is called MAC spoofing.
ARP poisoning is a kind of on-path attack (also called man-in-the-middle). The adversary sits between two parties, captures what each one sends, and may copy or change it before passing it on. Both sides think they're talking directly to each other.
Three more network attacks
- MAC flooding: the adversary sends a switch a huge number of Ethernet frames, each with a different fake MAC address. A switch normally sends each frame only to the port where its destination lives. When its address table overflows, it can fall back to broadcasting every frame to every port. Now the adversary receives everyone's traffic. Capturing data in transit like this is called eavesdropping, or sniffing.
- DNS poisoning: DNS (the domain name system) turns names like portal.example.com into IP addresses. The adversary pretends to be an authoritative name server and plants a fake record on a DNS server, so people who type the real name land on the adversary's look-alike site. That fake login page is credential harvesting: users type real usernames and passwords, and the adversary collects them.
- Smurf attack: the adversary sends many ICMP requests (the messages behind the ping command) to the network's broadcast address, faking the victim's address as the sender. Every device on the network replies to the victim at once, and the flood blocks legitimate traffic. Making a system unavailable like this is a denial of service (DoS). When many devices attack one target at the same time, it's a distributed denial of service (DDoS).
Weak spots that let attacks in
- No firewall, or a badly configured one, lets adversaries send traffic in to flood the network, map its internal layout or spoof a legitimate device.
- One compromised device becomes a launch pad for attacking others on the same local area network (LAN).
- An open data port on a switch without port security lets anyone who plugs in join the LAN and try DoS, MAC flooding or MAC spoofing.
- A rogue access point: an adversary plugs their own wireless access point into an open port and reaches the internal network wirelessly, maybe from outside the building, bypassing the firewalls.
- Wi-Fi that leaks outside the building lets adversaries pick up the signal and its beacon frames (announcements of the network's name and settings), then attempt eavesdropping or attacks on the encryption. Weak wireless encryption can be broken outright.
- Networks that don't authenticate devices and users let adversaries join and attack from inside.
Rating network risks
Network weaknesses can hurt confidentiality (intercepted data), integrity (altered data in transit) and availability (DoS), and they can let adversaries move toward more critical systems. Automated vulnerability scanners check networks, devices and applications for known weaknesses and report each one with its severity and suggested fixes. Remember that many network exploits take advanced skill, which lowers their likelihood.
| Rating | Pattern | Example |
|---|---|---|
| High | An adversary could easily capture traffic, spoof a device or launch a DoS, with big impact | One flat, unsegmented network reachable through weakly encrypted Wi-Fi, with the company's main app server on it |
| Moderate | An adversary could learn about systems and devices on the network | The outside firewall doesn't block ICMP from the internet, so anyone can ping-map the network |
| Low | Hard to exploit, small impact | Access points broadcast beacon frames showing the network name and encryption type |
Worked examples
Try each one yourself first, then open the solution.
- Example 1
Naming the attack
Identify the attack in each case. (a) Students at Westbrook High type the school portal's address but land on a look-alike page that asks for their passwords; the real portal is fine. (b) A laptop on the office network starts receiving copies of all its neighbors' traffic shortly after a burst of thousands of frames from new MAC addresses. (c) A server becomes unreachable as it's buried in ICMP replies from every device on one network.
Show the solutionHide the solution
- Step 1: (a) The name led to the wrong address, but the real site is untouched. The name-to-address lookup was tampered with: DNS poisoning, used for credential harvesting.
- Step 2: (b) Thousands of fake MAC addresses overflowed the switch's table, so it broadcast everything: MAC flooding, which enables eavesdropping.
- Step 3: (c) Many devices replying with ICMP to one victim at once is the smurf pattern, a denial of service.
Answer: (a) DNS poisoning (credential harvesting). (b) MAC flooding (eavesdropping). (c) Smurf attack (DoS).
- Example 2
Ranking network findings
A scan of Bayview Credit Union finds: (1) an open Ethernet jack in the public lobby that connects to the internal network; (2) printers on the internal network show their model numbers and firmware versions; (3) the guest Wi-Fi signal reaches the parking lot, and the guest network is separate from the internal one. Which is the highest risk, and why?
Show the solutionHide the solution
- Step 1: (1) Anyone in the lobby could plug in, join the internal LAN and spoof a device, flood the switch or add a rogue access point. Easy to exploit, big impact.
- Step 2: (2) This leaks information about devices, which helps an adversary plan. That's the moderate pattern.
- Step 3: (3) The leak is on a separate guest network, so it doesn't expose internal systems. Lower risk.
- Step 4: Pick the one with the easiest path to a big impact.
Answer: The open lobby jack is the highest risk: anyone can physically connect to the internal network and launch spoofing, MAC flooding or rogue access point attacks.
Common mistakes
- Confusing ARP poisoning with DNS poisoning. ARP poisoning fakes which MAC address goes with an IP address on the local network; DNS poisoning fakes which IP address goes with a domain name.
- Thinking MAC flooding takes the network down. Its goal is to make the switch broadcast traffic so the adversary can eavesdrop.
- Saying the smurf attack's adversary sends the flood directly. The adversary sends requests to the broadcast address with the victim's address faked, and the network's own devices flood the victim.
- Forgetting that a rogue access point bypasses firewalls, since it connects inside the network.
On the exam
- Expect descriptions of symptoms (redirected logins, a switch broadcasting, a flood of ICMP) and questions asking which attack is happening. Tie the symptom to the mechanism in your explanation.
- For risk-rating questions, weigh how easy the exploit is and how much damage it could do. An easily reached internal connection usually beats information leaks.
Connected topics
Videos
Check yourself: 3.1 Network Vulnerabilities and Attacks
5 questions on 3.1 Network Vulnerabilities and Attacks. Pick an answer to see if you got it, and why.
Thousands of compromised home routers around the world send traffic to a school district's website at the same moment, and the site goes offline. Which term best describes this attack?
A visitor plugs a small wireless access point into an unused network port in a public library's community meeting room. Why is this especially dangerous?
An automated vulnerability scanner checked the network of the Riverside Public Library and reported these findings:
Finding 1: All of the library's devices, including the server that runs its book-checkout application, are on one unsegmented internal network. Staff and patrons join that network through Wi-Fi that uses WEP encryption.
Finding 2: The library's external firewall doesn't block ICMP traffic from the internet.
Finding 3: The library's wireless access points broadcast beacon frames that contain the network's SSID and encryption type.
Finding 4: A smart TV in the staff break room is on a separate guest network that has no connection to any library system.
Invented scanner report
Which finding would most likely be documented as a high risk?
Why would Finding 2 most likely be rated as a moderate risk?
Which information does a vulnerability scanner's report usually include?
0 of 5 answered