Learning Objective 3.1.A: Identify common network attacks.
- 3.1.A.1 The address resolution protocol (ARP) is used by a default gateway on a network to establish a table that pairs internet protocol (IP) addresses with media access control (MAC) addresses. An ARP poisoning attack is when an adversary sends falsified ARP packets to the default gateway to modify the table so that the adversary’s device receives traffic intended for the target by linking the target’s IP address to the adversary’s MAC address. Faking a MAC address is called MAC spoofing. This is an example of an on-path attack (or man-in-the-middle attack), which is when an adversary interrupts a data stream between two parties, captures both parties’ data, and copies or alters the data before sending them on. Both parties think they are communicating directly with each other, but instead they are each communicating with the adversary who is secretly intercepting their messages.
- 3.1.A.2 A MAC flooding attack is when an adversary sends the target switch many Ethernet frames, each with a different MAC address. This can force the switch into broadcast mode, and the adversary can then collect all of the frames on the network (because they are being broadcast), which could allow the adversary to access sensitive information. This is an example of eavesdropping (or sniffing), which is when an adversary captures data in transit and can record and copy the data.
- 3.1.A.3 A domain name system (DNS) poisoning attack is when an adversary pretends to be an authoritative name server (NS) and plants a fake DNS record on a DNS server to redirect browser traffic to a malicious website designed to steal credentials. This is an example of credential harvesting, which is when adversaries set up a fake login site that looks like a real one. Unsuspecting users enter their real credentials, which the adversaries capture and use.
- 3.1.A.4 A smurf attack attempts to overwhelm a network with Internet Control Message Protocol (ICMP) requests. It is a type of denial of service (DoS) attack, which makes a system or resource unavailable to authorized users. During a smurf attack, an adversary sends many ICMP requests with the victim’s address to the network’s broadcast address. The network’s gateway then sends these requests to all devices on the network. Each device on the network replies to the victim’s address, creating a flood of traffic that can block legitimate messages. When multiple devices attack the same target simultaneously, it’s called a distributed denial of service (DDoS) attack.
Learning Objective 3.1.B: Explain how adversaries can exploit network vulnerabilities to steal, disrupt, or destroy network communication.
- 3.1.B.1 Adversaries can send malicious traffic into a network to flood it creating a DoS, to map the internal structure of the network, or to spoof a legitimate device. Networks without firewalls, or with improperly configured firewalls, are vulnerable to these types of attacks.
- 3.1.B.2 Adversaries that have compromised a device often attempt to leverage their access to compromise other devices on the local area network (LAN).
- 3.1.B.3 Adversaries that physically plug into a data port can gain access to a LAN through the switch port unless port security is enabled. This allows adversaries to launch DoS attacks or perform MAC flooding or MAC spoofing attacks.
- 3.1.B.4 Adversaries standing outside of physically secure spaces can pick up the signals and beacon frames from a wireless access point that is broadcasting outside the physical space. This allows them to gather information about the wireless network and to attempt eavesdropping and cryptographic attacks on it.
- 3.1.B.5 Adversaries can attempt to join networks to launch attacks from within the networks. Networks that do not authenticate devices and users make it easier for adversaries to join.
- 3.1.B.6 If there is an open network port, an adversary can plug a wireless access point into the port creating a rogue access point. The adversary could use this rogue access point to access the internal network wirelessly (maybe even from outside the physical space). This allows the adversary direct access to the LAN, bypassing any firewalls.
- 3.1.B.7 Adversaries can attempt to break wireless encryption and intercept, steal, or compromise data on a network.
Learning Objective 3.1.C: Assess and document risks from network vulnerabilities.
- 3.1.C.1 Vulnerabilities on a network can lead to adversaries being able to intercept and alter data in transit, launch DoS attacks, or move laterally on a network to gain access to more sensitive or critical systems. Network vulnerabilities can constitute a risk to confidentiality, integrity, and availability.
- 3.1.C.2 There are automated vulnerability scanners that can check networks, devices, and applications for known vulnerabilities. These scanners produce a report that often includes the vulnerabilities detected, their severity, and mitigation recommendations.
- 3.1.C.3 Successfully exploiting a network vulnerability often requires advanced technical ability and knowledge. This can impact the likelihood of an exploit.
- 3.1.C.4 High risks from network vulnerabilities allow an adversary to easily have a significant impact by capturing network traffic, spoofing a legitimate device on the network, or launching a DoS attack.
- Illustrative examples for 3.1.C.4:
- An organization has a single unsegmented internal network that is accessible via a wireless network with weak encryption, and on that network it has a server running its proprietary web-application.
- Illustrative examples for 3.1.C.4:
- 3.1.C.5 Moderate risks from network vulnerabilities could include vulnerabilities that might give adversaries the ability to gain information about systems or devices on a network.
- Illustrative examples for 3.1.C.5:
- An organization’s external firewall is not configured to block external ICMP traffic.
- Illustrative examples for 3.1.C.5:
- 3.1.C.6 Low risks from network vulnerabilities include vulnerabilities that would be difficult to exploit and would likely have minimal negative impacts on an organization.
- Illustrative examples for 3.1.C.6:
- An organization has wireless access points that broadcast a beacon frame, which contains the network service set identifier (SSID) and the wireless encryption protocols.
- Illustrative examples for 3.1.C.6:
هدف التعلم 3.1.A: تحديد هجمات الشبكة الشائعة.
- 3.1.A.1 يُستخدم بروتوكول حل العناوين (ARP) بواسطة بوابة افتراضية في الشبكة لإنشاء جدول يربط بين عناوين بروتوكول الإنترنت (IP) وعناوين التحكم في الوصول إلى الوسائط (MAC). هجوم تسميم ARP هو عندما يرسل الخصم حزم ARP مزورة إلى البوابة الافتراضية لتعديل الجدول بحيث تستقبل جهازه حركة البيانات الموجهة إلى الهدف عن طريق ربط عنوان IP الخاص بالهدف بعنوان MAC الخاص بالخصم. يُسمى تزوير عنوان MAC بتزوير MAC (MAC spoofing). هذا مثال على هجوم في المسار (On-path attack) أو هجوم الرجل في المنتصف (Man-in-the-middle)، وهو عندما يقاطع الخصم تدفق البيانات بين طرفين، ويحتوي بيانات الطرفين، وينسخ أو يعدل البيانات قبل إرسالها. يعتقد كلا الطرفين أنه يتواصل مباشرة مع الآخر، ولكن بدلاً من ذلك، يتواصل كل منهما مع الخصم الذي يعترض رسائلهما سرًا.
- 3.1.A.2 هجوم طمس MAC هو عندما يرسل الخصم العديد من إطارات الإيثرنت إلى المحول المستهدف، كل إطار يحمل عنوان MAC مختلف. يمكن لهذا أن يجبر المحول على وضع البث (Broadcast mode)، وحينها يمكن للخصم جمع جميع الإطارات على الشبكة (لأنها تُبث)، مما قد يسمح له بالوصول إلى معلومات حساسة. هذا مثال على التنصت (Eavesdropping) أو التقط signals (Sniffing)، وهو عندما يلتقط الخصم البيانات أثناء مرورها ويمكنه تسجيل ونسخ البيانات.
- 3.1.A.3 هجوم تسميم نظام أسماء النطاقات (DNS Poisoning) هو عندما يتظاهر الخصم بأنه خادم أسماء مفوض (NS) ويزرع سجلاً مزيفاً في DNS على خادم DNS لإعادة توجيه حركة متصفح الويب إلى موقع ضار مصمم لسرقة بيانات الاعتماد. هذا مثال على صيد بيانات الاعتماد (Credential Harvesting)، وهو عندما يقوم الخصوم بإعداد موقع تسجيل دخول مزيف يبدو حقيقياً. يدخل المستخدمون غير المشتبه بهم بيانات اعتمادهم الحقيقية، والتي يلتقطها الخصوم ويستخدمونها.
- 3.1.A.4 يحاول هجوم Smurf إغراق الشبكة بطلبات بروتوكول رسائل Internet Control (ICMP). إنه نوع من هجمات حرمان الخدمة (DoS)، والتي تجعل النظام أو المورد غير متاح للمستخدمين المصرح لهم. أثناء هجوم Smurf، يرسل الخصم العديد من طلبات ICMP بعنوان الضحية إلى عنوان البث للشبكة. ترسل بوابة الشبكة بعد ذلك هذه الطلبات إلى جميع الأجهزة المتصلة بالشبكة. ترد كل جهاز على الشبكة بعنوان الضحية، مما يخلق سيولة هائلة من حركة البيانات يمكن أن تحجب الرسائل الشرعية. عندما تهاجم عدة أجهزة نفس الهدف في وقت واحد، يُسمى ذلك هجوم حرمان الخدمة الموزع (DDoS).
هدف التعلم 3.1.B: شرح كيفية استغلال الخصوم لثغرات الشبكة لسرقة أو تعطيل أو تدمير اتصالات الشبكة.
- 3.1.B.1 يمكن للخصوم إرسال حركة مرور خبيثة إلى الشبكة لإغرائها وإنشاء هجوم DoS، أو لرسم البنية الداخلية للشبكة، أو لتزوير جهاز شرعي. الشبكات التي لا تحتوي على جدران حماية، أو التي تكون جدران الحماية فيها مضبوطة بشكل غير صحيح، عرضة لهذه الأنواع من الهجمات.
- 3.1.B.2 الخصوم الذين استحوذوا على جهاز ما غالباً ما يحاولون الاستفادة من وصولهم لاستهداف أجهزة أخرى على الشبكة المحلية (LAN).
- 3.1.B.3 يمكن للخصوم الذين يوصلون أسلاكهم جسدياً بمنفذ بيانات الحصول على الوصول إلى الشبكة المحلية عبر منفذ المحول ما لم يتم تفعيل أمان المنافذ. هذا يسمح للخصوم بإطلاق هجمات DoS أو تنفيذ هجمات طمس MAC أو تزوير MAC.
- 3.1.B.4 يمكن للخصوم الواقفين خارج المساحات الآمنة جسدياً التقاط الإشارات وإطارات البث من نقطة الوصول اللاسلكية التي تبث خارج المساحة الجسدية. يسمح هذا لهم بجمع معلومات حول الشبكة اللاسلكية ومحاولة التنصت والهجمات المشفرة عليها.
- 3.1.B.5 يمكن للخصوم محاولة الانضمام إلى شبكات لإطلاق هجمات من داخل تلك الشبكات. الشبكات التي لا تقوم بمصادقة الأجهزة والمستخدمين تسهل على الخصوم الانضمام إليها.
- 3.1.B.6 إذا كان هناك منفذ شبكة مفتوح، يمكن للمهاجم توصيل نقطة وصول لاسلكية بالمنفذ مما يخلق نقطة وصول غير شرعية. قد يستخدم المهاجم هذه النقطة الوصول غير الشرعية للوصول إلى الشبكة الداخلية لاسلكيًا (ربما حتى من خارج المكان المادي). هذا يسمح للمهاجم بالوصول المباشر إلى LAN، متجاوزًا أي جدران حماية.
- 3.1.B.7 يمكن للمهاجمين محاولة كسر تشفير الشبكة اللاسلكية والتقاط أو سرقة أو الإضرار بالبيانات على الشبكة.
هدف التعلم 3.1.C: تقييم مخاطر ثغرات الشبكة وتوثيقها.
- 3.1.C.1 يمكن أن تؤدي الثغرات في الشبكة إلى قدرة المهاجمين على التقاط البيانات أثناء النقل وتعديلها، أو إطلاق هجمات حجب الخدمة (DoS)، أو التحرك أفقيًا عبر الشبكة للحصول على وصول إلى أنظمة أكثر حساسية أو حرجة. قد تمثل الثغرات في الشبكة خطرًا على السرية والنزاهة والتوافر.
- 3.1.C.2 توجد ماسحات أوتوماتائية للثغرات يمكنها فحص الشبكات والأجهزة والتطبيقات بحثًا عن ثغرات معروفة. تنتج هذه الماسحات تقريرًا يتضمن عادةً الثغرات التي تم اكتشافها، وخطورتها، وتوصيات التخفيف.
- 3.1.C.3 يتطلب استغلال ناجح لثغرة في الشبكة غالبًا قدرات ومعرفة تقنية متقدمة. وهذا يمكن أن يؤثر على احتمالية الاستغلال.
- 3.1.C.4 تسمح المخاطر العالية الناتجة عن ثغرات الشبكة للمهاجم بالحصول بسهولة على تأثير كبير من خلال التقاط حركة مرور الشبكة، أو تزوير جهاز شرعي على الشبكة، أو إطلاق هجوم حجب الخدمة (DoS).
- أمثلة توضيحية لـ 3.1.C.4:
- تمتلك منظمة شبكة داخلية واحدة غير مقسمة قابلة للوصول عبر شبكة لاسلكية ذات تشفير ضعيف، وعلى تلك الشبكة يوجد خادم يعمل عليه تطبيق الويب الخاص بها.
- أمثلة توضيحية لـ 3.1.C.4:
- 3.1.C.5 قد تشمل المخاطر المتوسطة الناتجة عن ثغرات الشبكة ثغرات قد تمنح المهاجمين القدرة على الحصول على معلومات حول الأنظمة أو الأجهزة على الشبكة.
- أمثلة توضيحية لـ 3.1.C.5:
- جدار الحماية الخارجي للمنظمة غير مُضبط لمنع حركة مرور ICMP الخارجية.
- أمثلة توضيحية لـ 3.1.C.5:
- 3.1.C.6 تشمل المخاطر المنخفضة الناتجة عن ثغرات الشبكة ثغرات سيكون من الصعب استغلالها ومن المرجح أن يكون لها تأثير سلبي طفيف على المنظمة.
- أمثلة توضيحية لـ 3.1.C.6:
- تمتلك المنظمات نقاط وصول لاسلكية تبث إطار البون (beacon frame)، والذي يحتوي على معرف مجموعة الخدمات للشبكة (SSID) وبروتوكولات التشفير اللاسلكي.
- أمثلة توضيحية لـ 3.1.C.6:

*عتاد شبكي حقيقي: جدار الحماية هو جهاز (أو برنامج) يقع حيث يلتقي هذه الكابلات بالعالم الخارجي