Learning Objective 3.1.A: Identify common network attacks.
- 3.1.A.1 The address resolution protocol (ARP) is used by a default gateway on a network to establish a table that pairs internet protocol (IP) addresses with media access control (MAC) addresses. An ARP poisoning attack is when an adversary sends falsified ARP packets to the default gateway to modify the table so that the adversary’s device receives traffic intended for the target by linking the target’s IP address to the adversary’s MAC address. Faking a MAC address is called MAC spoofing. This is an example of an on-path attack (or man-in-the-middle attack), which is when an adversary interrupts a data stream between two parties, captures both parties’ data, and copies or alters the data before sending them on. Both parties think they are communicating directly with each other, but instead they are each communicating with the adversary who is secretly intercepting their messages.
- 3.1.A.2 A MAC flooding attack is when an adversary sends the target switch many Ethernet frames, each with a different MAC address. This can force the switch into broadcast mode, and the adversary can then collect all of the frames on the network (because they are being broadcast), which could allow the adversary to access sensitive information. This is an example of eavesdropping (or sniffing), which is when an adversary captures data in transit and can record and copy the data.
- 3.1.A.3 A domain name system (DNS) poisoning attack is when an adversary pretends to be an authoritative name server (NS) and plants a fake DNS record on a DNS server to redirect browser traffic to a malicious website designed to steal credentials. This is an example of credential harvesting, which is when adversaries set up a fake login site that looks like a real one. Unsuspecting users enter their real credentials, which the adversaries capture and use.
- 3.1.A.4 A smurf attack attempts to overwhelm a network with Internet Control Message Protocol (ICMP) requests. It is a type of denial of service (DoS) attack, which makes a system or resource unavailable to authorized users. During a smurf attack, an adversary sends many ICMP requests with the victim’s address to the network’s broadcast address. The network’s gateway then sends these requests to all devices on the network. Each device on the network replies to the victim’s address, creating a flood of traffic that can block legitimate messages. When multiple devices attack the same target simultaneously, it’s called a distributed denial of service (DDoS) attack.
Learning Objective 3.1.B: Explain how adversaries can exploit network vulnerabilities to steal, disrupt, or destroy network communication.
- 3.1.B.1 Adversaries can send malicious traffic into a network to flood it creating a DoS, to map the internal structure of the network, or to spoof a legitimate device. Networks without firewalls, or with improperly configured firewalls, are vulnerable to these types of attacks.
- 3.1.B.2 Adversaries that have compromised a device often attempt to leverage their access to compromise other devices on the local area network (LAN).
- 3.1.B.3 Adversaries that physically plug into a data port can gain access to a LAN through the switch port unless port security is enabled. This allows adversaries to launch DoS attacks or perform MAC flooding or MAC spoofing attacks.
- 3.1.B.4 Adversaries standing outside of physically secure spaces can pick up the signals and beacon frames from a wireless access point that is broadcasting outside the physical space. This allows them to gather information about the wireless network and to attempt eavesdropping and cryptographic attacks on it.
- 3.1.B.5 Adversaries can attempt to join networks to launch attacks from within the networks. Networks that do not authenticate devices and users make it easier for adversaries to join.
- 3.1.B.6 If there is an open network port, an adversary can plug a wireless access point into the port creating a rogue access point. The adversary could use this rogue access point to access the internal network wirelessly (maybe even from outside the physical space). This allows the adversary direct access to the LAN, bypassing any firewalls.
- 3.1.B.7 Adversaries can attempt to break wireless encryption and intercept, steal, or compromise data on a network.
Learning Objective 3.1.C: Assess and document risks from network vulnerabilities.
- 3.1.C.1 Vulnerabilities on a network can lead to adversaries being able to intercept and alter data in transit, launch DoS attacks, or move laterally on a network to gain access to more sensitive or critical systems. Network vulnerabilities can constitute a risk to confidentiality, integrity, and availability.
- 3.1.C.2 There are automated vulnerability scanners that can check networks, devices, and applications for known vulnerabilities. These scanners produce a report that often includes the vulnerabilities detected, their severity, and mitigation recommendations.
- 3.1.C.3 Successfully exploiting a network vulnerability often requires advanced technical ability and knowledge. This can impact the likelihood of an exploit.
- 3.1.C.4 High risks from network vulnerabilities allow an adversary to easily have a significant impact by capturing network traffic, spoofing a legitimate device on the network, or launching a DoS attack.
- Illustrative examples for 3.1.C.4:
- An organization has a single unsegmented internal network that is accessible via a wireless network with weak encryption, and on that network it has a server running its proprietary web-application.
- Illustrative examples for 3.1.C.4:
- 3.1.C.5 Moderate risks from network vulnerabilities could include vulnerabilities that might give adversaries the ability to gain information about systems or devices on a network.
- Illustrative examples for 3.1.C.5:
- An organization’s external firewall is not configured to block external ICMP traffic.
- Illustrative examples for 3.1.C.5:
- 3.1.C.6 Low risks from network vulnerabilities include vulnerabilities that would be difficult to exploit and would likely have minimal negative impacts on an organization.
- Illustrative examples for 3.1.C.6:
- An organization has wireless access points that broadcast a beacon frame, which contains the network service set identifier (SSID) and the wireless encryption protocols.
- Illustrative examples for 3.1.C.6:
学習目標 3.1.A: 一般的なネットワーク攻撃を特定する。
- 3.1.A.1 アドレス解像プロトコル (ARP) は、ネットワーク上のデフォルトゲートウェイによって使用され、インターネットプロトコル (IP) アドレスとメディアアクセスコントロール (MAC) アドレスをペアにするテーブルを構築するために用いられる。ARP ポイズニング攻撃とは、敵対者が偽造された ARP パケットをデフォルトゲートウェイに送信し、ターゲットの IP アドレスを敵対者の MAC アドレスにリンクすることで、ターゲット宛てのトラフィックを敵対者のデバイスに転送するようにテーブルを変更することである。MAC アダプタを偽装することを MAC スPUフィングという。これはオンパス攻撃(またはミドルマン攻撃)の例であり、敵対者が2者間のデータストリームを遮断し、両者のデータをキャッチし、送信する前にデータをコピーまたは改変する攻撃である。双方は互いに直接通信していると思っているが、実際には各自が敵対者と通信しており、そのメッセージが密かに傍受されている状態となる。
- 3.1.A.2 MAC フラッディング攻撃とは、敵対者が異なる MAC アダプタを持つ多数のエターネットフレームをターゲットスイッチに送信することである。これによりスイッチがブロードキャストモードに強制され、敵対者はネットワーク上のすべてのフレームを収集できる(これらはブロードキャストされているため)。これにより、敵対者は機密情報へのアクセスが可能になる可能性がある。これはイブスドロップ(またはスニフィング)の例であり、敵対者が進行中のデータをキャッチし、記録・コピーできる攻撃である。
- 3.1.A.3 DNS ポイズニング攻撃とは、敵対者が権威あるネームサーバー (NS) を装い、DNS サーバーに偽の DNS レコード植入して、認証情報を盗むために設計された悪意のあるウェブサイトへブラウザのトラフィックをリダイレクトすることである。これはクレデンシャルハーベストingの例であり、敵対者が本物のように見える偽のログインサイトを设置し、無邪気なユーザーが本物の認証情報を入力すると、それらを敵対者がキャッチして利用する攻撃である。
- 3.1.A.4 スマーフ攻撃は、インターネットコントロールメッセージプロトコル (ICMP) リクエストでネットワークを飽和させようとする攻撃である。これは denial of service (DoS) 攻撃の一種であり、システムやリソースを authorized users が利用できないようにする攻撃である。スマーフ攻撃中、敵対者は被害者のアドレスを含む多数の ICMP リクエストをネットワークのブロードキャストアドレスに送信する。ネットワークのゲートウェイはこれらのリクエストをネットワーク上のすべてのデバイスに送信する。各デバイスは被害者のアドレスに返信し、正規のメッセージをブロックする可能性のあるトラフィックの洪水を生み出す。複数のデバイスが同時に同じターゲットを攻撃する場合、これを分散 denial of service (DDoS) 攻撃と呼ぶ。
学習目標 3.1.B: 敵対者がネットワーク脆弱性をどう活用してネットワーク通信を盗聴、妨害、破壊するか説明する。
- 3.1.B.1 敵対者は、DoS を引き起こすためにネットワークを飽和させる恶意trafficを送信したり、ネットワークの内部構造をマッピングしたり、合法デバイスを偽装したりできる。ファイアウォールがない、または適切に構成されていないファイアウォールを持つネットワークは、これらの攻撃に脆弱である。
- 3.1.B.2 デバイスを乗っ取った敵対者は、ローカルエリアネットワーク (LAN) 上の他のデバイスも乗っ取るためにそのアクセスを利用しようとする傾向がある。
- 3.1.B.3 敵対者がデータポートに物理的に接続した場合、ポートセキュリティが有効化されていない限り、スイッチポートを通じて LAN にアクセスできる。これにより、敵対者は DoS 攻撃を実行したり、MAC フラッディングや MAC スPUフィング攻撃を行ったりできる。
- 3.1.B.4 物理的に安全なスペースの外にいる敵対者は、物理的空間の外にブロードキャストされているワイヤレスアクセスポイントからの信号やビコンフレームをキャッチできる。これにより、ワイヤレスネットワークに関する情報を収集し、それに対するイブスドロップ暗号化攻撃を試みることが可能になる。
- 3.1.B.5 敵対者はネットワークに参加して、その内部から攻撃を行うことを試みることがある。デバイスやユーザーを認証しないネットワークでは、敵対者が参加することが容易になる。
- 3.1.B.6 開放されたネットワークポートがある場合、攻撃者はそのポートにワイヤレスアクセスポイントを接続し、不正アクセスポイントを作成できます。攻撃者はこの不正アクセスポイントを利用して、内部ネットワークに無線でアクセスすることが可能であり(物理的な空間の外からでも)、これによりファイアウォールを回避してLANへの直接アクセスが可能になります。
- 3.1.B.7 攻撃者は、ワイヤレス暗号化の解除を試み、ネットワーク上のデータを傍受、盗取、または侵害しようとする可能性があります。
学習目標 3.1.C: ネットワーク脆弱性からのリスクを評価・文書化する。
- 3.1.C.1 ネットワーク上の脆弱性は、攻撃者が送信中のデータを傍受・改変したり、DoS攻撃を実行したり、ネットワーク上で横方向に移動してより敏感かつ重要なシステムへのアクセスを得たりする原因となることがあります。ネットワーク脆弱性は、機密性、完全性、可用性に対するリスクとなる可能性があります。
- 3.1.C.2 既知の脆弱性に対してネットワーク、デバイス、アプリケーションを検査できる自動化された脆弱性スキャナがあります。これらのスキャナは、検出された脆弱性、その深刻度、および軽減策に関する推奨事項を含むレポートを生成します。
- 3.1.C.3 ネットワーク脆弱性を成功裏に悪用するには、高度な技術的能力及び知識が通常必要です。これはエクスプロイトの可能性に影響を与えます。
- 3.1.C.4 ネットワーク脆弱性による高リスクは、攻撃者がネットワークトラフィックをキャプチャしたり、ネットワーク上の正規デバイスを偽装したり、DoS攻撃を実行したりすることで、容易に重大な影響を与えることを意味します。
- 3.1.C.4 の例:
- 組織が単一の未分割内部ネットワークを持ち、弱体な暗号化を持つワイヤレスネットワークを通じてアクセス可能であり、そのネットワーク上で独自ウェブアプリケーションを実行しているサーバーを運用している場合。
- 3.1.C.4 の例:
- 3.1.C.5 ネットワーク脆弱性による中程度のリスクには、攻撃者にネットワーク上のシステムやデバイスに関する情報を取得させる可能性がある脆弱性が含まれます。
- 3.1.C.5 の例:
- 組織の外部ファイアウォールが、外部ICMPトラフィックをブロックするように設定されていない場合。
- 3.1.C.5 の例:
- 3.1.C.6 ネットワーク脆弱性による低リスクには、悪用が困難であり、組織に与える否定的な影響が最小限である可能性が高い脆弱性が含まれます。
- 3.1.C.6 の例:
- 組織が、ネットワークサービスセットID(SSID)およびワイヤレス暗号化プロトコルを含むビーコンフレームをブロードキャストするワイヤレスアクセスポイントを持っている場合。
- 3.1.C.6 の例:

