Learning Objective 3.1.A: Identify common network attacks.
- 3.1.A.1 The address resolution protocol (ARP) is used by a default gateway on a network to establish a table that pairs internet protocol (IP) addresses with media access control (MAC) addresses. An ARP poisoning attack is when an adversary sends falsified ARP packets to the default gateway to modify the table so that the adversary’s device receives traffic intended for the target by linking the target’s IP address to the adversary’s MAC address. Faking a MAC address is called MAC spoofing. This is an example of an on-path attack (or man-in-the-middle attack), which is when an adversary interrupts a data stream between two parties, captures both parties’ data, and copies or alters the data before sending them on. Both parties think they are communicating directly with each other, but instead they are each communicating with the adversary who is secretly intercepting their messages.
- 3.1.A.2 A MAC flooding attack is when an adversary sends the target switch many Ethernet frames, each with a different MAC address. This can force the switch into broadcast mode, and the adversary can then collect all of the frames on the network (because they are being broadcast), which could allow the adversary to access sensitive information. This is an example of eavesdropping (or sniffing), which is when an adversary captures data in transit and can record and copy the data.
- 3.1.A.3 A domain name system (DNS) poisoning attack is when an adversary pretends to be an authoritative name server (NS) and plants a fake DNS record on a DNS server to redirect browser traffic to a malicious website designed to steal credentials. This is an example of credential harvesting, which is when adversaries set up a fake login site that looks like a real one. Unsuspecting users enter their real credentials, which the adversaries capture and use.
- 3.1.A.4 A smurf attack attempts to overwhelm a network with Internet Control Message Protocol (ICMP) requests. It is a type of denial of service (DoS) attack, which makes a system or resource unavailable to authorized users. During a smurf attack, an adversary sends many ICMP requests with the victim’s address to the network’s broadcast address. The network’s gateway then sends these requests to all devices on the network. Each device on the network replies to the victim’s address, creating a flood of traffic that can block legitimate messages. When multiple devices attack the same target simultaneously, it’s called a distributed denial of service (DDoS) attack.
Learning Objective 3.1.B: Explain how adversaries can exploit network vulnerabilities to steal, disrupt, or destroy network communication.
- 3.1.B.1 Adversaries can send malicious traffic into a network to flood it creating a DoS, to map the internal structure of the network, or to spoof a legitimate device. Networks without firewalls, or with improperly configured firewalls, are vulnerable to these types of attacks.
- 3.1.B.2 Adversaries that have compromised a device often attempt to leverage their access to compromise other devices on the local area network (LAN).
- 3.1.B.3 Adversaries that physically plug into a data port can gain access to a LAN through the switch port unless port security is enabled. This allows adversaries to launch DoS attacks or perform MAC flooding or MAC spoofing attacks.
- 3.1.B.4 Adversaries standing outside of physically secure spaces can pick up the signals and beacon frames from a wireless access point that is broadcasting outside the physical space. This allows them to gather information about the wireless network and to attempt eavesdropping and cryptographic attacks on it.
- 3.1.B.5 Adversaries can attempt to join networks to launch attacks from within the networks. Networks that do not authenticate devices and users make it easier for adversaries to join.
- 3.1.B.6 If there is an open network port, an adversary can plug a wireless access point into the port creating a rogue access point. The adversary could use this rogue access point to access the internal network wirelessly (maybe even from outside the physical space). This allows the adversary direct access to the LAN, bypassing any firewalls.
- 3.1.B.7 Adversaries can attempt to break wireless encryption and intercept, steal, or compromise data on a network.
Learning Objective 3.1.C: Assess and document risks from network vulnerabilities.
- 3.1.C.1 Vulnerabilities on a network can lead to adversaries being able to intercept and alter data in transit, launch DoS attacks, or move laterally on a network to gain access to more sensitive or critical systems. Network vulnerabilities can constitute a risk to confidentiality, integrity, and availability.
- 3.1.C.2 There are automated vulnerability scanners that can check networks, devices, and applications for known vulnerabilities. These scanners produce a report that often includes the vulnerabilities detected, their severity, and mitigation recommendations.
- 3.1.C.3 Successfully exploiting a network vulnerability often requires advanced technical ability and knowledge. This can impact the likelihood of an exploit.
- 3.1.C.4 High risks from network vulnerabilities allow an adversary to easily have a significant impact by capturing network traffic, spoofing a legitimate device on the network, or launching a DoS attack.
- Illustrative examples for 3.1.C.4:
- An organization has a single unsegmented internal network that is accessible via a wireless network with weak encryption, and on that network it has a server running its proprietary web-application.
- Illustrative examples for 3.1.C.4:
- 3.1.C.5 Moderate risks from network vulnerabilities could include vulnerabilities that might give adversaries the ability to gain information about systems or devices on a network.
- Illustrative examples for 3.1.C.5:
- An organization’s external firewall is not configured to block external ICMP traffic.
- Illustrative examples for 3.1.C.5:
- 3.1.C.6 Low risks from network vulnerabilities include vulnerabilities that would be difficult to exploit and would likely have minimal negative impacts on an organization.
- Illustrative examples for 3.1.C.6:
- An organization has wireless access points that broadcast a beacon frame, which contains the network service set identifier (SSID) and the wireless encryption protocols.
- Illustrative examples for 3.1.C.6:
학습 목표 3.1.A: 일반적인 네트워크 공격을 식별하십시오.
- 3.1.A.1 주소 해결 프로토콜(ARP)은 네트워크의 기본 게이트웨이에서 인터넷 프로토콜(IP) 주소를 미디어 액세스 제어(MAC) 주소와 짝짓기하는 표를 생성하는 데 사용됩니다. ARP 포이징 공격은 적대자가 기본 게이트웨이에 위조된 ARP 패킷을 전송하여 표를 수정함으로써 타의 IP 주소를 적대자의 MAC 주소와 연결하고, 타겟으로 향해야 할 트래픽을 적대자 장치가 reception하게 만드는 것입니다. MAC 주위를 위장하는 것을 MAC 스포핑(MAC spoofing)이라고 합니다. 이는 온패스(on-path) 공격(또는 맨-인-더-미들(man-in-the-middle) 공격)의 예입니다. 이 공격은 적대자가 두 당사자 사이의 데이터 스트림을 중계하여 양쪽의 데이터를 캡처하고, 전송 전에数据进行 복제하거나 변조하는 경우를 말합니다. 두 당사자는 서로 직접 통신한다고 생각하지만, 실제로는 각자가 자신의 메시지를 비밀리에 도청하는 적대자와 소통하고 있습니다.
- 3.1.A.2 MAC 플러딩(MAC flooding) 공격은 적대자가 타겟 스위치에 서로 다른 MAC 주소를 가진 수많은 이더넷 프레임을 전송하는 경우입니다. 이로 인해 스위치가 브로드캐스트 모드로 전환되고, 적대자는 네트워크상의 모든 프레임(브로드캐스트되기 때문에)을 수집할 수 있게 되며, 이는 민감한 정보에 접근할 수 있음을 의미할 수 있습니다. 이는 이브dropping(또는 스니핑, sniffing)의 예입니다. 이攻击은 적대자가 전송 중인 데이터를 캡처하고 기록 및 복제할 수 있는 경우를 말합니다.
- 3.1.A.3 DNS 포이징(DNS poisoning) 공격은 적대자가 권위 있는 네임 서버(NS)인 척하여 DNS 서버에 가짜 DNS 레코드를 심어 브라우저 트래픽을 자격증 도난을 목적으로 하는 악성 웹사이트로 리디렉션시키는 경우입니다. 이는 크레덴셜 하버스팅(credential harvesting)의 예입니다. 이는 적대자가 실제와 유사한 가짜 로그인 사이트를 설치하여 무고한 사용자들이 실제 자격증을 입력하게 하고, 이를 capture하여 사용하는 경우를 말합니다.
- 3.1.A.4 스머프(Smurf) 공격은 인터넷 제어 메시지 프로토콜(ICMP) 요청을 사용하여 네트워크를 과부하 상태로 만들려는 시도를 합니다. 이는 서비스 부재(DoS) 공격의 일종으로,AUTHORIZED 사용자에게 시스템이나 자원을 사용 불가능하게 만듭니다. 스머프 공격 중 적대자는 피해자 주소가 포함된 수많은 ICMP 요청을 네트워크의 브로드캐스트 주소로 전송합니다. 네트워크 게이트웨이는 이러한 요청을 네트워크상의 모든 장치로 전송합니다. 네트워크상의 각 장치는 피해자 주소로 응답하며, 정당한 메시지를 차단할 수 있는 트래픽 폭을 생성합니다. 여러 장치가 동일한 타겟을 동시에 공격할 때는 분산 서비스 부재(DDoS) 공격이라고 합니다.
학습 목표 3.1.B: 적대자가 네트워크 취약점을如何利用하여 네트워크 통신을 도난, 방해 또는 파괴할 수 있는지 설명하십시오.
- 3.1.B.1 적대자는 네트워크를 DoS로 과부하状态로 만들거나 내부 네트워크 구조를 매핑하거나 정당한 장치를 스포핑하기 위해 악성 트래픽을 네트워크에 보낼 수 있습니다. 방화벽이 없거나 부적절하게 구성된 방화벽이 있는 네트워크는 이러한 유형의 공격에 취약합니다.
- 3.1.B.2 장치를 해킹한 적대자는 종종 로컬 영역 네트워크(LAN)상의 다른 장치도 해킹하기 위해 해당 액세스를 활용하려 시도합니다.
- 3.1.B.3 적대자가 데이터 포트에 물리적으로 연결하면 포트 보안이 활성화되지 않는 한 스위치 포트를 통해 LAN에 접근할 수 있습니다. 이는 적대자가 DoS 공격을 발동하거나 MAC 플러딩 또는 MAC 스포핑 공격을 수행할 수 있게 합니다.
- 3.1.B.4 물리적 보안 구역 외부에 서 있는 적대자는 물리적 구역 외부로 브로드캐스팅되는 무선 액세스 포인트의 신호와 Beacon 프레임을 capturing할 수 있습니다. 이를 통해 무선 네트워크에 대한 정보를 gather하고 이에 대한 이브dropping 및 암호화 공격을 시도할 수 있습니다.
- 3.1.B.5 적대자는 네트워크 내부에서 공격을 발동하기 위해 네트워크에 join하려는 시도를 할 수 있습니다. 장치와 사용자를 인증하지 않는 네트워크는 적대자가 join하기 쉽게 만듭니다.
- 3.1.B.6 개방된 네트워크 포트가 있다면, 적대자는 해당 포트에 무선 액세스 포인트를 연결하여 로거(Rogue) 액세스 포인트를 생성할 수 있다. 이 로거 액세스 포인트를 통해 내부 네트워크에 무선으로 접근할 수 있으며(물리적 공간 외부에서도 가능), 이는 방화벽을 우회하여 LAN에 직접 접근하게 한다.
- 3.1.B.7 적대자는 무선 암호화를 해킹하거나, 네트워크상의 데이터를 도청, 도난 또는 유출시키는 시도를 할 수 있다.
학습 목표 3.1.C: 네트워크 취약성으로부터의 위험을 평가하고 문서화한다.
- 3.1.C.1 네트워크의 취약성은 적대자에게 전송 중인数据进行 도청 및 변조하거나, DoS 공격을发起하거나, 네트워크 내에서 이동(navigating)하여 더 민감하거나 중요한 시스템에 접근하는 것을 허용할 수 있다. 네트워크 취약성은 기밀성, 무결성, 가용성에 대한 위험을 구성할 수 있다.
- 3.1.C.2 네트워크, 장치, 애플리케이션에서 알려진 취약점을 검사할 수 있는 자동화 취약점 스캐너가 있다. 이러한 스캐너는 일반적으로 탐지된 취약점, 그 심각도, 그리고 완화 방안을 포함하는 보고서를 생성한다.
- 3.1.C.3 네트워크 취약성을 성공적으로 악용하는 것은 종종 고도의 기술적 능력과 지식을 요구한다. 이는 악용 가능성에 영향을 미칠 수 있다.
- 3.1.C.4 네트워크 취약성에 대한 높은 위험은 적대자가 네트워크 트래픽을 포획하거나, 네트워크 상의 합법적인 장치를 위장(spoofing)하거나, DoS 공격을发起하여 쉽게 중대한 영향을 미치게 할 수 있게 한다.
- 3.1.C.4에 대한 예시:
- 한 조직은 무선 네트워크를 통해 접근 가능한 단일 분할되지 않은 내부 네트워크를 가지고 있으며, 해당 네트워크에는 자체 개발 웹 애플리케이션을 실행하는 서버가 있다.
- 3.1.C.4에 대한 예시:
- 3.1.C.5 네트워크 취약성에 대한 متوسط 위험은 적대자에게 네트워크 상의 시스템이나 장치에 대한 정보를 얻을 수 있게 하는 취약점을 포함할 수 있다.
- 3.1.C.5의 예시:
- 한 조직의 외부 방화벽이 외부 ICMP 트래픽을 차단하도록 설정되어 있지 않다.
- 3.1.C.5의 예시:
- 3.1.C.6 네트워크 취약성에 대한 낮은 위험은 악용하기 어려우며 조직에 미칠 부정적 영향이 극미미한 취약점을 포함한다.
- 3.1.C.6에 대한 예시:
- 한 조직의 무선 액세스 포인트가 네트워크 서비스 세트 식별자(SSID)와 무선 암호화 프로토콜을 포함 beacon frame를 방송한다.
- 3.1.C.6에 대한 예시:

