Network Vulnerabilities and Attacks · 网络漏洞与攻击
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| ARP poisoning/ɑːp ˈpɔɪzənɪŋ/ | 地址解析投毒 | dì zhǐ jiě xī tóu dú |
| on-path attack/ɒn pæθ əˈtæk/ | 中间人攻击 | zhōng jiān rén gōng jī |
| MAC flooding/mæk ˈflʌdɪŋ/ | 物理地址泛洪 | wù lǐ dì zhǐ fàn hóng |
| switch/swɪtʃ/ | 交换机 | jiāo huàn jī |
| eavesdropping/ˈiːvzdrɒpɪŋ/ | 窃听 | qiè tīng |
| DNS poisoning/ˌdiː en ˈes ˈpɔɪzənɪŋ/ | 域名投毒 | yù míng tóu dú |
| denial of service/dɪˈnaɪəl ɒv ˈsɜːvɪs/ | 拒绝服务 | jù jué fú wù |
| distributed denial of service/ˈdɪstrɪbjuːtɪd dɪˈnaɪəl ɒv ˈsɜːvɪs/ | 分布式拒绝服务 | fēn bù shì jù jué fú wù |
| rogue access point/rəʊɡ ˈækses pɔɪnt/ | 非法接入点 | fēi fǎ jiē rù diǎn |
On-path and flooding attacks
- ARP poisoning 地址解析投毒: fake ARP messages send traffic to the adversary — an on-path attack 中间人攻击.
- MAC flooding 物理地址泛洪: overloading a switch 交换机 so it broadcasts all traffic (eavesdropping 窃听).
- The adversary reads or alters messages between two parties.
中间人与洪泛攻击
- 地址解析投毒(ARP poisoning):伪造ARP消息把流量发给对手——一种中间人攻击(on-path attack)。
- 物理地址泛洪(MAC flooding):使交换机(switch)过载,让它广播所有流量(窃听eavesdropping)。
- 对手读取或更改两方之间的消息。
Redirection and denial
- DNS poisoning 域名投毒: a fake record redirects users to a malicious site.
- Smurf attack: an ICMP flood — a denial of service (DoS) 拒绝服务.
- Many machines at once = a distributed denial of service (DDoS) 分布式拒绝服务.
重定向与拒绝服务
- 域名投毒(DNS poisoning):伪造记录把用户重定向到恶意网站。
- Smurf攻击:ICMP洪泛——一种拒绝服务(denial of service)。
- 许多机器同时进行=分布式拒绝服务(distributed denial of service)。
Identify the network attack · 识别网络攻击
Each attack has a distinct trace: ARP=two MACs for one IP; MAC flooding=switch overload; DNS=redirect; smurf=ICMP flood. · 每种攻击都有独特的痕迹:ARP=一个IP对应两个MAC;MAC泛洪=交换机过载;DNS=重定向;Smurf=ICMP泛洪。
An adversary secretly sitting between two parties, reading their traffic, performs a(n)... · 一名敌对者秘密地坐在两方之间读取其流量,这属于……攻击
This is an on-path / man-in-the-middle attack. · 这是一种中间人 / on-path 攻击。
One IP address shown with two different MAC addresses in a log suggests... · 日志中显示一个IP地址对应两个不同的MAC地址,这表明……
Duplicate MAC for one IP = ARP poisoning. · 一个IP对应重复的MAC = ARP欺骗。
An unauthorised access point plugged into an open port is a ____ access point. · 插入开放端口的未授权接入点是一个____接入点。
A rogue access point bypasses the firewall. · 一个非法接入点可以绕过防火墙。
Which attacks let an adversary eavesdrop on traffic? (Choose all) · 哪些攻击允许敌对者窃听流量?(多选)
A UPS failure is not an eavesdropping attack. · UPS故障不是窃听攻击。
How networks get exploited
- An open port lets an attacker install a rogue access point 非法接入点.
- A rogue AP bypasses the firewall entirely.
- We rate risk by impact and the skill an exploit needs.
网络如何被利用
- 开放端口让攻击者安装非法接入点(rogue access point)。
- 非法接入点完全绕过防火墙。
- 我们按影响和漏洞利用所需技能来评定风险。
In an on-path (man-in-the-middle) attack, both parties think they are talking directly to each other. They are actually each talking to the adversary, who quietly reads or changes every message.
在中间人攻击中,双方都以为在直接交谈。实际上他们各自都在和对手交谈,对手悄悄读取或更改每一条消息。
When many machines flood a target at once, it is a distributed denial of service (DDoS). · 当多台机器同时向目标发起大量请求时,这是分布式拒绝服务(DDoS)。
Many attackers at once = DDoS. · 多个攻击者同时发动 = DDoS。
In ARP poisoning, the adversary tells the network "the target's IP belongs to MY hardware address." Traffic meant for the target now flows through the adversary first. The tell-tale sign in a log: one IP shown with two different MAC addresses.
在ARP投毒中,对手告诉网络"目标的IP属于我的硬件地址"。发往目标的流量现在先经过对手。日志中的明显迹象:一个IP显示两个不同的MAC地址。
Key network attacks: ARP poisoning (eavesdrop from an on-path / man-in-the-middle position), MAC flooding (eavesdrop by forcing the switch to broadcast every frame), DNS poisoning (redirect), and smurf/DoS/DDoS (flood). Weak or open ports let an adversary add a rogue access point that bypasses the firewall.
关键网络攻击:地址解析投毒(从中间人位置窃听)、物理地址泛洪(迫使交换机广播每一帧来窃听)、域名投毒(重定向)、smurf/DoS/DDoS(洪泛)。弱的或开放的端口让对手添加绕过防火墙的非法接入点。