Learning Objective 3.1.A: Identify common network attacks.
- 3.1.A.1 The address resolution protocol (ARP) is used by a default gateway on a network to establish a table that pairs internet protocol (IP) addresses with media access control (MAC) addresses. An ARP poisoning attack is when an adversary sends falsified ARP packets to the default gateway to modify the table so that the adversary’s device receives traffic intended for the target by linking the target’s IP address to the adversary’s MAC address. Faking a MAC address is called MAC spoofing. This is an example of an on-path attack (or man-in-the-middle attack), which is when an adversary interrupts a data stream between two parties, captures both parties’ data, and copies or alters the data before sending them on. Both parties think they are communicating directly with each other, but instead they are each communicating with the adversary who is secretly intercepting their messages.
- 3.1.A.2 A MAC flooding attack is when an adversary sends the target switch many Ethernet frames, each with a different MAC address. This can force the switch into broadcast mode, and the adversary can then collect all of the frames on the network (because they are being broadcast), which could allow the adversary to access sensitive information. This is an example of eavesdropping (or sniffing), which is when an adversary captures data in transit and can record and copy the data.
- 3.1.A.3 A domain name system (DNS) poisoning attack is when an adversary pretends to be an authoritative name server (NS) and plants a fake DNS record on a DNS server to redirect browser traffic to a malicious website designed to steal credentials. This is an example of credential harvesting, which is when adversaries set up a fake login site that looks like a real one. Unsuspecting users enter their real credentials, which the adversaries capture and use.
- 3.1.A.4 A smurf attack attempts to overwhelm a network with Internet Control Message Protocol (ICMP) requests. It is a type of denial of service (DoS) attack, which makes a system or resource unavailable to authorized users. During a smurf attack, an adversary sends many ICMP requests with the victim’s address to the network’s broadcast address. The network’s gateway then sends these requests to all devices on the network. Each device on the network replies to the victim’s address, creating a flood of traffic that can block legitimate messages. When multiple devices attack the same target simultaneously, it’s called a distributed denial of service (DDoS) attack.
Learning Objective 3.1.B: Explain how adversaries can exploit network vulnerabilities to steal, disrupt, or destroy network communication.
- 3.1.B.1 Adversaries can send malicious traffic into a network to flood it creating a DoS, to map the internal structure of the network, or to spoof a legitimate device. Networks without firewalls, or with improperly configured firewalls, are vulnerable to these types of attacks.
- 3.1.B.2 Adversaries that have compromised a device often attempt to leverage their access to compromise other devices on the local area network (LAN).
- 3.1.B.3 Adversaries that physically plug into a data port can gain access to a LAN through the switch port unless port security is enabled. This allows adversaries to launch DoS attacks or perform MAC flooding or MAC spoofing attacks.
- 3.1.B.4 Adversaries standing outside of physically secure spaces can pick up the signals and beacon frames from a wireless access point that is broadcasting outside the physical space. This allows them to gather information about the wireless network and to attempt eavesdropping and cryptographic attacks on it.
- 3.1.B.5 Adversaries can attempt to join networks to launch attacks from within the networks. Networks that do not authenticate devices and users make it easier for adversaries to join.
- 3.1.B.6 If there is an open network port, an adversary can plug a wireless access point into the port creating a rogue access point. The adversary could use this rogue access point to access the internal network wirelessly (maybe even from outside the physical space). This allows the adversary direct access to the LAN, bypassing any firewalls.
- 3.1.B.7 Adversaries can attempt to break wireless encryption and intercept, steal, or compromise data on a network.
Learning Objective 3.1.C: Assess and document risks from network vulnerabilities.
- 3.1.C.1 Vulnerabilities on a network can lead to adversaries being able to intercept and alter data in transit, launch DoS attacks, or move laterally on a network to gain access to more sensitive or critical systems. Network vulnerabilities can constitute a risk to confidentiality, integrity, and availability.
- 3.1.C.2 There are automated vulnerability scanners that can check networks, devices, and applications for known vulnerabilities. These scanners produce a report that often includes the vulnerabilities detected, their severity, and mitigation recommendations.
- 3.1.C.3 Successfully exploiting a network vulnerability often requires advanced technical ability and knowledge. This can impact the likelihood of an exploit.
- 3.1.C.4 High risks from network vulnerabilities allow an adversary to easily have a significant impact by capturing network traffic, spoofing a legitimate device on the network, or launching a DoS attack.
- Illustrative examples for 3.1.C.4:
- An organization has a single unsegmented internal network that is accessible via a wireless network with weak encryption, and on that network it has a server running its proprietary web-application.
- Illustrative examples for 3.1.C.4:
- 3.1.C.5 Moderate risks from network vulnerabilities could include vulnerabilities that might give adversaries the ability to gain information about systems or devices on a network.
- Illustrative examples for 3.1.C.5:
- An organization’s external firewall is not configured to block external ICMP traffic.
- Illustrative examples for 3.1.C.5:
- 3.1.C.6 Low risks from network vulnerabilities include vulnerabilities that would be difficult to exploit and would likely have minimal negative impacts on an organization.
- Illustrative examples for 3.1.C.6:
- An organization has wireless access points that broadcast a beacon frame, which contains the network service set identifier (SSID) and the wireless encryption protocols.
- Illustrative examples for 3.1.C.6:
מטרות למידה 3.1.A: זיהוי התקפות רשת נפוצות.
- 3.1.A.1 פרוטוקול פתרון כתובות (ARP) משמש על ידי שערי ברירת מחדל ברשת ליצירת טבלה המקשרת כתובות אינטרנט (IP) לכתובות בקרת גישה מדיה (MAC). התקפת הרשלת ARP היא כאשר אויב שולח חבילות ARP מזויפות לשער ברירת מחדל כדי לשנות את הטבלה כך שמכשיר האויב יקבל תנועה שנועדה ליעד על ידי חיבור כתובת ה-IP של היעד לכתובת ה-MAC של האויב. הזיוף של כתובת MAC נקרא MAC spoofing. זהו דוגמה להתקפה מסלול (או man-in-the-middle), שבה אויב מפריע לזרימת נתונים בין שני צדדים, תופס את הנתונים של שני הצדדים ומעתיק או משנה אותם לפני השליחה. שני הצדדים חושבים שהם תקשורת ישירה אחד עם השני, אך למעשה כל אחד תקשורת עם האויב שחוצץ בסתר בהודעותיהם.
- 3.1.A.2 התקפת הצפת MAC היא כאשר אויב שולח למתג היעד מספר רב של מסגות אתרנט, כל אחת עם כתובת MAC שונה. זאת יכולה להכריח את המתג לעבור למצב שידור (broadcast), ובכך האויב יכול לאסוף את כל המסגות ברשת (מכיוון שהן משודרות), מה שיכול לאפשר לאויב לגשת למידע רגיש. זהו דוגמה להקשבה (או sniffing), שבה אויב תופס נתונים בזמן מעבר ויכול להקליט ולהעתיק אותם.
- 3.1.A.3 התקפת הרשלת DNS היא כאשר אויב מתחזה לשירות שם מוסמך (NS) ומוטען רקCORD DNS מזויף על שרת DNS כדי להפנות תנועת דפדפן לאתר רע designed to steal credentials. זהו דוגמה לאיסוף תעודות זיהוי (credential harvesting), שבו אויבים יוצרים אתר התחברות מזויף שנראה כמו אתר אמיתי. משתמשים חסרי ספק מכניסים את תעודות הזיהוי האמיתיות שלהם, שהאויבים תופסים ומשתמשים בהן.
- 3.1.A.4 התקפת Smurf מנסה לעמוס רשת בבקשות Internet Control Message Protocol (ICMP). זוהי סוג של התקפת סירוב שירות (DoS), שמפחיתה את זמינות מערכת או משאב למשתמשים מורשים. במהלם התקפת Smurf, אויב שולח מספר רב של בקשות ICMP עם כתובת הקורבן לכתובת השידור של הרשת. שערי הרשת שולחים את הבקשות הללו לכל המכשירים ברשת. כל מכשיר ברשת מגיב לכתובת הקורבן, ויוצר גלישת תנועה שיכולה לחסום הודעות חוקיות. כאשר מספר מכשירים תוקפים אותו יעד בו-זמנית, נקראת ההתקפה התקפת סירוב שרות מבוזרת (DDoS).
מטרות למידה 3.1.B: הסבר כיצד אויבים יכולים לנצל חולשות רשת לגניבה, הפרעה או הרס תקשורת רשת.
- 3.1.B.1 מתקיפים יכולים לשלוח תנועה זדונית לתוך רשת כדי לטבול אותה ולגרום להפסקת שירות (DoS), לעצב את המבנה הפנימי של הרשת, או לגרסת התחברות של התקן חוקי. רשתות שאין בהן אשונות גדר, או שהאשונות הגדר שלהן מוגדרות באופן לא תקין, הן רגישות לסוגי התקפות אלו.
- 3.1.B.2 מתקיפים שפרצו התקן מסוים נטים לנצל את גישה זו כדי לפרץ התקנים אחרים ברשת מקומית (LAN).
- 3.1.B.3 התוקפים שמחברים פיזית לתא נתונים יכולים להשיג גישה לרשת LAN דרך יציאת הסוויץ' כל עוד ביטחון יציאה אינו מופעל. הדבר מאפשר להתוקפים להפעיל תקיפת DoS או לבצע תקיפות MAC flooding או MAC spoofing.
- 3.1.B.4 מתקיפים הנמצאים מחוץ לחללים בטוחים פיזית יכולים לקלוט אותות ומסגרות ביקור (beacon frames) מאחת נגישות אלחוטית שמשידרת מחוץ לחלל הפיזי. זה מאפשר להם לאסוף מידע על הרשת האלחוטית ולנסות לבצע ציתת דיבור והתקפות קריפטוגרפיות עליה.
- 3.1.B.5 מתקיפים יכולים לנסות להתחבר לרשתות כדי לבצע התקבות מתוכן הרשתות. רשתות שאינן מאמתות התקנים ומשתמשים מקלות על מתקיפים להתחבר אליהן.
- 3.1.B.6 אם יש פורט רשת פתוח, מתקין יכול לחבר אחת נגישות אלחוטית לפורט ליצירת אחת נגישות זדונית. המתקין יכול להשתמש באחת הנגישות הזו כדי לגשת לרשת הפנימית אלחוטית (ואולי גם מחוץ לחלל הפיזי). זה מאפשר למתקין גישה ישירה ל-LAN, סביב כל אשון גדר.
- 3.1.B.7 מתקיפים יכולים לנסות לשבור את ההצפנה של רשתות אלחוטיות ולהצית, לגנוב או לפגוע במידע ברשת.
מטרות למידה 3.1.C: הערכה ותיעוד סיכונים ממעורעוריות ברשתות.
- 3.1.C.1 מעורעוריות ברשת עשויות להוביל לכך שמתקיפים יוכלו להצית ולשנות מידע במעבר, לבצע התקבות DoS, או לנוע בצדדים ברשת כדי לגשת למערכות רגישות או קריטיות יותר. מעורעוריות ברשת יכולות להוות סיכון לנאמנות, שלמות וזמינות.
- 3.1.C.2 קיימים סורקי מעורעוריות אוטומטיים שיכולים לבדוק רשתות, התקנים ואפליקציות למעורעוריות ידועות. סורקים אלו מייצרים דוח המכלל לעיתים קרובות את המעורעוריות שזוהו, את חומרתן, והמלצות לטיפול.
- 3.1.C.3 ניצול מוצלח של מעורעוריות ברשת דורש לעיתים קרובות יכולת טכנית ומידע מתקדמים. הדבר יכול להשפיע על הסבירות לניצול.
- 3.1.C.4 סיכונים גבוהים ממעורעוריות ברשת מאפשרים למתקין להשיג השפעה משמעותית בקלות על ידי לכידת תנועת רשת, גרסת התחברות של התקן חוקי ברשת, או ביצוע התקבת DoS.
- דוגמאות מדגמיות ל-3.1.C.4:
- ארגון בעל רשת פנימית אחת שאינה מחולקת, הנגישה דרך רשת אלחוטית עם הצפנה חלשה, ועל הרשת הזו יש שרת המופעלת בו אפליקציית אינטרנט פרופריטארית.
- דוגמאות מדגמיות ל-3.1.C.4:
- 3.1.C.5 סיכונים בינוניים ממעורעוריות ברשת יכולים לכלול מעורעוריות שיכולות לתת למתקינים יכולת לקבל מידע על מערכות או התקנים ברשת.
- דוגמאות מדגמיות ל-3.1.C.5:
- אשון גדר חיצוני של ארגון אינו מוגדר כדי לחסום תנועת ICMP חיצונית.
- דוגמאות מדגמיות ל-3.1.C.5:
- 3.1.C.6 סיכונים נמוכים ממעורעוריות ברשת כוללים מעורעוריות שייהיו קשות לניצול ושמסביר שיהיו להן השפעות שליליות מינימליות על ארגון.
- דוגמאות מדגמיות ל-3.1.C.6:
- לארגון יש אחת נגישות אלחוטית שמשידרת מסגרת ביקור, המכילה את מזהה שרת השירות של הרשת (SSID) ואת פרוטוקולי ההצפנה האלחוטיים.
- דוגמאות מדגמיות ל-3.1.C.6:
*מארזי שרתים: חלוקת רשת מבודדת מערכים כך שפרצת אבטחה אחת לא פותחת את הכל
*ציוד רשת אמיתי: מצפן הוא מכשיר (או תוכנה) הממוקם במקום שבו כבלים אלו נפגשים עם העולם החיצוני