Chapter 2: Types of Attacks
Core Objectives of Network Defense
Network security countermeasures and defense principles require identifying common network attack vectors, understanding their execution mechanisms, implementing mitigation controls, and configuring network devices and host operating systems to prevent compromise.
The primary categories of network attacks include:
Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks
Buffer overflow attacks
Trojan horse and virus attacks
Session hijacking
IP spoofing
Effective system configuration procedures focus on hardening operating systems against buffer overflow vulnerabilities, preventing unauthorized access via Trojan horses, and mitigating resource exhaustion from denial of service exploits.
Denial of Service (DoS) and Distributed Denial of Service (DDoS) Attacks
Fundamental Premise of DoS Attacks:
All host computers, network devices, and software applications operate under finite processing, memory, and bandwidth limitations.
Denial of Service attacks exploit these limitations by flooding a target with traffic or processing requests until system resources are exhausted and service to legitimate users is disrupted.
Execution Mechanisms and Utilities:
Basic DoS attacks frequently utilize standard network diagnostic utilities such as the
pingcommand to generate network traffic.In command-line environments, available syntax options and parameters for the
pingutility can be reviewed using switches such as/?or/h.While normal usage involves a standard traffic flow between a client and a server, a DoS attack generates excessive traffic that saturates the server's operational capabilities.
Distributed Denial of Service (DDoS):
A DDoS attack is an advanced variation of a DoS attack launched concurrently from multiple distributed client machines.
Attackers utilize compromised intermediate hosts—referred to as zombie machines or botnets—to amplify traffic volume.
The use of zombie machines obfuscates the primary attacker's identity, making DDoS attacks significantly harder to trace, filter, and mitigate compared to single-source DoS attacks.
Specific Denial of Service Vectors
TCP SYN Flood:
Takes advantage of the standard Transmission Control Protocol (TCP) three-way handshake mechanism.
The attacking machine sends a continuous stream of initial TCP SYN packets with spoofed or unroutable source addresses. The target server responds with SYN-ACK packets and reserves memory resources waiting for final ACK responses that are never returned.
Specific countermeasures and mitigations for TCP SYN Floods include:
Micro Blocks: Allocating miniature memory structures (a few bytes) for pending TCP connection states rather than full connection objects.
Bandwidth Throttling: Capping the rate of incoming SYN connection requests allowed through network interfaces.
SYN Cookies: Encoding initial TCP connection parameters into the initial sequence number () sent in the SYN-ACK, eliminating the need to allocate memory on the server until the client completes the handshake with a valid ACK packet.
RST Cookies: Sending an intentionally invalid SYN-ACK response to force a legitimate client to reply with a TCP RST packet, verifying host authenticity before reserving resources.
Stack Tweaking: Altering network operating system TCP/IP stack parameters (e.g., reducing connection timeout periods or increasing the maximum backlog queue size).
Smurf Attack:
A widely recognized, high-volume attack vector that leverages Internet Control Message Protocol (ICMP) echo request packets for traffic amplification.
The attacking machine sends ICMP echo requests to an IP network broadcast address (e.g., ) with the source IP address spoofed to match the target machine's IP address.
Every active computer on the broadcast network responds to the ICMP request by sending ICMP echo replies directly to the spoofed target machine, flooding its network interface.
Ping of Death (PoD):
Directly attacks host operating systems that cannot properly handle malformed or oversized network packets.
Involves sending ICMP echo requests exceeding the maximum permissible IPv4 packet size limit of . Malformed structural components can follow execution paths such as
packets/Ping/ICMP/ICMPv6/Container/Error/.Defensive posture requires ensuring all operating systems are fully updated with security patches; virtually all modern operating systems automatically detect and drop oversized packets.
UDP Flood:
A variation of packet-flooding techniques that targets open User Datagram Protocol (UDP) host ports.
Executes faster than TCP floods because UDP is a connectionless protocol that requires no connection handshake or packet acknowledgments.
The attacker floods random, unassigned ports with UDP datagrams; processing these invalid requests forces the target computer to exhaust CPU cycles sending ICMP "Port Unreachable" responses, ultimately causing system shutdown or severe instability.
ICMP Flood:
Alternative terminology for a standard ping flood attack, involving the continuous transmission of rapid ICMP echo request packets to consume target upstream and downstream bandwidth.
DHCP Starvation:
Exhausts available Dynamic Host Configuration Protocol pools by flooding the server with forged MAC addresses, preventing valid hosts from obtaining IP addresses.
HTTP Post DoS:
An application-layer DoS vector that sends legitimate HTTP POST request headers specifying a large payload, but delivers the message body at an extremely slow rate (e.g., one byte every few hundred seconds).
Occupies server thread resources and web server connection limits, effectively hanging the server for legitimate web traffic.
Permanent Denial of Service (PDoS) / Phlashing:
An extremely severe, non-recoverable attack vector aimed at permanently damaging host hardware.
Exploits hardware firmware vulnerabilities (often flashing corrupt, illegitimate BIOS or system firmware updates remotely) to render the target physical device completely unbootable.
Distributed Reflection Denial of Service (DRDoS):
Leverages intermediate Internet routers to amplify and reflect DoS traffic toward a target machine.
Routers used in a DRDoS attack do not need to be compromised or infected.
The attacking machine transmits connection requests to multiple Internet routers while forging the source address as the target machine's IP address. The routers automatically send reflected response packets to the victim host.
Mitigated on network routers by configuring interfaces to block and refrain from forwarding directed broadcast packets.
DoS Attack Tools and Real-World Malware Examples
Publicly Available DoS Software Tools:
Attack software tools are easily downloadable from public Internet repositories, facilitating widespread execution even by unsophisticated actors.
Common DoS/DDoS execution tools include:
Low Orbit Ion Cannon (LOIC): An open-source network stress testing and DoS attack application.
High Orbit Ion Cannon (HOIC): A high-speed, multi-threaded HTTP flood attack tool.
DOSHTTP: A specialized HTTP flood testing utility.
Stacheldraht: A classic distributed denial-of-service tool featuring multi-layered master/agent botnet control structures.
Notable Real-World Malware Case Examples:
FakeAV: Also designated as Fake AntiVirus, Rogue AntiVirus, Rogues, or ScareWare. Rogue security applications that display fraudulent alert messages claiming system infection to extort money or install secondary payloads.
Flame: Also known as Flamer, skyWlper, and Skywiper. Advanced, highly modular computer malware that specifically targets host operating systems running Microsoft Windows.
GameoverZeuS: A peer-to-peer (P2P) botnet architecture developed using core components of the earlier ZeuS Trojan, created by Russian hacker Evgeniy Mikhailovich Bogachev.
CryptoLocker and CryptoWall: High-impact ransomware families designed to encrypt host storage drives and demand ransom payments for decryption keys.
MyDoom: A high-speed, mass-mailing email worm designed to open backdoors and initiate automated network flooding.
Strategies for Defending Against Denial of Service Attacks
Gain a thorough, technical understanding of specific attack vectors and how each exploit is perpetrated.
Configure firewall rule bases to block unnecessary incoming protocols or temporarily drop all external traffic during an active breach (though complete blocking is often impractical for commercial operations).
Establish a network baseline threshold to continuously monitor normal traffic levels; abnormal deviations provide early indicators of incoming DoS activity.
Disable the forwarding of directed IP broadcast packets across all network routers to prevent reflection attacks.
Install, update, and maintain enterprise antivirus software across every client node connected to the network.
Enforce a continuous operating system patching policy to remediate system vulnerabilities.
Formulate and enforce strict administrative downloading policies regulating software acquisition and execution.
Consult baseline security guidelines and frameworks, such as those published at
www.sans.org/dosstep.
Buffer Overflow Attacks and Defensive Strategies
Mechanics of Buffer Overflow Attacks:
Memory buffers are designated memory storage blocks set aside by programs to temporarily hold data input (e.g., variables such as textboxes, credit card numbers, or dates).
A buffer overflow occurs when an application receives more data than its allocated buffer is designed to hold.
Exploit payloads violate bounds checking rules of programming languages, causing extra data to spill past the buffer boundary and overwrite adjacent memory addresses.
Execution visualization: An attacking machine transmits a buffer overflow packet containing extra data blocks beyond the capacity of the target machine's memory buffer (e.g., sending a payload with two extra blocks beyond the designated buffer size). The target system accepts the input and loads the excess data directly into adjacent host memory.
Overwriting adjacent stack or heap memory allows attackers to inject and execute arbitrary malicious code or corrupt application control flow.
Script viruses are frequently constructed to deliver or trigger buffer overflow vulnerabilities in target systems.
Countermeasures and Mitigation:
Implement secure software development lifecycles (SDLC) focusing on bounds checking, input sanitization, and variable safety.
Maintain continuous patch management programs to regularly update software applications and system software.
Keep operating system security patches fully up to date to remediate newly discovered memory management flaws.
IP Spoofing Mechanics and Vulnerabilities
Mechanics:
IP spoofing involves maliciously altering the source address in an IP packet header to impersonate a trusted computer system and gain unauthorized network access.
Though defensive controls have made IP spoofing less prevalent, architectural design flaws leave specific systems exposed.
Specific Network Vulnerabilities:
External border routers configured with direct connections to multiple internal network subnets.
Legacy proxy firewalls that rely exclusively on incoming source IP addresses for access control and client authentication.
Routers that perform internal subnetting without strict ingress or egress packet verification.
Networks permitting unfiltered incoming packets that carry source IP addresses belonging to the internal local network or domain.
Session Hijacking Countermeasures
Occurs when an attacker intercepts and takes complete control of an active TCP connection session between two authenticated endpoints.
The most common form of session hijacking is the "man-in-the-middle" (MitM) attack vector, where the attacker positions themselves transparently between communicating nodes.
Session hijacking can also occur if an attacker gains direct unauthorized local access to either the client or server host machine.
Primary Mitigation: Robust end-to-end network encryption protocols (such as IPsec or TLS) represent the only effective defense against session hijacking.
Virus Attacks, Mechanisms, and Protection Procedures
Characteristics:
Viruses represent one of the most persistent and common security threats to modern enterprise networks.
Viruses typically propagate across systems using two primary automated mechanics:
Actively scanning local subnets and network adapters to locate and exploit connected network devices.
Reading local email client address books and automatically sending self-replicating infected messages to every listed contact.
Notable Examples:
Sobig Virus
Mimail
Bagle
Sasser
Required Protection Rules:
Install, enable, and continually update anti-virus scanning software on all client systems.
Establish a strict operational policy against opening unverified or unexpected email attachments.
Establish personal authentication mechanisms (such as verified code words) with friends and business colleagues to validate emailed files prior to execution.
Ignore and do not act upon unverified, unsolicited security alerts, pop-ups, or warning messages.
Trojan Horse Attacks and Legal Implications
Program Capabilities:
A Trojan horse is a program that appears benign, useful, or harmless to the user while concealing hidden malicious routines.
Upon execution, Trojan horses perform unauthorized actions, including:
Silently downloading secondary harmful software payloads.
Installing covert keyloggers or specialized spyware to harvest credentials and personal data.
Corrupting, encrypting, or deleting critical system files.
Opening backdoor network listeners to grant remote attackers full remote access.
Legal and Criminal Penalties:
Creating, testing, or deploying Trojan horse programs constitutes a major criminal offense.
Release of Trojan horse malware triggers prosecution under federal and state computer crime statutes, resulting in significant mandatory prison sentences and civil monetary penalties.
Summary of Network Countermeasures
Summary of Primary Network Attacks:
Session Hijacking
Virus and Trojan Horse Attacks
Denial of Service (DoS) and Distributed Denial of Service (DDoS)
Buffer Overflow Exploits
General Network Security Controls:
Deploy and maintain enterprise antivirus software across endpoints.
Implement hardened router interface configurations (e.g., blocking directed IP broadcasts).
Implement strict administrative rules governing email attachments, software execution, and file downloads.
Monitor network traffic baselines continuously to spot anomalous behavior.
Enforce systemic patch management programs to keep all system software updated against known vulnerabilities.
Leverage proxy servers and restrictive internet access policies to control software deployment.