Network Attacks Flashcards
Virus
Infection of system that modifies behavior
Worm
Code that propagates / replicates across network
Worm Lifecycle
Scan for vulnerable hosts
Infect hosts
Remain undiscovered
Famous Worms
Morris Worm Code Red 1v2 Code Red 2 Nimda Slammer Worm
Model spread of worms
Random Constant Spread Model
Spam
Work overhead (designing filters)
Storage (servers save mail)
Security (phishing emails)
Spam filters
content
IP
behavior
Dos Defense
Ingress filtering
Reverse Path Filtering check
Syn Cookies
Backscatter
Assume source IPs are spoofed
Measure traffic going back to source IPs
Why do defenses fail against crossfire DDoS?
Bots dont spoof IPs
Traffic is legitimate traffic
Low intensity flows dont trip sensors
Why does crossfire attack dynamically change set of target links?
Conduct a rolling attack as to not trip router failure detection mechanisms