Network Security Flashcards
BGP Route hijacks
ASes believe other ASes routing advertisements, allowing an AS to hijack routes
DNS Reflection
Distributed Denial of Service
Security Components
Confidentiality
Integrity
Availability
Authenticity
Confidentiality
Information only provided to authorized parties
Integrity
Information isnt changed in storage / transit
Availability
Information accessible when needed
Authenticity
Information origin is accurate
Threat
Potential violation of security components
Attack
Action that violates a security component
Routing Security
Control Plane Authentication
Session
Path
Origin
DNS Masquerade
Spoof DNS Server IP address
Provide name:IP mapping to attackers address
Session Authentication
ASes send message, and message hash ( md5(message,key))
Kaminsky Attack
DNS attack where attack sends fake DNS requests to recursive server.
When recursive server queries authoritative server for answer, attacker responds first, winning the race condition.
Attackers response has NS match in it, poisoning the cache
DNS Poison defenses
ID randomization
Source Port randomization
0x20 (random hostname capitalization)
DNS Sec
Adds authentication to DNS protocol to allow devices to confirm identity of senders