Review - CS6262 Final Exam 495 Questions with Correct Answers 100 % Verified Random Scanning - Correct Answers Each comprised computer probes random addresses Permutation Scanning - Correct Answers All comprised computers share a common psuedo-random permutation of the IP address space Signpost Scanning - Correct Answers Uses the communication patterns of the comprised computer to find a new target Hit List Scanning - Correct Answers A portion of a list of targets is supplied to a comprised computer Subnet Spoofing - Correct Answers Generate random addresses within a given address space Random Spoofing - Correct Answers Generate 32-bit numbers and stamp packets with them Fixed Spoofing - Correct Answers The spoofed address is the address of the target Server Application - Correct Answers The attack is targeted to a specific application on a server Network Access - Correct Answers The attack is used to overload or crash the communication mechanism of a network Infrastructure - Correct Answers The motivation of this attack is a crucial service of a global internet operation, for example core router DoS Bug (Amplification Attack) - Correct Answers Design flaw allowing one machine to disrupt a service DoS Flood (Amplification Attack) - Correct Answers Command botnets to generate flood of requests UDP-based NTP - Correct Answers -Particularly vulnerable to amplification attacks 1 / 4
-Small command can generate a large response -Vulnerable to source IP spoofing -Difficult to ensure computers only communicate with legitimate NTP servers IP Header Format - Correct Answers -Connectionless -Unreliable -No authentication SYN Flood - Correct Answers A type of DoS where an attacker sends a large amount of SYN request packets to a server in an attempt to deny service.SYN Flood Mitigations - Correct Answers Syn Cookies - remove state from server, but incur performance overhead Crowdturfers - Correct Answers - Crowdsource to create, verify, and manage fake accounts
- Solve CAPTCHAs
- Interception of requests or compromise of DNS servers
- Few use DNSsec
- Cache poisining 2 / 4
Penetration Testing - Correct Answers Footprinting, Scanning, Enumeration, Gaining Access, Escalating Privileged, Pilfering (steal data), Covering Tracks, Creating Backdoors NS Record - Correct Answers Points to other server A Record - Correct Answers Contains IP Address MX - Correct Answers Address in charge of handling email TXT - Correct Answers Generic text; distribute site public keys DNS vulnerabilities - Correct Answers - Users/hosts trust the host-address mapping provided by DNS
Cache Poisoning - Correct Answers Corrupting an Internet server's DNS table by replacing an Internet address with that of another, rogue address. When a Web user seeks the page with that address, the request is redirected by the rogue entry in the table to a different address. At that point, a worm, spyware, Web browser hijacking program, or other malware can be downloaded to the user's computer from the rogue location.DNSsec - Correct Answers - Authenticity of DNS answer origin
- Integrity of reply
- Authenticity of denial of existence
- Uses public key crypto to sign responses
- TCP state easily obtained by eavesdropping
- IP info not protected
- C-Plane monitor for C&C traffic
- A-Plane monitor malicious instances
TCP Problems - Correct Answers - Network packets pass untrusted hosts
Open Shortest Path First (OSPF) - Correct Answers An interior gateway routing protocol developed for IP networks based on the shortest path first or link-state algorithm.Looks for the lowest cost path within nodes.Border Gateway Protocol (BGP) - Correct Answers A core routing protocol that bases routing decisions on the network path and rules.Protocol designed to exchange routing and reachability information among autonomous systems (AS).Botminer - Correct Answers - Botnet can have different infection life cycles and they can change protocols and structure of the command-and-control
Defense in Depth - Correct Answers Prevention, Detection, Survival 3 / 4
Shamir's Scheme Simulation - Correct Answers - Add or delete shares without affecting others
- Easy to create new shares without changing secret
- Easy to create hierarchical schemes
- Information theoretic security
- Fault tolerance can be achieved through failure masking
- Spyware use anonymously registered domains
- Adware uses disposable domains
- / 4
Byzantine Fault Tolerance - Correct Answers - A fault is the cause of an error that leads to a system failure
DNS Reputation - Correct Answers - Prejudge, Profile, Stereotype DNS Black List - Correct Answers White - Complete Trust Black - No trust Grey - Not directly involved in spamming but associated with spam-like behaviors Yellow - known to produce spam and non-spam email NoBL - trustworthy DNSBL Domain Info - Correct Answers - Botnets use short lived domains
Data Poisining - Correct Answers Attacker injects data to cause machine-learning to produce the raw model Syntactic Worm Signature - Correct Answers Automatic signature generators look for invariant parts of polymorphic worms Vulnerable to Noise Injection Attack Noise Injection Attacks - Correct Answers Worm also sends out fake anomalous flows Fake invariants