Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsEasy
A security analyst is reviewing network traffic logs and observes a high volume of ICMP echo requests targeting various internal hosts from an external IP address. The analyst also notes that the external IP address appears to be spoofed. Which type of attack is most likely occurring?
- AMan-in-the-Middle (MitM)
- BSmurf Attack
- CSQL Injection
- DCross-Site Scripting (XSS)
Show answer & explanationAnswer & explanation
Correct answer: B. Smurf Attack
A Smurf attack is a type of Distributed Denial of Service (DDoS) attack that uses ICMP echo requests to overwhelm a target network. Attackers spoof the victim's IP address as the source of the ICMP requests, which are then broadcast to a large number of hosts on an intermediary network, causing all responders to send replies to the victim.
Why the other options are wrong
- A. MitM intercepts communication between two parties, which doesn't directly explain broadcast ICMP floods.
- C. SQL Injection targets databases through web application vulnerabilities, not network-level ICMP traffic.
- D. XSS exploits client-side scripts in web applications, unrelated to ICMP traffic.
Smurf Attack
A DDoS attack where an attacker spoofs the victim's IP address and sends ICMP echo requests to a network's broadcast address, causing all hosts on that network to reply to the victim, overwhelming them.
- Uses ICMP echo requests (ping).
- Involves IP address spoofing.
- Leverages an intermediary network's broadcast address.
- Results in a Denial of Service (DoS) for the target.
Memory trick: Denial of Service impacts availability, like a Smurf overwhelming with pings.