Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium

A security analyst is reviewing network traffic and observes a high volume of fragmented IP packets, many of which overlap or have invalid offsets. The destination IP address is a critical web server. This activity is causing the server to become unresponsive. Which type of attack is most likely occurring?

  1. ASYN Flood Attack
  2. BDNS Amplification Attack
  3. CIP Fragmentation Attack
  4. DSmurf Attack
Show answer & explanation

Correct answer: C. IP Fragmentation Attack

The scenario explicitly mentions 'fragmented IP packets' with 'overlapping or invalid offsets' targeting a server and causing unresponsiveness. This is a classic description of an IP fragmentation attack, which aims to overwhelm the target's reassembly buffer or crash the system by sending malformed fragments.

Why the other options are wrong

  • A. A SYN flood attack involves a high volume of TCP SYN requests, not fragmented IP packets.
  • B. A DNS amplification attack uses DNS resolvers to amplify traffic, typically UDP, not fragmented IP packets with invalid offsets.
  • D. A Smurf attack uses ICMP echo requests to a broadcast address, not fragmented IP packets with invalid offsets.

IP Fragmentation Attack

An IP fragmentation attack is a type of Denial-of-Service (DoS) attack that exploits the IP fragmentation and reassembly process by sending a large number of overlapping, malformed, or oversized IP fragments to a target.

  • Aims to exhaust target's reassembly buffer or cause crashes.
  • Examples include Teardrop and Ping of Death attacks.
  • Characterized by fragmented IP packets with unusual offsets.
  • Detection involves monitoring for high volumes of fragments and malformed packets.

Memory trick: DoS attacks are like trying to overwhelm a bridge with too many cars, some are subtle, some are outright floods.

More Security Monitoring questions