Cisco CyberOps Associate (CBROPS) 200-201Security MonitoringMedium
A security analyst is reviewing network traffic and observes a high volume of fragmented IP packets, many of which overlap or have invalid offsets. The destination IP address is a critical web server. This activity is causing the server to become unresponsive. Which type of attack is most likely occurring?
- ASYN Flood Attack
- BDNS Amplification Attack
- CIP Fragmentation Attack
- DSmurf Attack
Show answer & explanationAnswer & explanation
Correct answer: C. IP Fragmentation Attack
The scenario explicitly mentions 'fragmented IP packets' with 'overlapping or invalid offsets' targeting a server and causing unresponsiveness. This is a classic description of an IP fragmentation attack, which aims to overwhelm the target's reassembly buffer or crash the system by sending malformed fragments.
Why the other options are wrong
- A. A SYN flood attack involves a high volume of TCP SYN requests, not fragmented IP packets.
- B. A DNS amplification attack uses DNS resolvers to amplify traffic, typically UDP, not fragmented IP packets with invalid offsets.
- D. A Smurf attack uses ICMP echo requests to a broadcast address, not fragmented IP packets with invalid offsets.
IP Fragmentation Attack
An IP fragmentation attack is a type of Denial-of-Service (DoS) attack that exploits the IP fragmentation and reassembly process by sending a large number of overlapping, malformed, or oversized IP fragments to a target.
- Aims to exhaust target's reassembly buffer or cause crashes.
- Examples include Teardrop and Ping of Death attacks.
- Characterized by fragmented IP packets with unusual offsets.
- Detection involves monitoring for high volumes of fragments and malformed packets.
Memory trick: DoS attacks are like trying to overwhelm a bridge with too many cars, some are subtle, some are outright floods.