ISC2 CISSP (Certified Information Systems Security Professional)Communication and Network SecurityEasy
A company is experiencing slow network performance and occasional outages, particularly during peak hours. Investigation reveals that the network is being flooded with an unusually high volume of broadcast traffic, causing network devices to become overwhelmed. Which type of network attack is most likely occurring?
- AMan-in-the-Middle Attack
- BBuffer Overflow
- CSQL Injection
- DSmurf Attack
Show answer & explanationAnswer & explanation
Correct answer: D. Smurf Attack
A Smurf attack is a type of Distributed Denial of Service (DDoS) attack that overwhelms a target network by flooding it with ICMP echo reply packets. This is achieved by sending ICMP echo requests to a network's broadcast address with the victim's spoofed IP address as the source.
Why the other options are wrong
- A. A Man-in-the-Middle attack involves intercepting and potentially altering communication between two parties but typically doesn't manifest as a broadcast flood.
- B. A Buffer Overflow exploits software vulnerabilities by overwriting memory buffers, leading to crashes or arbitrary code execution, not network broadcast floods.
- C. SQL Injection targets databases through web application vulnerabilities and does not typically result in network-wide broadcast flooding.
Smurf Attack
A DDoS attack in which the attacker sends a large number of ICMP echo requests to an IP broadcast address using a spoofed source IP address that belongs to the victim.
- Relies on ICMP and IP broadcast addresses.
- Amplifies traffic, causing a denial of service to the victim.
- Mitigated by disabling IP directed broadcasts on routers.
Memory trick: DOS: 'D'o 'O'ver 'S'ervice.