Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisHard
A security analyst is investigating a series of alerts from an Intrusion Prevention System (IPS) indicating attempts to exploit a web server. The alerts show that an attacker is sending requests with unusually large HTTP POST bodies, often containing seemingly random data. These requests are causing the web server process to crash or become unresponsive. What type of attack is most likely being attempted?
- ASession fixation
- BCross-Site Request Forgery (CSRF)
- CHTTP Flood (DoS)
- DSQL injection
Show answer & explanationAnswer & explanation
Correct answer: C. HTTP Flood (DoS)
An HTTP flood is a type of Denial of Service (DoS) attack that overwhelms a web server with a high volume of seemingly legitimate HTTP requests, often with large POST bodies or complex requests, to consume server resources and make it unresponsive. The description of unusually large HTTP POST bodies and the server crashing or becoming unresponsive aligns with this attack.
Why the other options are wrong
- A. Session fixation involves an attacker fixing a user's session ID to a known one, not overwhelming a server with large POST bodies.
- B. CSRF tricks a user into performing unwanted actions; it's not a direct attack on server availability via large POST bodies.
- D. SQL injection attempts to manipulate database queries, not typically by sending large, random HTTP POST bodies to crash the server.
HTTP Flood (DoS)
A type of Denial of Service (DoS) attack that targets web servers by sending a high volume of seemingly legitimate HTTP GET or POST requests, aiming to consume server resources and make it unavailable to legitimate users.
- Operates at the application layer (Layer 7).
- Can be difficult to distinguish from legitimate traffic due to well-formed requests.
- Often uses large POST bodies, slow requests (Slowloris), or complex query parameters.
Memory trick: App layer DoS attacks make websites stop working.