Network Manipulation
Table 3-7 shows the summary information for the network manipulation attack.
|
Attack name |
Network manipulation |
|
Class/subclass |
Manipulate |
|
Sample implementations |
Fragroute |
|
Prerequisites |
Variable |
|
Pertinent vulnerability |
Software |
|
Typical use |
Bypass security technology |
|
Attack result |
Increased access |
|
Likely follow-up attack |
Read and composite |
|
OSI layers |
34 |
|
Detection |
IDS, routers |
|
Protection |
Firewall/application security/cryptography |
|
Detection difficulty |
2 |
|
Ease of use |
3 |
|
Frequency |
2 |
|
Impact |
3 |
|
Overall rating |
26 |
The most common network manipulation attack is IP fragmentation. Here the attacker intentionally fragments traffic in an effort to bypass a security control, which could be network based (IDS or firewall) or application based. One tool used to launch an IP fragmentation attack is called Fragroute. More information about Fragroute is available at http://monkey.org/~dugsong/fragroute/. For details on the ways fragmentation can be used to bypass security devices, take a look at the paper titled "Insertion, Evasion, and Denial of Service: Eluding Network Intrusion Detection" at http://www.insecure.org/stf/secnet ids/secnet ids.html.
In addition to IP fragmentation, the attacker can execute a source route attack. Source routing allows the attacker to pick the path of the attack through the network. Source routing has almost no legitimate use and is turned off by default on most routers.
IP and Transmission Control Protocol (TCP) are complex protocols. User Datagram Protocol (UDP) is less so. Still, all of these protocols leave a fair bit of room for creative attackers to do things the protocols were not designed to do. Although not exclusively intended for attacks, Dan Kaminsky's Paketto suite of tools shows what can be done with TCP/IP given sufficient motivation and free time: http://www.doxpara.com/read.php/code/paketto.html.
Continue reading here: Table 38 Buffer Overflow
Was this article helpful?