Table 315 Rogue Devices
|
Attack name |
|
|
Class/subclass |
Spoof |
|
Sample implementations |
Any legitimate networking device; popular choices include WLAN AP, DHCP server, router, host |
|
Prerequisites |
Physical access |
|
Pertinent vulnerability |
Usage or physical security controls |
|
Typical use |
Offer services to a user community; stealing data as their requests are passed through to the legitimate network |
|
Attack result |
Disclosure and corruption of information |
|
Likely follow-up attacks |
Read and manipulate |
|
OSI layers |
All |
|
Detection |
Varies by rogue device |
|
Protection |
Varies by rogue device |
|
Detection difficulty |
3 |
|
Ease of use |
2 |
|
Frequency |
2 |
|
Impact |
5 |
|
Overall rating |
33 |
Until now in the discussion, the spoofing attack class has exclusively contained software-based attacks in which attackers attempt to convince network resources or clients that they are something they are not. In the rogue device attack, however, attackers introduce a rogue device into the network, hoping to convince other devices and users that the device is valid. The "Everything is a weapon" axiom from Chapter 1 discusses the rogue AP attack in some detail. It is also easy to reclassify the DHCP attack mentioned in the same section as a rogue device rather than a compromised one. If attackers simply introduced a new DHCP server into the network, they would be able to accomplish much the same thing.
A host could also be introduced as a rogue device. The DC Phone Home project shows how an attacker can introduce a PC, Sega Dreamcast, or Compaq iPAQ into a network to run remote attacks. The system is introduced into the network, where it attempts to determine the IP addressing and the presence of a HTTP proxy server and then creates a tunneled connection back out to the attacker. This gives a remote attacker a local presence from which to launch attacks. From here, local attacks such as ARP redirection or MAC flooding are possible. For more information about the DC Phone Home project, see the following URL: http://www.dcphonehome.com/.
The use of rogue devices can be a devastating attack, but such attacks generally require the attacker to have physical access to the target network. The detection of a rogue device can be difficult or easy, depending on how the network is managed and the specific type of rogue device. Techniques for rogue device detection and mitigation are covered in Chapter 5, "Device Hardening."
Continue reading here: MAC Flooding
Was this article helpful?