48730-32548 Cyber Security


48730-32548, Cyber Security Week-5 
 
Lab Overview 
 
The learning objective of this lab is to gain first-hand experience on TCP/IP vulnerabilities, as well as 
attacks against these vulnerabilities. The vulnerabilities in the TCP/IP protocols represent a special genre 
of vulnerabilities in protocol designs and implementations. They provide an invaluable lesson as to why 
security should be designed in from the beginning, rather than being added as an afterthought. Moreover, 
studying these vulnerabilities help students understand the challenges of cyber security and why many 
cyber security measures are needed. Vulnerabilities of the TCP/IP protocols occur at several layers. This 
lab is designed to learn them step-by-step. 
 
Lab Environment Setup 
 
To conduct this lab, we require all the three virtual machines: Server, Client and Attacker. The tools being 
used for this lab are Wireshark/Tshark, Netwox/Netwag. 
 
Netwox/Netwag 
 
We need tools to send out network packets of different types and with different contents. We can use 
Netwag to do that. However, the GUI interface of Netwag makes it difficult for us to automate our process. 
Therefore, we strongly suggest that you use its command-line version, the Netwox command, which is 
the underlying command invoked by Netwag. 
 
Netwox consists of a suite of tools, each having a specific number. You can run the command as following 
(the parameters depend on which tool you are using). For some of the tools, you have to run it with the 
root privilege: 
➢ netwox <number> [parameters ...]
 
If you are not sure how to set the parameters, you can look at the manual by issuing "netwox <number> --
help". You can also learn the parameter settings by running Netwag for each command you execute from the 
graphic interface, Netwag actually invokes a corresponding Netwox command, and it displays the parameter 
settings. Therefore, you can simply copy and paste the displayed command. 
 
Wireshark Tool. 
 
You also need a good network-traffic sniffer tool for this lab. Although Netwox comes with a sniffer, you 
will find that another tool called Wireshark is a much better sniffer tool. 
 
Both Netwox and Wireshark can be downloaded. If you are using our pre-built virtual machine, both tools 
are already installed. To sniff all the network traffic, both tools need to be run with root privilege. 
 
Tshark Tool. 
 
It is a terminal based network packet analyzer. You also need a good command line network-traffic sniffer 
tool for this lab. 
 
48730-32548, Cyber Security Week-5 
 
 The lab is based on documents “SEED Labs” provided by Wenliang Du, Syracuse University 
 
Lab Tasks 
 
In this lab, you need to conduct attacks on the TCP/IP protocols. You can use the Netwox or Netwag, 
Wireshark, Tshark tools in the attacks. All the attacks are performed on Linux operating systems. However, 
you can also conduct the same attack on the other operating system and compare the observations after 
lab classes. You are supposed to use all the three Virtual Machines for the experiments. 
 
To simplify the “guess” of TCP sequence numbers and source port numbers, we assume that attacks are 
on the same physical network as the victims (Think of where such attacks may happen?). Therefore, you 
can use sniffer tools to get that information. The following is the list of attacks that need to be 
implemented and studied in this lab. 
 
Before starting the task, disconnect the internet from the Server VM. 
 
Task 1: SYN Flooding Attack 
 
SYN flood is a form of DoS attack in which attackers send many SYN requests to a victim’s TCP port, but 
the attackers have no intention to finish the 3-way handshake procedure. Attackers either use spoofed IP 
address or do not continue the procedure. Through this attack, attackers can flood the victim’s queue that 
is used for half-opened connections, i.e. the connections that has finished SYN, SYN-ACK, but has not yet 
got a final ACK back. When this queue is full, the victim cannot take any more connection. Following figure 
illustrates the attack. 
 
48730-32548, Cyber Security Week-5 
 
 The lab is based on documents “SEED Labs” provided by Wenliang Du, Syracuse University 
 
The size of the queue has a system-wide setting. In Linux, you can check the system queue size setting 
using the following command: 
➢ sysctl -q net.ipv4.tcp_max_syn_backlog
You can use command netstat -na to check the usage of the queue, i.e., the number of half opened 
connection associated with a listening port. 
 
For this task, Netwag Tool 76 will be used to conduct the attack, and tshark tool to capture the packets. 
 
Steps: 
 
1. As SYN flood produces a lot of traffic in the VM due to high speed, Wireshark might 
crash. It is recommended to use “tshark” by entering “sudo tshark” on Terminal of the 
Client VM. 
 
2. Then go to Attacker VM and start Netwag by entering “sudo netwag” on the Terminal. 
3. Select 76: Synflood. 
4. Enter the details and click run it. (Screenshot required) 
5. Observe the captured packets on Client VM. (Screenshot required) 
 
Questions: 
 
1. Observe the attack and take screenshots of the attack scenario. 
2. Comment on your observation. 
3. Categorize this attack in terms of severity and how it is linked to the DoS attack 
48730-32548, Cyber Security Week-5 
 
 The lab is based on documents “SEED Labs” provided by Wenliang Du, Syracuse University 
 
Task 2: ARP cache poisoning 
 
The ARP cache is an important part of the ARP protocol. Once a mapping between a MAC address and an 
IP address is resolved as the result of executing the ARP protocol, the mapping will be cached. Therefore, 
there is no need to repeat the ARP protocol if the mapping is already in the cache. However, because the 
ARP protocol is stateless, the cache can be easily poisoned by maliciously crafted ARP messages. Such an 
attack is called the ARP cache poisoning attack. 
 
Normal Scenario: 
Attackers may use spoofed ARP messages to trick the victim to accept an invalid MAC-to IP mapping, and 
store the mapping in its cache. There can be various types of consequences depending on the motives of 
the attackers. For example, attackers can launch a DoS attack against a victim by associating a non-existent 
MAC address to the IP address of the victim’s default gateway; attackers can also redirect the traffic to 
and from the victim to another machine, etc. 
 
Attack Scenario: 
48730-32548, Cyber Security Week-5 
 
 The lab is based on documents “SEED Labs” provided by Wenliang Du, Syracuse University 
 5 
 
For this task, Netwag Tool 80 is required to conduct the attack, and wireshark tool to capture the packets. 
 
HINTS: In this task, you need to demonstrate how the ARP cache poisoning attack work. In Linux we can 
use the command arp -a to check the current mapping between IP address and MAC address. 
 
Steps: 
 
1. In Server VM, run “arp -a” on terminal to get the ARP Information (MAC Table). 
(Screenshot Required) 
2. Open Netwag on Attacker VM by entering “sudo netwag” on the Terminal. 
3. Select Tool 80: Periodically Send ARP Replies. 
4. Add the fake MAC address and IP address and select the interface. (Screenshot 
Required) 
5. Click “Run It”. 
6. Check the MAC Table on Server VM and look for the change in MAC address for IP 
address provided in the Netwag tool 80. (Screenshot required) 
 
Questions: 
1. Observe the attack and take screenshots of the attack scenario. 
2. Comment on your observation. 
3. Briefly describe how you can mitigate this attack. 
 
Task 3: ICMP Redirect Attack 
 
The ICMP redirect message is used by routers to provide the up-to-date routing information to hosts, 
which initially have minimal routing information. When a host receives an ICMP redirect message, it will 
modify its routing table according to the message. 
 
Because of the lack of validation, if attackers want the victim to set its routing information in a particular 
way, they can send spoofed ICMP redirect messages to the victim and trick the victim to modify its routing 
table. 
 
For this task, Netwag Tool 86 is required to conduct the attack, and wireshark tool to capture the packets. 
 
HINTS: In this task, you should demonstrate how the ICMP redirect attack works, and describe the 
observed consequence. To check the routing information in Linux, you can use the command route 
 
Steps: 
 
1. Open Wireshark on Client VM by entering “sudo wireshark” in the terminal. 
2. Select the interface and set “icmp” as filter and click “Apply”. 
3. Open a new terminal on Client VM and ping the server. (Screenshot required) 
4. Go to Attacker VM, run Netwag using the terminal. 
5. Select the interface and “spoofip: IP spoof initialization type”. Input the required IP 
address into “gw: new gateway” and “src-ip: source IP address”. (Screenshot Required) 
6. Click “Run It”. 
7. Go back to Client VM, check the Wireshark output. (Screenshot Required) 
  
48730-32548, Cyber Security Week-5 
 
 The lab is based on documents “SEED Labs” provided by Wenliang Du, Syracuse University 
 
Questions: 
1. Observe the attack and take screenshots of the attack scenario. 
2. Comment on your observation. 
3. Briefly describe how you can mitigate this attack. 

  • 2
    点赞
  • 2
    收藏
    觉得还不错? 一键收藏
  • 0
    评论
“实践型人工智能在网络安全中的应用”是指人工智能技术在网络安全领域的实际应用。随着网络攻击日益复杂和普遍,传统的网络安全措施已经无法满足对抗威胁的需求。而人工智能的出现,为网络安全提供了新的解决方案。 实践型人工智能在网络安全中的应用可以分为几个方面。首先是入侵检测和预防。人工智能技术可以通过对网络流量和系统日志的分析,识别出潜在的入侵行为,并及时采取相应的措施进行预防。其次是威胁情报和分析。通过对大数据的分析和挖掘,人工智能可以帮助企业获得有关网络威胁的实时情报,从而更好地了解和应对各种威胁。此外,人工智能还可以应用于恶意代码检测、虚拟专用网络安全、恶意活动预测等方面,从而提升网络安全的整体水平。 实践型人工智能在网络安全中的应用具有许多优势。首先,它可以通过大数据处理和机器学习算法实现对大量数据的实时分析,提高威胁检测和预测的准确性和效率。其次,人工智能可以从历史数据和实时数据中学习并更新自己的模型,以应对不断变化的威胁。此外,人工智能还可以通过自动化处理和响应系统来减少人为错误和延迟,提高网络安全的响应速度。 然而,实践型人工智能在网络安全中也面临一些挑战。首先,人工智能技术的应用需要大量的计算资源和数据训练,这对于一些中小型企业来说可能是一个挑战。其次,人工智能面临着隐私和伦理问题,如如何保护个人隐私和防止滥用人工智能的问题。此外,人工智能还需要不断与新的威胁和攻击方式保持同步,才能保持其有效性。 综上所述,“实践型人工智能在网络安全中的应用”是一个应对不断增长的网络威胁的新兴领域。通过将人工智能技术应用于网络安全,我们可以提高网络安全的效率和准确性,加强对网络威胁的防范和应对能力。尽管面临一些挑战,但实践型人工智能在网络安全中的应用具有广阔的前景和潜力。
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值