DoS vs DDoS Attacks Explained: How Hackers Overwhelm Systems
HELLO FRIENDS
WELCOME TO MY CYPHER
Guys, in this blog we are going to see about network based attacks which I have learned today and I am going to share how DoS and DDoS works and also about man in the middle attack let's get into the topic without blabbering.
Denial of service ( DoS )
Denial of service is just a simple concept it will affect the availability factor that we have learned in a previous blog which is a part of the CIA triad, now your mind will raise a question about how it can affect that. let me explain it, actually attackers use a computer and internet connection to flood a target with request and it is easier to block.
To make it more clear here is an example, if you want to check the result of your exam through your university's website but it will load for eternity actually this will happen because every student requests at the same time for their results. This is how the dos attack works.
Distributed denial of service (DDoS)
This is an upgraded variant of dos attacker don't use a single system in this, they will use botnet like the network of hijacked and infected computers or IOT device like smart cameras to flood the target simultaneously from multiple locations worldwide.
This can't be easier to stop because of the number of IP addresses, Stoping a single IP address can't stop the others.
But investigators us other ways to stop this
Botnet
They don't just stop IP addresses, they would look for botnet to know where are the infected machines located and it's often traced through traffic analysis
And the next one is the most important factor which is,
The C2
This C2 is nothing but command and control, even if the attacker used a number of machines to make traffic definitely they need a central server which will command the others to do that, we can think it as a head of mafia gang if we knock out the head the others will automatically stop right that's how it works.
And the last one is,
The PCAP files - packet capture
It is the network log that shows the exact structure of the malicious traffic and it also helps to identify the specific type of DDoS
Let's move into next topic
Man in the middle attack - MITM
Actually, we can figure out what it will be with its name yeah you guessed right.
This will intercept between two systems communicating, without their knowledge it alters the information from the middle.
For example, if you send a parcel to someone in another city with the confidence of it will reach as it is but someone had changed the parcel without you guys know this is how it works.
There are some common MITM technique
Evil twin
The attacker set up a fake wi-fi hotspot with a legitimate name and we would usually connect with that, by this they can enter into our systems and our data will flow into attackers system.
ARP spoofing
If there is a network in our area and the attacker sends a fake message to link their MAC address with the IP address of the router, by this all the traffic which are meant for router will goes to attacker first.
Session hijacking
Session hijacking is, if you are need to attend a meeting and an attacker steals your session cookie they can easily attend that meeting by impersonating you and also without needing your password and the system will also think that's you.
So that's it guys. We all get an overall idea about network based attacks, I hope you guys understand it well. And if there is any mistake I have made you can let me know in the comments.
If you want study guide to learn you can get from this site

Comments
Post a Comment