null
US
Entrar
Registre-se gratuitamente
Registre-se
Detectamos que o JavaScript não está habilitado no teu navegador. Habilite o Javascript para o funcionamento correto do nosso site. Por favor, leia os
Termos e Condições
para mais informações.
Próximo
Copiar e Editar
Você deve estar logado para concluir esta ação!
Inscreva-se gratuitamente
727624
U2.2 Switches, ARP
Descrição
Nework Security Mapa Mental sobre U2.2 Switches, ARP, criado por jjanesko em 07-04-2014.
Sem etiquetas
nework security
nework security
Mapa Mental por
jjanesko
, atualizado more than 1 year ago
Mais
Menos
Criado por
jjanesko
mais de 10 anos atrás
36
0
0
Resumo de Recurso
U2.2 Switches, ARP
addressing
MAC
media access control
unique identifier for NICs
source and destination in ethernet frames
48 bit value
IP
32 bits long
4 octects
reserved ranges for private networks
10.0.0.0 - 10.255.255.255
172.16.0.0-172.31.255.255
192.168.0.0-192.168.255.255
RFC 1918
ARP
address resolution protocol
protocol that translates MAC addresses to IP addresses
steps
1. Device broadcasts to network: who has IP 192.168.0.x?
ARP Query
2. All devices receive request and evaluate.
3. Device with 192.168.0.x responds with MAC address
ARP Reply
4. Querying device updates its ARP table
switches
network topology like hub
only sends frames to intended recipient (rather than broadcasting like hub)
generally more efficient than hubs because of this routing
maps ports to MAC addresses
layer 2
ARP spoofing
type of attack that uses ARP protocol to allow one network device to masquerade as another.
ARP spoofing steps (see note)
Anexos:
U2.2 Switches, ARP - ARP spoofing steps
tools: DSniff http://www.monkey.org/~dugsong/dsniff/
defense
statically define ARP cache
big maintenance overhead
lock down port-MAC mapping
inflexible
issue notification of port-MAC change
legitimate use: failover scenario, crashed server
MAC flooding attack
type of attack where the switch becomes overwhelmed and does one of 2 things
switch does not accept any more mappings, freshly booted devices denied
switch stops routing and broadcasts all messages
steps
1. Attacker floods network with gratuitous ARP replies with fake MAC addresses.
2. Switch attempts to map fake addresses and fills up its mapping table.
defense
configure to ignore MAC address floods
could deny legitimate traffic
send admin alerts on MAC address floods
Quer criar seus próprios
Mapas Mentais
gratuitos
com a GoConqr?
Saiba mais
.
Semelhante
U2.6 SNMPv3
jjanesko
U2.1 Cables, Hubs, Sniffers
jjanesko
U2.4 LANs, MANs, WANs
jjanesko
U2.5 SNMPv1
jjanesko
U2.1 Cables,Hubs,Sniffers- Thin Ethernet
jjanesko
U2.5 SNMPv1 - architectural model
jjanesko
U2.1 Cables, Hubs, Sniffers - Hub Diagram
jjanesko
U2.2 Switches, ARP - ARP spoofing steps
jjanesko
U2.3 TCP, Routers - Router Diagram
jjanesko
U2.5 SNMPv1 - SNMPv1 protocol stack
jjanesko
U2.3 TCP, Routers, VLAN
jjanesko
Explore a Biblioteca