Network Tech
TCP/IP Stack
Network Attack IoCs
Network Attack IoC 2
Ports
99

Is responsible for sending packets across the internet

Router

99

Layer that the end user interacts with

Application

99
A wireless access point that is not authorized by an organization

Rouge Access Point

99

Fake information is entered into the cache of a DNS server, resulting in queries producing an incorrect reply

DNS Poisoning

99

80

HTTP

199

Uses a table of MAC address to forward data to their destination

Switch

199

Layer that is responsible for sending the 1s and 0s

Physical

199

Unauthorized access of information through a Bluetooth connection

Bluesnarfing

199

What could the outcome of DNS Poisoning

Sending victims to the wrong website

199

DNS

53

299
Connection-based protocol, guarantees in order delivery

TCP

299

Layer with the router and IP addresses

Network

299

Attacker corrupts ARP tables

ARP Poisoning

299

Technology that can detect anomalies and take some action to stop them

IPS

299

SSH

22

399

Protocol used to find MAC address provided an IP address

ARP

399

Layer that defines how data will be sent - over TCP or UDP

Transport

399

Attacker overwhelms a switch's table

MAC Flooding

399

Technology that can detect anomalies and alerts someone to them

IDS

399

 49152-65535

Ephemeral ports

499

Connects devices to the network - wirelessly

Wireless Access Point

499

Layer with switches and MAC addresses

Link
499

Attacker copies a known MAC address to pretend to be a different computer

MAC Cloning

499

Has a list of rules - granting or denyng traffic

Firewall

499

0–1023

Well known ports