Networks under attack
The Internet runs on trust:
- between private networks that form the global Internet
- in the IP addresses advertised between adjacent networks via Border Gateway Protocol
- in the queries returned from the DNS
- in the third-party institutions that authenticate websites
- in the IP addresses themselves (is the address authentic or is it being spoofed?)
Much can go wrong when this trust is broken.
The Internet is essential but vulnerable
The Internet is critical for individuals, businesses, and governments.
However, its widespread use also exposes users to security threats from malicious actors.
Network security is about defending against these threats:
- the field focuses on understanding attacks and designing defenses or even redesigning network architectures to resist them
- security is now a central concern in computer networking
Common Internet security threats
Malware
Malware can enter devices via Internet communication.
It may:
- delete files
- steal private data (e.g. passwords, social security numbers)
- enroll devices in botnets for spamming or DDoS attacks
Malware often self-replicates, spreading quickly across the Internet.
Denial-of-Service (DoS) and Distributed DoS (DDoS) attacks
DoS attacks aim to make services or networks unusable.
DDoS attacks are more dangerous, using multiple compromised devices to flood targets.
Types include:
- protocol attack: causing damage by exploiting weaknesses in the design or operation of a network protocol (e.g., TCP/SYN flood)
- volume-based attack: consuming network capacity by sending a large amount of traffic toward a target (e.g., ICMP flood)
Packet sniffing
Attackers can intercept and inspect data packets, especially on wireless or shared wired networks:
- sniffers are hard to detect and can capture sensitive information like passwords
- cryptography is a key defense
IP spoofing
Attackers can forge the source address of packets to impersonate trusted users or systems:
- this can lead to unauthorized actions like altering router configurations
- defense requires end-point authentication to verify sender identity
Why is the Internet insecure?
The original Internet was designed under the assumption of mutual trust, with no built-in security.
Today's environment lacks trust, and users must defend against a wide range of threats.
Trust is no longer the default. Modern networking must assume the opposite.