Computer Networks · Module 8 — Network Security & Wireless Basics
Common attacks
The original protocols verify almost nothing.
Sign in to track your score
Everything in this course assumed the packets were honest. Nothing in the design of IP or Ethernet actually checks that.
Why & what
Why attacks are possible at all. The original protocols verify almost nothing.
- Nothing in an Ethernet frame proves the source MAC is real.
- Nothing in an IP header proves the source IP is real.
- Plain HTTP is readable by every device on the path.
Security was added later, on top. Understanding these attacks is mostly understanding what the original design left out.
The four you must know.
- Sniffing — quietly capturing traffic that was not meant for you. On old hubs this was trivial, because every port got a copy. On open Wi-Fi it is still possible, because radio reaches everyone.
- Spoofing — sending packets that claim to come from someone else's address. Possible because the source field is simply written by the sender, and nothing checks it.
- Man in the middle (MITM) — positioning yourself between two parties and relaying their traffic while reading it. Both sides think they are talking directly.
- DDoS (Distributed Denial of Service) — flooding a server with so much traffic from so many machines that real users cannot get through. Not a break-in. An overwhelm.
What actually stops them. Notice how short the list of defences is.
| Attack | What defeats it |
|---|---|
| Sniffingencryption — captured traffic is unreadable | |
| Spoofing | verification — checks that confirm who really sent it |
| MITM | certificates — the identity check fails |
| DDoS | filtering and rate limits before the traffic arrives |
Three of the four come down to encryption or proving identity.
How it works
Take MITM against Aisha, since it ties the whole course together.
- An attacker on HostelNet-3F sends fake ARP replies claiming that 192.168.1.1 is at the attacker's MAC address.
- Aisha's laptop believes it — recall from Topic 4.5 that ARP has no verification at all.
- Her frames now go to the attacker instead of the router.
- The attacker forwards them onward, so her browsing still works and nothing looks wrong.
- If she is on plain HTTP, everything is readable. If she is on HTTPS, the certificate does not match and her browser shows a warning.
That last step is the whole reason certificates exist.

Common confusion
Students think a DDoS attack breaks into the server. Actually, it never gets inside anything. It just makes the server too busy to answer.
Nothing is stolen or modified. The server does exactly what it was built to do, but so many requests arrive that real users get nothing. That is why its defences differ from every other attack here. Encryption does not help. Passwords do not help. Only filtering the flood before it arrives does.
Interview angle
Asked as: "What is a man-in-the-middle attack?" or "Difference between DoS and DDoS?"
Model answer:
In a man-in-the-middle attack, an attacker places themselves between two communicating parties and relays traffic while reading or altering it, so both sides believe they are talking directly. On a local network this is often done by poisoning ARP, since ARP has no authentication. HTTPS defeats it, because the attacker cannot present a valid certificate for the domain. A DoS attack floods a target from one source; a DDoS uses many machines at once, which makes it far harder to filter by address and much harder to absorb. Neither is a break-in the goal is to exhaust capacity so real users cannot be served. Most of these are possible because the original protocols verify nothing. The general defences are encryption for confidentiality and certificates or authentication for identity.
- 1.
Spoofing is possible because
- 2.
A DDoS attack aims to
- 3.
What defeats a man-in-the-middle attack on a website?
- 4.
Which attack does encryption not protect against?