CS 6250 PRACTICE EXAMS ANSWERS AND
QUESTIONS SET A+
✔✔How do CDNs and RRDNS benefit scammers? - ✔✔- Harder to shut down online
scams because if just one IP is functional, it still works
(9)
✔✔How do fast flux service networks work? - ✔✔DNS records are short lived (low TTL)
They return a set of records that are only a small percentage of the available IP
addresses for that domain
they belong to compromised machines to act as proxies
they form a resilient one-hop overlay network
(9)
✔✔What has the shortest TTL? - ✔✔Fast flux SN
(9)
✔✔What happens when a TTL expires with FFSN? Why? - ✔✔After TTL expires, it
returns a different set of records from a larger set of compromised machines
- machines act as proxies between request and control node
(9)
✔✔What is the purpose of FIRE? - ✔✔Finding Rogue Networks
- monitors internet for rogue networks
(9)
✔✔What is a rogue network? - ✔✔Network with purpose of malicious activity
(9)
,✔✔what are the 3 main data sources of FIRE to identify hosts that belong to rogue
networks? - ✔✔1. botnet command and control providers - they rely on a centralized
C&C
2. drive-by download hosting providers - malware installs without interaction
3. phish housing providers - URLs that host phishing pages - up for a short period of
time
(9)
✔✔Difference between rogue and legit networks? - ✔✔- longevity of malicious behavior
- legit networks can remove them much more quickly
(9)
✔✔Does FIRE observe networks w/ malicious IP addresses that have been up for a
short period of time? - ✔✔No because legit networks can remove content quicker
(9)
✔✔How does FIRE determine a rogue AS? - ✔✔- each data source provides list of
malicious IPs daily
- highest ratio of of malicious IP address compared to total IPs in AS
(9)
✔✔What are the disadvantages of data plane monitoring for malicious networks? - ✔✔-
not feasible to monitor all traffic
- can take a long time
- doesn't differentiate well between legit abused networks and malicious ones
(9)
✔✔What is AS Watch? Why use it? - ✔✔- uses info from control plane (routing
behavior) to identify malicious networks as opposed to abused, legit networks
(9)
✔✔What plane is FIRE on? ASWatch? - ✔✔- Data plane (focus on explicit packet
forwarding)
- Control plane (focus on routing behavior)
(9)
✔✔What are the 2 phases of AS Watch - ✔✔1. training phase - learn control plane
behavior typical of legit and malicious ASes
, 2. operational phase - calculates features given an unknown AS
- assigns score to AS based on the model
- if score is low several days in a row, it's malicious
(9)
✔✔What are the 3 families of features of the ASWatch training phase? - ✔✔1. rewiring
activity - changing customers/providers often
2. IP space fragmentation and churn
- small BGP prefixes to partition IP space is used to avoid being taken down at once
3. BGP routing dynamics
- announce prefixes for short periods of time
(9)
✔✔What are 3 classes of features used for likelihood of breach/random forest model? -
✔✔1. mismanagement symptoms
- policies/tech capability in place to prevent attacks
2. malicious activities
- level of activities coming from network
3. security incident reports
- data based on actual incidents
(9)
✔✔What is likelihood of breach/random forest model? - ✔✔determine likelihood of a
security breach in an organization
(9)
✔✔what are mismanagement symptoms, give examples - ✔✔misconfigurations in
organization's network that indicate lack of policy/technology in place to prevent attacks
- open recursive resolvers, DNS port randomization, BGP misconfiguration, untrusted
certificates, open SMTP mail relays
(9)
✔✔what are 4 types of malicious activities we can observe with random forest? - ✔✔1.
spam activity
2. phishing/malware
3. scanning activity
(9)
QUESTIONS SET A+
✔✔How do CDNs and RRDNS benefit scammers? - ✔✔- Harder to shut down online
scams because if just one IP is functional, it still works
(9)
✔✔How do fast flux service networks work? - ✔✔DNS records are short lived (low TTL)
They return a set of records that are only a small percentage of the available IP
addresses for that domain
they belong to compromised machines to act as proxies
they form a resilient one-hop overlay network
(9)
✔✔What has the shortest TTL? - ✔✔Fast flux SN
(9)
✔✔What happens when a TTL expires with FFSN? Why? - ✔✔After TTL expires, it
returns a different set of records from a larger set of compromised machines
- machines act as proxies between request and control node
(9)
✔✔What is the purpose of FIRE? - ✔✔Finding Rogue Networks
- monitors internet for rogue networks
(9)
✔✔What is a rogue network? - ✔✔Network with purpose of malicious activity
(9)
,✔✔what are the 3 main data sources of FIRE to identify hosts that belong to rogue
networks? - ✔✔1. botnet command and control providers - they rely on a centralized
C&C
2. drive-by download hosting providers - malware installs without interaction
3. phish housing providers - URLs that host phishing pages - up for a short period of
time
(9)
✔✔Difference between rogue and legit networks? - ✔✔- longevity of malicious behavior
- legit networks can remove them much more quickly
(9)
✔✔Does FIRE observe networks w/ malicious IP addresses that have been up for a
short period of time? - ✔✔No because legit networks can remove content quicker
(9)
✔✔How does FIRE determine a rogue AS? - ✔✔- each data source provides list of
malicious IPs daily
- highest ratio of of malicious IP address compared to total IPs in AS
(9)
✔✔What are the disadvantages of data plane monitoring for malicious networks? - ✔✔-
not feasible to monitor all traffic
- can take a long time
- doesn't differentiate well between legit abused networks and malicious ones
(9)
✔✔What is AS Watch? Why use it? - ✔✔- uses info from control plane (routing
behavior) to identify malicious networks as opposed to abused, legit networks
(9)
✔✔What plane is FIRE on? ASWatch? - ✔✔- Data plane (focus on explicit packet
forwarding)
- Control plane (focus on routing behavior)
(9)
✔✔What are the 2 phases of AS Watch - ✔✔1. training phase - learn control plane
behavior typical of legit and malicious ASes
, 2. operational phase - calculates features given an unknown AS
- assigns score to AS based on the model
- if score is low several days in a row, it's malicious
(9)
✔✔What are the 3 families of features of the ASWatch training phase? - ✔✔1. rewiring
activity - changing customers/providers often
2. IP space fragmentation and churn
- small BGP prefixes to partition IP space is used to avoid being taken down at once
3. BGP routing dynamics
- announce prefixes for short periods of time
(9)
✔✔What are 3 classes of features used for likelihood of breach/random forest model? -
✔✔1. mismanagement symptoms
- policies/tech capability in place to prevent attacks
2. malicious activities
- level of activities coming from network
3. security incident reports
- data based on actual incidents
(9)
✔✔What is likelihood of breach/random forest model? - ✔✔determine likelihood of a
security breach in an organization
(9)
✔✔what are mismanagement symptoms, give examples - ✔✔misconfigurations in
organization's network that indicate lack of policy/technology in place to prevent attacks
- open recursive resolvers, DNS port randomization, BGP misconfiguration, untrusted
certificates, open SMTP mail relays
(9)
✔✔what are 4 types of malicious activities we can observe with random forest? - ✔✔1.
spam activity
2. phishing/malware
3. scanning activity
(9)