Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 1 out of 4 pages
Exam (elaborations)

CS 6250 LESSON 9 - INTERNET SECURITY EXAM QUESTIONS WITH VERIFIED SOLUTIONS LATEST UPDATE 2026

Document preview thumbnail
Preview 1 out of 4 pages

CS 6250 LESSON 9 - INTERNET SECURITY EXAM QUESTIONS WITH VERIFIED SOLUTIONS LATEST UPDATE 2026 What are the properties of secure communication? - Answers 1. Confidentiality 2. Integrity 3. Authentication 4. Availability How does Round Robin DNS (RRDNS) work? - Answers This method is used by large websites to distribute the load of incoming requests to several servers at a single physical location. It responds to a DNS request with a list of DNS A records, which it then cycles through in a round-robin manner. The DNS client can then choose a record using different strategies - choose the first record each time, use the closest record in terms of network proximity, etc. How does DNS-based content delivery work? - Answers Content Distribution Networks (CDNs) also use DNS-based techniques to distribute content but use more complex strategies. For example, CDNs distribute the load amongst multiple servers at a single location but also distribute these servers across the world. When accessing the name of the service using DNS, the CDN computes the 'nearest edge server' and returns its IP address to the DNS client. It uses sophisticated techniques based on network topology and current link characteristics to determine the nearest server. This results in the content being moved 'closer' to the DNS client, which increases responsiveness and availability. How do Fast-Flux Service Networks work? - Answers Fast-Flux Service Networks (FFSN) are an extension of the ideas behind RRDNS and CDN. As its name suggests, it is based on a 'rapid' change in DNS answers, with a TTL lower than that of RRDNS and CDN. One key difference between FFSN and the other methods is that after the TTL expires, it returns a different set of A records from a larger set of compromised machines. These compromised machines act as proxies between the incoming request and control node/mothership, forming a resilient, robust, one-hop overlay network. What are the main data sources used by FIRE (FInding Rogue nEtworks) to identify hosts that likely belong to rogue networks? - Answers 1. Botnet command and control providers 2. Drive-by-download hosting providers 3. Phish hosting providers The design of ASwatch is based on monitoring global BGP routing activity to learn the control plane behavior of a network. Describe 2 phases of this system. - Answers 1. Training phase - The system learns control-plane behavior typical of both types of ASes. The system is given a list of known malicious and legitimate ASes. It then tracks the behavior of these ASes over time to track their business relationships with other ASes and their BGP update and withdrawal patterns. ASwatch then computes the statistical features of each AS 2. Operational phase - Given an unknown AS, it then calculates the features for this AS. It then uses the model to assign a reputation score to the AS. If the system assigns the AS a low reputation score for several days in a row (indicating consistent suspicious behavior), it identifies it as malicious. What are three classes of features used to determine the likelihood of a security breach within an organization? - Answers 1. Mismanagement symptoms 2. Malicious activities 3. Security incident reports (BGP hijacking) What is the classification by affected prefix? - Answers In this class of hijacking attacks, we are primarily concerned with the IP prefixes that are advertised by BGP. There are different ways the prefix can be targeted, such as: - Exact prefix hijacking - Sub-prefix hijacking - Squatting (BGP hijacking) What is the classification by AS-Path announcement? - Answers In this class of attacks, an illegitimate AS announces the AS-path for a prefix for which it doesn't have ownership rights. There are different ways this can be achieved: - Type-0 - This is simply an AS announcing a prefix not owned by itself. - Type-N - This is an attack where the counterfeit AS announces an illegitimate path for a prefix that it does not own to create a fake link (path) between different ASes. - Type-U - In this attack the hijacking AS does not modify the AS-PATH but may change the prefix. (BGP hijacking) What is the classification by data plane traffic manipulation? - Answers In this class of attacks, the intention of the attacker is to hijack the network traffic and manipulate the redirected network traffic on its way to the receiving AS. There are three ways the attack can be realized under this classification, i.e. traffic intercepted by the hijacker can be - Dropped - Eavesdropped or manipulated - Impersonated What are the causes or motivations behind BGP attacks? - Answers 1. Human error 2. Targeted attack 3. High impact attack

Content preview

CS 6250 LESSON 9 - INTERNET SECURITY EXAM QUESTIONS WITH
VERIFIED SOLUTIONS LATEST UPDATE 2026


What are the properties of secure communication? - Answers 1. Confidentiality
2. Integrity
3. Authentication
4. Availability
How does Round Robin DNS (RRDNS) work? - Answers This method is used by
large websites to distribute the load of incoming requests to several servers at a single
physical location. It responds to a DNS request with a list of DNS A records, which it
then cycles through in a round-robin manner. The DNS client can then choose a
record using different strategies - choose the first record each time, use the closest
record in terms of network proximity, etc.
How does DNS-based content delivery work? - Answers Content Distribution
Networks (CDNs) also use DNS-based techniques to distribute content but use more
complex strategies. For example, CDNs distribute the load amongst multiple servers
at a single location but also distribute these servers across the world. When accessing
the name of the service using DNS, the CDN computes the 'nearest edge server' and
returns its IP address to the DNS client. It uses sophisticated techniques based on
network topology and current link characteristics to determine the nearest server. This
results in the content being moved 'closer' to the DNS client, which increases
responsiveness and availability.
How do Fast-Flux Service Networks work? - Answers Fast-Flux Service Networks
(FFSN) are an extension of the ideas behind RRDNS and CDN. As its name suggests,
it is based on a 'rapid' change in DNS answers, with a TTL lower than that of RRDNS
and CDN. One key difference between FFSN and the other methods is that after the
TTL expires, it returns a different set of A records from a larger set of compromised
machines. These compromised machines act as proxies between the incoming request
and control node/mothership, forming a resilient, robust, one-hop overlay network.
What are the main data sources used by FIRE (FInding Rogue nEtworks) to identify
hosts that likely belong to rogue networks? - Answers 1. Botnet command and
control providers
2. Drive-by-download hosting providers
3. Phish hosting providers
The design of ASwatch is based on monitoring global BGP routing activity to learn
the control plane behavior of a network. Describe 2 phases of this system. - Answers
1. Training phase - The system learns control-plane behavior typical of both types of
ASes. The system is given a list of known malicious and legitimate ASes. It then
tracks the behavior of these ASes over time to track their business relationships with
other ASes and their BGP update and withdrawal patterns. ASwatch then computes
the statistical features of each AS

2. Operational phase - Given an unknown AS, it then calculates the features for this
AS. It then uses the model to assign a reputation score to the AS. If the system assigns
the AS a low reputation score for several days in a row (indicating consistent
suspicious behavior), it identifies it as malicious.
What are three classes of features used to determine the likelihood of a security
breach within an organization? - Answers 1. Mismanagement symptoms
2. Malicious activities

Document information

Uploaded on
September 10, 2026
Number of pages
4
Written in
2026/2027
Type
Exam (elaborations)
Contains
Questions & answers
$11.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
joshuawesonga22
3.5
(14)
Sold
122
Followers
2
Items
15228
Last sold
2 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions