Skip to content

Module 11 Overview ​

March 29 - April 4 · Reading: 17 pages · Estimated total: 6 hours

The internet's core protocols were designed by people who were solving a different problem. They were building something that would keep working when links failed and routers died, among institutions that broadly trusted each other. Almost none of it authenticates anything.

That inheritance explains most of this week. ARP believes any reply. DNS believed any answer until DNSSEC. BGP largely believes any route announcement. TCP's sequence numbers give you robustness against faults, not against an adversary. Every one of those is a design that was correct for its requirements and became a vulnerability when the requirements changed.

The second half of the week is what defenders do about it: firewalling, segmentation, monitoring, and the observation that in a world where nearly all traffic is encrypted, a network sensor sees metadata rather than content, and metadata turns out to be enough for a great deal.

Learning Objectives ​

By the end of this week, the successful student will be able to:

  • 4.1: Explain how common network attacks work at the protocol layer where they operate.
  • 4.2: Recommend network defenses (firewalling, segmentation, and monitoring) for a described network.

Assignments and Tasks ​

Due by Thursday at 11:59 p.m. Mountain Time ​

Due by Sunday at 11:59 p.m. Mountain Time ​

D4 asks you to find an incident nobody else has claimed. Check the board and post early.

Time Estimate ​

ActivityTime
Reading (17 pages)2 hrs
The notes page and the worked example40 min
D4 post and two replies1 hr
Review and slack2 hrs 30 min
Total~6 hrs

Released under the MIT License.