Computer Science · Ch 12 — Security Aspects
Intrusion Problems
Intrusion Problems
What “Intrusion” Really Means
Before the book lists the attacks, it sets the stage with a definition. Network intrusion is any unauthorised activity on a computer network. That activity can take two broad forms: misusing network resources (the book names DoS as the example) or threatening the security of the network and the data it carries. The point being made is that intrusion is not a minor nuisance — it is a serious problem, and the network administrator must actively devise a strategy and implement security measures to protect the network.
The book reminds you that some intrusion attacks were already covered earlier in the chapter — specifically DoS, Trojans, and Worms. What follows in this section are the remaining attacks, discussed briefly. There are three of them.
(A) Asymmetric Routing
The first attack is about evasion. The attacker's goal is to avoid being detected, and the method is to send intrusion packets through multiple paths rather than a single route. Because the packets are scattered across different routes, the network's intrusion sensors — which typically monitor traffic along expected paths — get bypassed. The attack works precisely because the sensors never see the complete picture; they only catch fragments, or nothing at all.
(B) Buffer Overflow Attacks
This one is a programming-error exploit. The attacker overwrites certain memory areas of computers within the network with code — a set of commands — that will be executed later, when the buffer overflow actually occurs. The key idea is that the overflow is a programming error: the buffer (a temporary memory region) receives more data than it can hold, and the excess data spills over and overwrites adjacent memory. The attacker has planted malicious code in that spill. When the overflow happens, that code executes.
Once the malicious code runs, the attacker can do one of two things: launch a DoS attack or gain access to the network. So the buffer overflow is not the end goal — it is the entry point that enables a bigger attack.
(C) Traffic Flooding
The book calls this one of the most trivial methods of network intrusion — trivial in the sense of being simple and unsophisticated, not ineffective. The method is straightforward: flood the network intrusion detection system with message packets. The sheer volume of traffic creates a huge load, and that load leaves the detection system incapable of monitoring the packets adequately. The system is overwhelmed, congested, chaotic.
The hacker then exploits this chaos. While the detection system is drowning in packets and unable to do its job properly, the attacker sneaks into the system undetected. The flooding itself is not the intrusion — it is the distraction that makes the real intrusion possible.
The Three Attacks at a Glance
| Attack | Core Idea | What the Attacker Gains |
|---|---|---| …
Asymmetric Routing
Asymmetric Routing is a network phenomenon where data packets travel from the source to the destination along one path, but the return traffic takes a completely different route. This happens because routing decisions are made independently at each hop, based on the current state of routing tables, link costs, or load-balancing policies. In the context of security, asymmetric routing can break stateful firewalls and intrusion detection systems, since these devices expect to see both directions of a connection on the same interface. The textbook highlights that while asymmetric routing is often a performance …
Buffer Overflow Attacks
A buffer overflow attack happens when a program tries to store more data in a fixed-size memory buffer than it can hold, causing the extra data to spill into adjacent memory. The NCERT text walks through this with a concrete C-style example: a character array buffer[10] is meant to hold ten characters, but the strcpy function copies a much longer string into it. Because strcpy does not check the destination size, the excess characters overwrite neighbouring memory locations, which can corrupt variables, crash the program, or even let an attacker inject malicious code. The book stresses that this is a classic programming error — the fix is to use sa …
Traffic Flooding
Traffic Flooding is a denial-of-service attack where an attacker overwhelms a server or network with a massive volume of requests, making it unable to respond to legitimate users. The textbook presents it as a simple but effective way to exhaust system resources — think of it like a crowd of people all trying to push through a single door at once, so nobody can get in. The key idea is that the attacker doesn't need to break any security barrier; they just need to send so much data that the system's processing capacity is completely tied up. This is often done using automated tools that generate thousands of requ …