Question: 3. Present, with a sequence diagram, an efficient network scan, which identifies SYN-ACK amplifiers in a large block of IP addresses (e.g., the entire Internet).

3. Present, with a sequence diagram, an efficient network scan, which identifies SYN-ACK amplifiers in a large block of IP addresses (e.g., the entire Internet). In this question, the scan should be simple and efficient rather than stealthy; a later question will ask for a stealthy scan. The amplifiers may be in any of the 216 ports of each of the IP addresses. Consider (realistically) that many IP addresses do not respond with SYN-ACK at all (no host, blackholed IP, filtered host, no TCP). No need to consider possible rate limiting mechanisms that block excessive scanning of a given network. 4. First, design a scan to find what we refer to as helper hosts, e.g., at IP 9.9.9.9, that (1) run HTTP (web) server (on TCP port 80) and DNS server (on UDP port 53), (2) are global-IP-ID-incrementing, and (3) are behind RST-dropping router (FW). Design and explain, using a sequence diagram a scan for helper hosts. This scan does not have to 2 be stealthy, i.e., the scanner sends in the scan packets using its correct IP address (and hence can receive responses)
Step by Step Solution
There are 3 Steps involved in it
Get step-by-step solutions from verified subject matter experts
