Basic Terminologies: IP Address, MAC Address; Domain Name Server (DNS); DHCP, Router, Bots

A handful of networking terms recur throughout security: an IP address identifies a device on a network, a MAC address is its hardware id, DNS turns names into IP addresses, DHCP hands out IP addresses automatically, a router connects networks, and bots are automated programs that can be turned to malicious use.

10 min read · 7 cards · 2 checks

Read in: English · हिन्दी · ગુજરાતી


Theory

The vocabulary of security

Cyber security constantly uses a set of networking terms: attackers spoof IP addresses, abuse DNS, and marshal bots; defenders track MAC addresses and configure routers. To discuss attacks and defences clearly, you need these terms pinned down.

You met most of them in networking; this lesson gathers the key ones, IP address, MAC address, DNS, DHCP, router, and bots, as a quick, security-focused reference. Getting them straight makes the attack and defence lessons that follow much easier to follow, because the same words appear again and again.

At a glance

TermWhat it is
IP addressA unique numeric identifier for a device on a network (logical address)
MAC addressThe hardware (physical) address of a network interface, set by the manufacturer
DNS (Domain Name System)Translates domain names into IP addresses (the internet's phonebook)
DHCPAutomatically assigns IP addresses and settings to devices joining a network
RouterA device that forwards data packets between networks
BotsAutomated software programs; malicious ones (a botnet) power attacks like DDoS

Theory

Addresses, names, and routing

An IP address is a device's unique numeric identifier on a network, its logical address, used to route data to it. A MAC address is the device's hardware address, fixed by the manufacturer on the network card. So a device has both: an IP address (which can change) and a MAC address (its permanent hardware id).

DNS (Domain Name System) translates human names (like a website's domain) into IP addresses, the internet's phonebook. DHCP automatically assigns IP addresses to devices as they join a network, so you do not set them by hand. A router forwards data between networks, directing packets toward their destination. These are the basic machinery of getting data to the right device.

Formula

Why bots matter for security

Bots are automated software programs that perform tasks without a human. Many are harmless (search engine crawlers), but malicious bots are a major security concern: attackers infect many computers with bot malware and control them as a botnet, an army of compromised machines.

Botnets power some of the worst attacks: a DDoS floods a target from thousands of bots at once (recall why that is so hard to stop), and bots also send spam, spread malware, and harvest data. So when you hear 'botnet', think of a hijacked army of computers doing an attacker's bidding. Bots turn ordinary infected devices into weapons.

Quiz

What does DNS (Domain Name System) do?

  1. It assigns IP addresses automatically to new devices
  2. It translates domain names into IP addresses (the internet's phonebook)
  3. It is the hardware address of a network card
  4. It forwards packets between networks
Show the answer

It translates domain names into IP addresses (the internet's phonebook)

DNS (Domain Name System) translates human-friendly domain names into the numeric IP addresses that networks use to route data, acting as the internet's phonebook. Option A describes DHCP, which automatically assigns IP addresses to devices joining a network, a different job. Option C describes a MAC address (the hardware address of a network interface), not DNS. Option D describes a router, which forwards packets between networks. Keep the terms distinct: DNS resolves names to addresses, DHCP hands out addresses, a MAC address is the hardware id, and a router routes between networks.

Think first

Why do attackers care about DNS in particular?

DNS just maps names to addresses. Why is it a frequent target or tool in cyber attacks? Then tap.

Show the answer

Because DNS controls where a name POINTS, so subverting it lets an attacker silently redirect victims to malicious destinations while they believe they are visiting a legitimate site, a powerful deception. Remember what DNS does: when you type a bank's or store's domain name, DNS translates it into the IP address your device connects to. You trust the NAME, but the connection actually follows the ADDRESS that DNS returns. If an attacker can tamper with that translation, through DNS spoofing or poisoning, or by compromising DNS settings, they can make the trusted name resolve to THEIR malicious server's address instead of the real one. Now when you type the genuine domain, you are silently sent to a fake site that looks identical, where you might enter your login or card details straight into the attacker's hands (a form of the phishing and man-in-the-middle attacks you studied). The victim did nothing obviously wrong, they typed the correct address, but DNS quietly sent them astray. DNS is attractive to attackers for other reasons too: it is fundamental (almost everything relies on it), often less scrutinised than the traffic it enables, and can be abused to hide command-and-control channels for malware. And attacking DNS infrastructure itself can knock large parts of the internet offline, since if names cannot be resolved, services become unreachable even though they are running. So DNS matters to attackers because it sits at a point of TRUST and DIRECTION: control the mapping from names to addresses, and you can redirect, intercept, or disrupt at will. This is also why securing DNS (and verifying sites with SSL certificates, which detect impostors) is important. Whoever controls the phonebook controls where people actually go.

Summary

Key takeaways

  • Security reuses core networking terms constantly, so it helps to have them pinned down.
  • An IP address is a device's unique numeric (logical) identifier on a network; a MAC address is its permanent hardware id.
  • DNS (Domain Name System) translates domain names into IP addresses (the internet's phonebook).
  • DHCP automatically assigns IP addresses to devices joining a network; a router forwards packets between networks.
  • Bots are automated programs; malicious ones form a botnet, an army of compromised machines used for DDoS, spam, and spreading malware.
  • Attackers target DNS because controlling name-to-address mapping lets them silently redirect victims to malicious sites.
  • Memory hook: IP logical id, MAC hardware id, DNS names-to-addresses, DHCP hands out addresses, router routes, bots are automated (and dangerous in a botnet).

Study this properly

This page is the lesson to read. In Gri-Learn the same topic is a graded deck: the self-checks are scored and your weak topics are tracked. Free to start.

Start this topic

Already have an account? Sign in

More from Cyber Security Fundamentals

Gri-Learn · syllabus-mapped B.C.A. lessons in English, Hindi and Gujarati

Basic Terminologies: IP Address, MAC Address; Domain Name Server (DNS); DHCP, Router, Bots · E-Commerce and Cyber Security (Minor-6-01) · Gri-Learn