Theory
Security की Vocabulary
Cyber security constantly networking terms का एक set इस्तेमाल करता है: attackers IP addresses spoof करते हैं, DNS abuse करते हैं, और bots marshal करते हैं; defenders MAC addresses track करते हैं और routers configure करते हैं। Attacks और defences clearly discuss करने के लिए, आपको ये terms pinned down चाहिए।
आप इनमें से ज़्यादातर networking में मिले; यह lesson key ones, IP address, MAC address, DNS, DHCP, router, और bots, को एक quick, security-focused reference की तरह collect करता है। इन्हें straight पाना follow करने वाले attack और defence lessons को बहुत आसान बनाता है, क्योंकि same words बार-बार appear होते हैं।
At a glance
| Term | यह क्या है |
|---|---|
| IP Address | Network पर एक device का unique numeric identifier (logical address) |
| MAC Address | एक network interface का hardware (physical) address, manufacturer से set |
| DNS (Domain Name System) | Domain names को IP addresses में translate करता है (internet की phonebook) |
| DHCP | Network join करने वाले devices को automatically IP addresses और settings assign करता है |
| Router | एक device जो networks के बीच data packets forward करता है |
| Bots | Automated software programs; malicious ones (एक botnet) DDoS जैसे attacks power करते हैं |
Theory
Addresses, Names, और Routing
एक IP address एक network पर device का unique numeric identifier है, इसका logical address, इसे data route करने के लिए इस्तेमाल किया जाता है। एक MAC address device का hardware address है, network card पर manufacturer द्वारा fixed। तो एक device के पास दोनों हैं: एक IP address (जो change हो सकता है) और एक MAC address (इसकी permanent hardware id)।
DNS (Domain Name System) human names (जैसे एक website का domain) को IP addresses में translate करता है, internet की phonebook। DHCP automatically network join करते devices को IP addresses assign करता है, तो आप इन्हें हाथ से set नहीं करते। एक router networks के बीच data forward करता है, packets को इनकी destination की ओर directing करते हुए। ये सही device तक data पहुँचाने की basic machinery हैं।
Formula
Security के लिए Bots क्यों Matter करते हैं
Bots automated software programs हैं जो एक human के बिना tasks perform करते हैं। बहुत से harmless हैं (search engine crawlers), पर malicious bots एक major security concern हैं: attackers बहुत से computers को bot malware से infect करते हैं और इन्हें एक botnet की तरह control करते हैं, compromised machines की एक army।
Botnets कुछ सबसे worst attacks power करते हैं: एक DDoS एक target को हज़ारों bots से एक साथ flood करता है (याद कीजिए क्यों यह रोकना इतना hard है), और bots spam भी भेजते हैं, malware फैलाते हैं, और data harvest करते हैं। तो जब आप 'botnet' सुनें, computers की एक hijacked army सोचिए जो एक attacker का bidding कर रही है। Bots ordinary infected devices को weapons में बदल देते हैं।
Quiz
DNS (Domain Name System) क्या करता है?
- यह नए devices को automatically IP addresses assign करता है
- यह domain names को IP addresses में translate करता है (internet की phonebook)
- यह एक network card का hardware address है
- यह networks के बीच packets forward करता है
Show the answer
यह domain names को IP addresses में translate करता है (internet की phonebook)
DNS (Domain Name System) human-friendly domain names को उन numeric IP addresses में translate करता है जो networks data route करने के लिए इस्तेमाल करते हैं, internet की phonebook की तरह act करते हुए। Option A DHCP describe करता है, जो network join करने वाले devices को automatically IP addresses assign करता है, एक अलग job। Option C एक MAC address describe करता है (network interface का hardware address), DNS नहीं। Option D एक router describe करता है, जो networks के बीच packets forward करता है। Terms को distinct रखिए: DNS names को addresses में resolve करता है, DHCP addresses देता है, MAC address hardware id है, और एक router networks के बीच route करता है।
Think first
Attackers DNS को Particular रूप में क्यों Care करते हैं?
DNS बस names को addresses में map करता है। यह cyber attacks में एक frequent target या tool क्यों है? फिर tap कीजिए।
Show the answer
क्योंकि DNS control करता है एक name कहाँ POINT करता है, तो इसे subvert करना एक attacker को victims को silently malicious destinations पर redirect करने देता है जबकि ये believe करते हैं कि ये एक legitimate site visit कर रहे हैं, एक powerful deception। याद कीजिए DNS क्या करता है: जब आप एक bank या store का domain name type करते हैं, DNS इसे उस IP address में translate करता है जिससे आपका device connect होता है। आप NAME को trust करते हैं, पर connection actually उस ADDRESS को follow करता है जो DNS return करता है। अगर एक attacker उस translation के साथ tamper कर सके, DNS spoofing या poisoning के through, या DNS settings compromise करके, ये trusted name को असली की बजाय THEIR malicious server के address में resolve करा सकते हैं। अब जब आप genuine domain type करते हैं, आप silently एक fake site पर भेजे जाते हैं जो identical दिखती है, जहाँ आप अपना login या card details सीधे attacker के हाथों में डाल सकते हैं (आपने study किए phishing और man-in-the-middle attacks का एक form)। Victim ने obviously कुछ गलत नहीं किया, इन्होंने correct address type किया, पर DNS ने quietly इन्हें astray भेजा। DNS दूसरे reasons से भी attackers के लिए attractive है: यह fundamental है (लगभग हर चीज़ इस पर rely करती है), अक्सर उस traffic से कम scrutinised है जो यह enable करता है, और malware के लिए command-and-control channels hide करने में abuse हो सकता है। और DNS infrastructure पर खुद attack करना internet के बड़े हिस्सों को offline कर सकता है, क्योंकि अगर names resolve नहीं हो सकते, services unreachable हो जाती हैं भले ये running हों। तो DNS attackers के लिए matter करता है क्योंकि यह TRUST और DIRECTION के एक point पर बैठा है: names से addresses तक mapping control कीजिए, और आप मर्ज़ी से redirect, intercept, या disrupt कर सकते हैं। यही वजह है DNS secure करना (और SSL certificates से sites verify करना, जो impostors detect करते हैं) important है। Phonebook जो control करता है वह control करता है लोग actually कहाँ जाते हैं।
Summary
Key takeaways
- Security core networking terms constantly reuse करती है, तो इन्हें pinned down रखना help करता है।
- एक IP address network पर device का unique numeric (logical) identifier है; एक MAC address इसकी permanent hardware id है।
- DNS (Domain Name System) domain names को IP addresses में translate करता है (internet की phonebook)।
- DHCP network join करने वाले devices को automatically IP addresses assign करता है; एक router networks के बीच packets forward करता है।
- Bots automated programs हैं; malicious ones एक botnet बनाते हैं, compromised machines की एक army जो DDoS, spam, और malware फैलाने के लिए इस्तेमाल होती है।
- Attackers DNS को target करते हैं क्योंकि name-to-address mapping control करना इन्हें victims को silently malicious sites पर redirect करने देता है।
- Memory hook: IP logical id, MAC hardware id, DNS names-to-addresses, DHCP addresses देता है, router route करता है, bots automated हैं (और एक botnet में dangerous)।