Forge University

Mapping Cloud and Network Threats to the Right Mitigation

Before you can defend a network you have to speak the language of what's attacking it — this lesson builds the threat, vulnerability, and mitigation vocabulary that every later control in this domain assumes you already know.

Common Attack Types

A DDoS attack comes in three flavors you should be able to tell apart: volumetric floods that simply saturate bandwidth, protocol attacks like SYN floods that exhaust connection-state tables on a server or firewall, and application-layer floods (like an HTTP GET flood) that look like legitimate traffic but exhaust backend resources such as database connections. On-path attacks (the modern term for man-in-the-middle) place the attacker between two communicating parties — think ARP spoofing on a LAN segment, a rogue access point mimicking a trusted SSID, or SSL-stripping that silently downgrades HTTPS to HTTP. Credential reuse attacks (credential stuffing) take usernames and passwords leaked from one breach and replay them against other services, which is why unique passwords plus MFA defeat this class outright. BGP hijacking happens when an autonomous system announces IP prefixes it doesn't legitimately own, which can silently redirect, blackhole, or allow interception of traffic destined for the real owner — this has caused real internet outages and traffic-interception incidents. Social engineering — phishing, pretexting, baiting — bypasses technical controls entirely by manipulating a human into granting access or divulging information.

Underlying Vulnerabilities

Attacks succeed because a vulnerability exists underneath them. A zero-day is a flaw unknown to the vendor (and therefore unpatched) at the time it's exploited, which is why defense-in-depth matters even when patching is current. The OWASP Top 10 is the standard reference classification of the most critical web-application risks — injection flaws, broken access control, security misconfiguration, and so on — and it gives security teams a shared vocabulary for prioritizing application-layer risk. In practice, the single most common real-world entry point is simple misconfiguration: default credentials left in place, an overly permissive cloud storage bucket, a security group open to 0.0.0.0/0, or unpatched firmware sitting on a forgotten device.

Mitigation Practices and Frameworks

DLP (Data Loss Prevention) inspects outbound traffic and endpoints for sensitive data patterns (credit card numbers, health records) and blocks or flags exfiltration attempts. IPAM (IP Address Management) gives you an authoritative inventory of what's using every address on the network, which turns "who is this device and why is it talking to our database" from a mystery into a lookup. MITRE ATT&CK is a continuously updated knowledge base of real-world adversary tactics and techniques, used to map your existing defenses against how attackers actually operate rather than against a hypothetical threat. CIS Benchmarks are vendor- and platform-specific configuration standards (for a given OS, cloud provider, or network device) that translate "harden this system" into a concrete, auditable checklist.

Key Mechanics

  • DDoS has three distinct attack surfaces: volumetric (bandwidth), protocol (state tables), and application-layer (backend resources) — each needs a different mitigation.
  • Credential stuffing exploits password reuse across sites, not a flaw in any single system — MFA is the primary defense.
  • BGP hijacking is a routing-layer threat, not a payload-based attack — it exploits trust between autonomous systems.
  • MITRE ATT&CK organizes attacker behavior into tactics and techniques; CIS Benchmarks organize secure configuration into hardening checklists — they solve different problems.
  • Misconfiguration, not zero-days, is the most statistically common root cause of real-world breaches.

Exam Tip: Don't confuse an on-path (MITM) attack with a DDoS attack — a scenario describing traffic being silently read or altered in transit is on-path; a scenario describing service becoming unavailable due to volume is DDoS.

Exam Tip: The exam may describe a scenario where a misconfigured router announces someone else's IP space — that's BGP hijacking, not DNS poisoning or ARP spoofing, even though the symptom (traffic going to the wrong place) can look similar.

Exam Tip: MITRE ATT&CK and CIS Benchmarks are both "frameworks" in casual speech, but the exam expects you to know ATT&CK maps attacker tactics/techniques while CIS Benchmarks map secure configuration baselines — they are not interchangeable answers.

Diagram

Worked example: A network engineer notices an unusual spike in outbound traffic to an unfamiliar IP range at 2 a.m., alongside several failed then successful admin logins from a new geographic location. Cross-referencing IPAM confirms the destination isn't a known internal or partner system, and the login pattern matches credential-stuffing behavior in the organization's MITRE ATT&CK-mapped playbook. The response team resets the compromised account's credentials, enforces MFA org-wide, and confirms DLP rules would have flagged the outbound data had it contained regulated data patterns — closing both the immediate access gap and the process gap that let it happen.

Knowledge check

Click an option to check yourself — this is a self-check, not graded or saved. The graded version pooling this module's questions is on the syllabus page.

1. A company's edge router suddenly begins receiving traffic destined for a partner organization's public IP block after another ISP's router mistakenly (or maliciously) announces routes for that block. Internal users report that some connections to the partner's services are being intercepted or fail entirely. What is this an example of?

2. A security audit finds that a cloud storage bucket containing customer records was left publicly readable for months due to a default setting nobody changed. No exploit code or unpatched software was involved. Which category best explains the root cause?

3. A SOC team wants to evaluate whether their current detection rules would catch the specific tactics and techniques real-world ransomware groups have been observed using, such as particular lateral-movement and credential-access methods. Which resource is purpose-built for this comparison?

4. An attacker sends a massive volume of traffic designed purely to saturate a target's internet bandwidth, without targeting any specific application logic. Which DDoS category is this?

5. An attacker sends a high volume of SYN packets designed specifically to exhaust a firewall's connection-state table rather than saturate bandwidth. Which DDoS category is this?

6. An attacker on a LAN segment sends forged ARP replies so that traffic between two hosts is silently routed through the attacker's machine, letting them read or alter it. What is this attack called?

7. An attacker takes a list of usernames and passwords leaked from an unrelated breach and attempts to log into a company's portal with them, succeeding for the small percentage of users who reused the same password. What is this attack called?

8. A vulnerability is actively exploited in the wild before the software vendor is even aware it exists or has issued a patch. What is this called?

9. An attacker calls an employee pretending to be IT support and convinces them to read out their MFA code over the phone. What category of attack is this?

10. A security team wants a standard reference classification of the most critical web-application risks, such as injection flaws and broken access control, to help prioritize application-layer risk. Which resource fits?

11. A security team investigating an unusual internal connection wants an authoritative inventory of which device is actually using a specific IP address on the network. Which tool provides this?

12. A company wants to automatically detect and block an employee from emailing a spreadsheet containing customer credit card numbers outside the organization. Which technology is purpose-built for this?

Log in to chat with your AI Mentor about this lesson.