Host Discovery |
Attack Pattern ID: 292 (Standard Attack Pattern Completeness: Stub) | Typical Severity: Low | Status: Draft |
Summary
An attacker sends a probe to an IP address to determine if the host is alive. Host discovery is one of the earliest phases of network reconnaissance. An attacker usually starts with a range of IP addresses belonging to a target network and uses various methods to determine if a host is present at that IP address. Host discovery is usually referred to as 'Ping' scanning using a sonar analogy. The goal of the attacker is to send a packet through to the IP address and solicit a response from the host. As such, a 'ping' can be virtually any crafted packet whatsoever, provided the attacker can identify a functional host based on its response. An attack of this nature is usually carried out with a 'ping sweep' where a particular kind of ping is sent to a range of IP addresses.
Target Attack Surface Description
Targeted OSI Layers: Network Layer Transport Layer
Target Attack Surface Localities
Target Attack Surface Types: Network Host
The resources required will differ based upon the type of host discovery being performed. Usually a scanner or scanning script is required due to the volume of requests that must be generated.
Nature | Type | ID | Name | Description | View(s) this relationship pertains to![]() |
---|---|---|---|---|---|
ChildOf | ![]() | 309 | Scanning for Devices, Systems, or Routes | Mechanism of Attack1000 | |
ParentOf | ![]() | 285 | ICMP Echo Request Ping | Mechanism of Attack1000 | |
ParentOf | ![]() | 288 | ICMP Echo Request Ping | Mechanism of Attack1000 | |
ParentOf | ![]() | 294 | ICMP Address Mask Request | Mechanism of Attack1000 | |
ParentOf | ![]() | 295 | ICMP Timestamp Request | Mechanism of Attack1000 | |
ParentOf | ![]() | 296 | ICMP Information Request | Mechanism of Attack1000 | |
ParentOf | ![]() | 297 | TCP ACK Ping | Mechanism of Attack1000 | |
ParentOf | ![]() | 298 | UDP Ping | Mechanism of Attack1000 | |
ParentOf | ![]() | 299 | TCP SYN Ping | Mechanism of Attack1000 |