Spoofing

Forging an identifier, such as an IP address, MAC address, DNS answer or email sender, so that a system or person accepts traffic or a message as coming from a trusted source.

Spoofing is presenting a false identity to a system or a person. The forged identifier can sit at almost any layer: the source IP address in a packet header, the MAC address of a network card, an ARP reply that maps the wrong hardware address to a gateway (ARP spoofing), a false DNS answer planted by DNS cache poisoning, or the sender field of a message (email spoofing). It works wherever a protocol accepts an identifier without verifying it. It is also the first category of the STRIDE threat model, violating authentication.

Spoofing is often a means rather than an end. A forged ARP or DNS answer is a common way to set up a man-in-the-middle attack, and a forged source address is what makes a reflection attack send its replies to the victim. The defences follow the layer: authenticating the source (for example DNSSEC for DNS, and SPF, DKIM and DMARC for email), and at the network edge, ingress filtering that drops packets whose source address cannot legitimately arrive from that direction (RFC 2827, also published as BCP 38).

Exam relevance: questions in this area tend to describe the forged identifier and ask for the attack or control. Candidates are expected to match each layer to its defence and to see spoofing as the enabler of interception and reflection.