What Are the Cyberattacks at Each OSI Layer and How Can You Defend Against Them?

Understanding the OSI model is crucial in cybersecurity, as each of its seven layers can be targeted by specific types of cyberattacks. From phishing and ransomware at the application layer to ARP poisoning and cable tapping at the data link and physical layers, knowing where threats originate enables stronger, layered defense. This blog explores real-time attack scenarios for each OSI layer and provides actionable security strategies for effective threat mitigation.

Jul 19, 2025 - 09:52
Updated: 6 days ago
105.6k
What Are the Cyberattacks at Each OSI Layer and How Can You Defend Against Them?

Quick answer: Each of the OSI model's seven layers faces different attacks and needs different defences. Top to bottom: the application layer faces phishing and injection, the presentation layer faces encryption downgrades, the session layer faces hijacking, the transport layer faces floods and scanning, the network layer faces spoofing and routing attacks, the data link layer faces ARP and MAC attacks, and the physical layer faces tampering and keyloggers. Mapping threats to layers helps you place the right control at the right level.

Key takeaways

  • Map attacks to layers: ARP and MAC attacks at Layer 2, spoofing at Layer 3, floods at Layer 4, injection at Layer 7.
  • A web application firewall will not stop ARP spoofing, so each control must sit at the layer where the attack happens.
  • Defend Layer 2 with port security and dynamic ARP inspection, and Layer 4 with firewalls, rate limiting and SYN-flood protection.

Thinking in layers turns a vague "secure the network" goal into specific, testable controls. This guide walks each OSI layer, the attacks that target it and the defences that stop them, with the India context in mind. If you need a refresher on the model itself first, read our explainer on the OSI model in networking.

Why map attacks to OSI layers?

Because defences live at specific layers, and an attack ignored at one layer cannot be fixed at another. A web application firewall does nothing about a hardware keylogger; a cable lock does nothing about SQL injection. Mapping threats to layers gives you a checklist: for each layer, what can go wrong here, and what control sits here to catch it? It is also how exam objectives for CEH, Security+ and network certifications are framed, so the mental model pays off twice.

LayerCommon attacksPrimary defences
7 ApplicationPhishing, SQL injection, XSS, malware deliveryWAF, email filtering, input validation, user training
6 PresentationTLS/SSL downgrade, encoding abuseHSTS, modern TLS, certificate checks
5 SessionSession hijacking, token theftSecure cookies, short timeouts, MFA
4 TransportSYN floods, port scanning, TLS downgradeRate limiting, SYN cookies, firewalls
3 NetworkIP spoofing, ICMP floods, routing abuseACLs, anti-spoofing filters, segmentation, IDS
2 Data linkARP poisoning, MAC spoofing, VLAN hoppingPort security, DHCP snooping, dynamic ARP inspection
1 PhysicalCable tapping, hardware keyloggers, jammingPhysical access control, port locks, inspections

Layer 7: Application layer attacks

This is where users and applications meet, so it is the most attacked layer. Threats here exploit either people or software flaws: phishing emails, malicious attachments, SQL injection, and cross-site scripting (XSS). Most breaches that make the news start here.

Example: a finance team member receives a convincing invoice email with a macro-enabled spreadsheet. Opening and enabling the macro runs code that encrypts shared files.

Defences: filter email and strip risky attachments; put a web application firewall in front of public apps; validate and parameterise all input to prevent injection (our guide to testing for SQL injection with sqlmap shows how testers check this); and run regular phishing awareness training, since no filter catches everything.

Layer 6: Presentation layer attacks

This layer handles encryption, compression and data formats. Attacks here try to weaken or strip encryption so data travels in the clear, or abuse how data is encoded.

Example: on an untrusted public Wi-Fi network, an attacker positioned between the user and the gateway forces a connection down from HTTPS to HTTP, so credentials are visible.

Defences: enforce HTTP Strict Transport Security (HSTS) so browsers refuse to drop to HTTP; disable old SSL and weak TLS versions and ciphers; and check certificates properly. These downgrade attacks fail when the client simply will not accept an unencrypted connection.

Layer 5: Session layer attacks

The session layer manages the dialogue between two systems. Attacks here steal or ride an already-authenticated session, so the attacker does not need the password at all.

Example: a user logs into a web app over an untrusted network. An attacker who can read the traffic captures the session cookie and reuses it to act as that user.

Defences: mark cookies Secure and HttpOnly so they only travel over HTTPS and are hidden from scripts; expire sessions quickly and on logout; bind sessions to extra signals where practical; and require multi-factor authentication, which limits what a stolen session is worth. Session hijacking often overlaps with man-in-the-middle attacks, covered in our guide to man-in-the-middle attacks.

Layer 4: Transport layer attacks

The transport layer sets up and manages end-to-end connections, mainly TCP and UDP. Attacks here either exhaust connection resources or probe for open services.

Example: a botnet sends a flood of TCP SYN requests to a web server and never completes the handshakes, filling the connection table so real users cannot get through.

Defences: enable SYN cookies and connection rate limiting; put a firewall and, for public services, a DDoS mitigation service in front; and monitor for port-scanning patterns so you see reconnaissance before the real attack.

Layer 3: Network layer attacks

The network layer routes packets using IP addresses. Attacks here forge source addresses, flood with ICMP, or interfere with routing to redirect or disrupt traffic.

Example: an attacker spoofs the IP address of an internal server to slip past an access rule that trusts that address.

Defences: apply anti-spoofing filters (such as BCP 38 ingress filtering) so packets with impossible source addresses are dropped; use access control lists and network segmentation to limit trust; and watch with an intrusion detection system. For the difference between detection and prevention, see our guide to IDS and IPS.

Layer 2: Data link layer attacks

The data link layer moves frames on the local network using MAC addresses and protocols such as ARP. Because many of these protocols were designed without authentication, this layer is a favourite for attackers who already have a foothold on the LAN.

Example: a rogue device on the LAN sends forged ARP replies so that other machines send their traffic through it, letting it read or alter that traffic.

Defences: turn on switch port security to limit MAC addresses per port; enable DHCP snooping and dynamic ARP inspection to block forged replies; and lock down VLAN trunking to prevent VLAN hopping. We cover one of these in depth in our explainer on VLAN hopping attacks.

Layer 1: Physical layer attacks

The physical layer is the cabling, ports and hardware. If an attacker can touch your equipment, most software controls can be bypassed, which is why physical security is a security control, not a facilities afterthought.

Example: in a shared workspace, a small hardware keylogger is fitted between a keyboard and a desktop, recording everything typed, including passwords.

Defences: control who can reach server rooms, cabinets and desks; disable unused ports and use port locks; inspect shared machines for unexpected inline devices; and protect wireless with modern encryption and monitoring for jamming or rogue access points.

How layered attacks chain together

Real incidents rarely stay on one layer. A phishing email (Layer 7) can install malware that scans for services (Layer 4), spoofs addresses to move around (Layer 3) and poisons ARP to capture credentials (Layer 2). This is why defence in depth works: if one layer's control fails, the next can still stop or at least reveal the attack. Map each control you own to a layer, and the gaps become obvious.

A note on the law in India

Studying these attacks is essential for defenders, but running them against systems you do not own or are not authorised to test is an offence under Sections 43 and 66 of the Information Technology Act, 2000. Practise attack techniques only in your own lab or under a written engagement, and use this knowledge to build and test defences.

What to do next

Turn the table above into an audit of your own environment: for each layer, write down the control you have and the one you are missing, then fix the biggest gap first. The physical and data link layers are the ones most often overlooked. If you want to learn to test and defend each layer hands-on, the CEH v13 AI ethical hacking course works through network attacks and countermeasures layer by layer.

Related reading

Frequently Asked Questions

Because defences live at specific layers. Mapping each threat to its layer gives you a checklist: for every layer you ask what can go wrong and which control belongs there. It also matches how CEH, Security+ and network exams frame attacks, so the model helps in both work and study.

Layer 7, the application layer, where users and software meet. Phishing, malicious attachments, SQL injection and cross-site scripting all target it, and most publicised breaches begin here through either human error or an application flaw.

Layer 2 attacks include ARP poisoning, MAC spoofing and VLAN hopping. They work because protocols like ARP were designed without authentication, so an attacker already on the LAN can reroute or capture traffic. Port security, DHCP snooping and dynamic ARP inspection are the main defences.

Control who can physically reach cabling, ports and hardware. Lock server rooms and cabinets, disable unused ports and fit port locks, inspect shared machines for inline devices such as hardware keyloggers, and protect wireless with modern encryption and monitoring for rogue access points.

It is a presentation-layer attack where an attacker between the user and server forces the connection to use weaker or no encryption, so data can be read. Enforcing HTTP Strict Transport Security and disabling old SSL and TLS versions prevents it, because the client refuses to drop to an insecure connection.

There is no single control; defence in depth is the point. Real attacks chain across layers, so you place a control at each layer and rely on the next one when one fails. Multi-factor authentication, segmentation and monitoring give broad protection across several layers at once.

Only on systems you own or are authorised in writing to test. Running these techniques against other systems can breach Sections 43 and 66 of the Information Technology Act, 2000. Use an isolated lab or a signed engagement, and apply what you learn to defence.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Wow Wow 0
Sad Sad 0
Angry Angry 0
Vaishnavi

Vaishnavi is a skilled tech professional at the Ethical Hacking Training Institute in Pune, responsible for managing and optimizing the technical infrastructure that supports advanced cybersecurity education. With deep expertise in network security, backend operations, and system performance, she ensures that practical labs, online modules, and assessments run smoothly and securely. Her behind-the-scenes contributions play a vital role in delivering a seamless and secure learning experience for aspiring ethical hackers.