What Are the Cyberattacks at Each OSI Layer and How Can You Defend Against Them?
Understanding the OSI model is crucial in cybersecurity, as each of its seven layers can be targeted by specific types of cyberattacks. From phishing and ransomware at the application layer to ARP poisoning and cable tapping at the data link and physical layers, knowing where threats originate enables stronger, layered defense. This blog explores real-time attack scenarios for each OSI layer and provides actionable security strategies for effective threat mitigation.
Quick answer: Each of the OSI model's seven layers faces different attacks and needs different defences. Top to bottom: the application layer faces phishing and injection, the presentation layer faces encryption downgrades, the session layer faces hijacking, the transport layer faces floods and scanning, the network layer faces spoofing and routing attacks, the data link layer faces ARP and MAC attacks, and the physical layer faces tampering and keyloggers. Mapping threats to layers helps you place the right control at the right level.
Key takeaways
- Map attacks to layers: ARP and MAC attacks at Layer 2, spoofing at Layer 3, floods at Layer 4, injection at Layer 7.
- A web application firewall will not stop ARP spoofing, so each control must sit at the layer where the attack happens.
- Defend Layer 2 with port security and dynamic ARP inspection, and Layer 4 with firewalls, rate limiting and SYN-flood protection.
Thinking in layers turns a vague "secure the network" goal into specific, testable controls. This guide walks each OSI layer, the attacks that target it and the defences that stop them, with the India context in mind. If you need a refresher on the model itself first, read our explainer on the OSI model in networking.
Why map attacks to OSI layers?
Because defences live at specific layers, and an attack ignored at one layer cannot be fixed at another. A web application firewall does nothing about a hardware keylogger; a cable lock does nothing about SQL injection. Mapping threats to layers gives you a checklist: for each layer, what can go wrong here, and what control sits here to catch it? It is also how exam objectives for CEH, Security+ and network certifications are framed, so the mental model pays off twice.
| Layer | Common attacks | Primary defences |
|---|---|---|
| 7 Application | Phishing, SQL injection, XSS, malware delivery | WAF, email filtering, input validation, user training |
| 6 Presentation | TLS/SSL downgrade, encoding abuse | HSTS, modern TLS, certificate checks |
| 5 Session | Session hijacking, token theft | Secure cookies, short timeouts, MFA |
| 4 Transport | SYN floods, port scanning, TLS downgrade | Rate limiting, SYN cookies, firewalls |
| 3 Network | IP spoofing, ICMP floods, routing abuse | ACLs, anti-spoofing filters, segmentation, IDS |
| 2 Data link | ARP poisoning, MAC spoofing, VLAN hopping | Port security, DHCP snooping, dynamic ARP inspection |
| 1 Physical | Cable tapping, hardware keyloggers, jamming | Physical access control, port locks, inspections |
Layer 7: Application layer attacks
This is where users and applications meet, so it is the most attacked layer. Threats here exploit either people or software flaws: phishing emails, malicious attachments, SQL injection, and cross-site scripting (XSS). Most breaches that make the news start here.
Example: a finance team member receives a convincing invoice email with a macro-enabled spreadsheet. Opening and enabling the macro runs code that encrypts shared files.
Defences: filter email and strip risky attachments; put a web application firewall in front of public apps; validate and parameterise all input to prevent injection (our guide to testing for SQL injection with sqlmap shows how testers check this); and run regular phishing awareness training, since no filter catches everything.
Layer 6: Presentation layer attacks
This layer handles encryption, compression and data formats. Attacks here try to weaken or strip encryption so data travels in the clear, or abuse how data is encoded.
Example: on an untrusted public Wi-Fi network, an attacker positioned between the user and the gateway forces a connection down from HTTPS to HTTP, so credentials are visible.
Defences: enforce HTTP Strict Transport Security (HSTS) so browsers refuse to drop to HTTP; disable old SSL and weak TLS versions and ciphers; and check certificates properly. These downgrade attacks fail when the client simply will not accept an unencrypted connection.
Layer 5: Session layer attacks
The session layer manages the dialogue between two systems. Attacks here steal or ride an already-authenticated session, so the attacker does not need the password at all.
Example: a user logs into a web app over an untrusted network. An attacker who can read the traffic captures the session cookie and reuses it to act as that user.
Defences: mark cookies Secure and HttpOnly so they only travel over HTTPS and are hidden from scripts; expire sessions quickly and on logout; bind sessions to extra signals where practical; and require multi-factor authentication, which limits what a stolen session is worth. Session hijacking often overlaps with man-in-the-middle attacks, covered in our guide to man-in-the-middle attacks.
Layer 4: Transport layer attacks
The transport layer sets up and manages end-to-end connections, mainly TCP and UDP. Attacks here either exhaust connection resources or probe for open services.
Example: a botnet sends a flood of TCP SYN requests to a web server and never completes the handshakes, filling the connection table so real users cannot get through.
Defences: enable SYN cookies and connection rate limiting; put a firewall and, for public services, a DDoS mitigation service in front; and monitor for port-scanning patterns so you see reconnaissance before the real attack.
Layer 3: Network layer attacks
The network layer routes packets using IP addresses. Attacks here forge source addresses, flood with ICMP, or interfere with routing to redirect or disrupt traffic.
Example: an attacker spoofs the IP address of an internal server to slip past an access rule that trusts that address.
Defences: apply anti-spoofing filters (such as BCP 38 ingress filtering) so packets with impossible source addresses are dropped; use access control lists and network segmentation to limit trust; and watch with an intrusion detection system. For the difference between detection and prevention, see our guide to IDS and IPS.
Layer 2: Data link layer attacks
The data link layer moves frames on the local network using MAC addresses and protocols such as ARP. Because many of these protocols were designed without authentication, this layer is a favourite for attackers who already have a foothold on the LAN.
Example: a rogue device on the LAN sends forged ARP replies so that other machines send their traffic through it, letting it read or alter that traffic.
Defences: turn on switch port security to limit MAC addresses per port; enable DHCP snooping and dynamic ARP inspection to block forged replies; and lock down VLAN trunking to prevent VLAN hopping. We cover one of these in depth in our explainer on VLAN hopping attacks.
Layer 1: Physical layer attacks
The physical layer is the cabling, ports and hardware. If an attacker can touch your equipment, most software controls can be bypassed, which is why physical security is a security control, not a facilities afterthought.
Example: in a shared workspace, a small hardware keylogger is fitted between a keyboard and a desktop, recording everything typed, including passwords.
Defences: control who can reach server rooms, cabinets and desks; disable unused ports and use port locks; inspect shared machines for unexpected inline devices; and protect wireless with modern encryption and monitoring for jamming or rogue access points.
How layered attacks chain together
Real incidents rarely stay on one layer. A phishing email (Layer 7) can install malware that scans for services (Layer 4), spoofs addresses to move around (Layer 3) and poisons ARP to capture credentials (Layer 2). This is why defence in depth works: if one layer's control fails, the next can still stop or at least reveal the attack. Map each control you own to a layer, and the gaps become obvious.
A note on the law in India
Studying these attacks is essential for defenders, but running them against systems you do not own or are not authorised to test is an offence under Sections 43 and 66 of the Information Technology Act, 2000. Practise attack techniques only in your own lab or under a written engagement, and use this knowledge to build and test defences.
What to do next
Turn the table above into an audit of your own environment: for each layer, write down the control you have and the one you are missing, then fix the biggest gap first. The physical and data link layers are the ones most often overlooked. If you want to learn to test and defend each layer hands-on, the CEH v13 AI ethical hacking course works through network attacks and countermeasures layer by layer.
Related reading
Frequently Asked Questions
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Wow
0
Sad
0
Angry
0