CompTIA CySA+ (CS0-003)Incident Response and ManagementMedium
A security analyst is investigating a suspected data exfiltration incident. The attacker gained access to a critical server and is believed to be using a covert channel for data transfer. The analyst observes the following log entries from a firewall: ``` TIME=2023-10-26T14:35:01 SRC_IP=192.168.1.10 DST_IP=8.8.8.8 PROTO=UDP DST_PORT=53 LEN=72 TIME=2023-10-26T14:35:02 SRC_IP=192.168.1.10 DST_IP=8.8.8.8 PROTO=UDP DST_PORT=53 LEN=85 TIME=2023-10-26T14:35:03 SRC_IP=192.168.1.10 DST_IP=8.8.8.8 PROTO=UDP DST_PORT=53 LEN=69 TIME=2023-10-26T14:35:04 SRC_IP=192.168.1.10 DST_IP=8.8.8.8 PROTO=UDP DST_PORT=53 LEN=78 ``` Which type of covert channel is most likely indicated by these log entries?
- AHTTP tunneling
- BICMP tunneling
- CSSH tunneling
- DDNS tunneling
Show answer & explanationAnswer & explanation
Correct answer: D. DNS tunneling
The log entries show consistent outbound UDP traffic on destination port 53 (DNS) to a well-known public DNS server (8.8.8.8), with varying packet lengths. This pattern is highly indicative of DNS tunneling, where data is encoded within legitimate DNS queries and responses to bypass firewalls and exfiltrate data.
Why the other options are wrong
- A. HTTP tunneling typically uses TCP ports 80 or 443.
- B. ICMP tunneling uses the ICMP protocol, not UDP port 53.
- C. SSH tunneling typically uses TCP port 22 and would not appear as UDP port 53 traffic.
DNS Tunneling
A type of covert channel that encodes data within DNS queries and responses, allowing attackers to bypass firewalls and exfiltrate data or establish command and control.
- Uses UDP port 53, the standard port for DNS.
- Often involves unusual subdomains or query types.
- Can be detected by analyzing DNS query patterns and sizes.
Memory trick: Sneaky Data Goes Through Uncommon Ports