A security analyst observes a flurry of network traffic alerts from the SIEM, all related to a single internal host. The alerts indicate attempts to connect to multiple external IP addresses on various high-numbered UDP ports, followed by a sudden decrease in the host's normal application traffic. What does this pattern of activity most strongly suggest?
- AA compromised host participating in a DDoS attack
- BRoutine system updates
- CUser attempting to bypass proxy controls
- DLegitimate peer-to-peer file sharing
Show answer & explanationAnswer & explanation
Correct answer: A. A compromised host participating in a DDoS attack
A 'flurry of network traffic alerts' from a 'single internal host' attempting to connect to 'multiple external IP addresses on various high-numbered UDP ports' is characteristic of a bot participating in a DDoS attack. The 'sudden decrease in the host's normal application traffic' further supports this, as the host's resources are being consumed by the attack traffic, leading to degraded performance for legitimate applications.
Why the other options are wrong
- B. Routine system updates typically involve connections to known update servers on standard ports (e.g., HTTP/S) and would not drastically reduce application traffic in this manner.
- C. Bypassing proxy controls might involve unusual outbound connections, but the *volume* to *multiple external IPs* and the *impact on normal traffic* are more indicative of a DDoS bot.
- D. Legitimate P2P file sharing would involve connections to other peers, but a 'flurry of alerts' to 'multiple external IPs' with a 'sudden decrease in normal application traffic' suggests malicious, resource-intensive activity.
DDoS Attack Participation (Bot)
When a compromised host (a 'bot') is controlled by an attacker to send high volumes of traffic to a target, contributing to a Distributed Denial of Service (DDoS) attack, often leading to resource starvation on the bot itself.
- High volume of outbound traffic from a single internal host.
- Traffic destined for multiple external targets.
- Often uses UDP or SYN floods.
- Impacts the compromised host's normal operations.
Memory trick: A stressed host, like a runner, has less energy for other tasks.