Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisHard

A security analyst is examining a PCAP file and notices a series of TCP connections where the SYN and ACK flags are set in the initial handshake, but the PSH flag is immediately set in subsequent data packets, even for very small payloads. This occurs repeatedly from an internal host to several external IP addresses known to be associated with command-and-control infrastructure. What network intrusion technique does this behavior most strongly suggest?

  1. AC2 communication using PSH flag for rapid data transfer
  2. BCovert channel using TCP sequence numbers
  3. CNmap's Xmas scan
  4. DFast-flux DNS
Show answer & explanation

Correct answer: A. C2 communication using PSH flag for rapid data transfer

The immediate and frequent use of the PSH flag for small payloads after the initial handshake, especially to known C2 infrastructure, is a common indicator of malware attempting to push data quickly to its C2 server without waiting for buffer fills, often to evade detection by minimizing connection duration.

Why the other options are wrong

  • B. Covert channels using TCP sequence numbers involve manipulating sequence numbers, not primarily the PSH flag, and are more subtle.
  • C. Nmap's Xmas scan involves setting FIN, URG, and PSH flags in a single packet to probe ports, not ongoing data transfer.
  • D. Fast-flux DNS is a technique for quickly changing DNS records to hide C2 servers, not a direct network communication pattern seen in individual TCP flows.

PSH Flag Abuse (C2)

Malware can abuse the TCP PSH (Push) flag to force immediate delivery of small data segments to a command-and-control (C2) server, bypassing buffering delays. This allows for rapid, low-latency communication, which can be harder to detect than larger, more sustained data transfers.

  • TCP PSH flag forces immediate data delivery
  • Abused by malware for rapid C2 communication
  • Often seen with small payloads to C2 servers
  • Helps malware minimize connection duration and evade detection

Memory trick: TCP Flags are like 'Traffic Signals', and malware often runs a red light (PSH) to speed past.

More Network Intrusion Analysis questions