Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisHard
A security analyst is examining a network capture for signs of malware. They observe multiple outbound HTTP requests from an internal host to various, seemingly random, subdomains under a single legitimate-looking top-level domain (e.g., `randomstring1.legitdomain.com`, `randomstring2.legitdomain.com`). The response sizes are consistently small. What technique is this malware most likely employing for its command and control (C2) communication?
- ADNS Tunneling
- BSQL Injection
- CDomain Generation Algorithm (DGA)
- DHTTP Flood
Show answer & explanationAnswer & explanation
Correct answer: C. Domain Generation Algorithm (DGA)
A Domain Generation Algorithm (DGA) is a technique used by malware to generate a large number of seemingly random domain names that can be used as rendezvous points with their C2 servers. This makes it harder for security teams to block all C2 domains, as new ones are constantly generated.
Why the other options are wrong
- A. DNS tunneling involves encapsulating data within DNS queries/responses, typically on port 53, not HTTP requests to random subdomains.
- B. SQL injection is a web application vulnerability, not a network-level C2 communication technique involving random subdomains.
- D. An HTTP flood is a DoS attack involving high volumes of HTTP requests to a target, not C2 communication via random subdomains.
Domain Generation Algorithm (DGA)
A technique used by malware to algorithmically generate a large number of new domain names, which can be used as potential command and control (C2) servers, making it difficult for defenders to block all C2 communication paths.
- Generates new domains on the fly
- Used for C2 resilience
- Challenges traditional blacklisting approaches
Memory trick: C2 Evasion: DGA for Domains, DNS for Tunnels.