Cisco CyberOps Associate (CBROPS) 200-201Network Intrusion AnalysisMedium
A security analyst is investigating a series of alerts from an Intrusion Detection System (IDS) indicating unusual outbound ICMP traffic from several internal workstations to external IP addresses. The ICMP packets contain unusually large data payloads that do not correspond to standard diagnostic messages. What type of network intrusion technique is most likely being employed?
- APort scanning
- BSYN Flood attack
- CARP spoofing
- DICMP tunneling
Show answer & explanationAnswer & explanation
Correct answer: D. ICMP tunneling
ICMP tunneling is a technique used to encapsulate arbitrary data within ICMP echo request and reply packets, often for covert communication or data exfiltration. The large, non-standard data payloads within ICMP traffic are a strong indicator of this technique.
Why the other options are wrong
- A. Port scanning involves attempts to connect to various ports on a target, typically using TCP or UDP, not large ICMP data payloads.
- B. SYN flood attacks involve a high volume of TCP SYN packets, not ICMP, and aim to disrupt service, not exfiltrate data.
- C. ARP spoofing manipulates MAC-to-IP address mappings on a local network segment and does not involve unusual outbound ICMP traffic with large payloads.
ICMP Tunneling
A technique that encapsulates IP traffic, or other data, within the data section of ICMP echo request and reply packets to create a covert communication channel.
- Often used for command and control (C2) or data exfiltration.
- Can bypass some firewall rules that permit ICMP traffic.
- Characterized by unusually large or non-standard data in ICMP packets.
Memory trick: Covert channels are like ghosts, hard to see but leave strange traces.