A security analyst is reviewing network traffic logs and observes multiple connections from an internal server to a known malicious IP address associated with a recent phishing campaign targeting the organization. The connections are encrypted and occur at irregular intervals. The analyst needs to determine the full scope of the compromise quickly. Which of the following analysis techniques would be most effective for understanding the communication patterns and potential data exfiltration without decrypting every packet?
- ALog correlation from endpoint detection and response (EDR) systems only
- BManual review of firewall allow/deny logs
- CFull packet capture and deep packet inspection
- DNetFlow analysis to identify connection metadata
Show answer & explanationAnswer & explanation
Correct answer: D. NetFlow analysis to identify connection metadata
NetFlow (or similar flow data like IPFIX, sFlow) provides metadata about network conversations (source/destination IPs, ports, protocols, timestamps, data volume) without inspecting the payload. This is crucial for understanding communication patterns, identifying connected hosts, and estimating data exfiltration volume from encrypted traffic quickly, without the overhead of full packet capture or the impossibility of decrypting unknown keys. While other options provide some insight, NetFlow gives the broadest network visibility for this specific scenario.
Why the other options are wrong
- A. Relying only on EDR logs might miss network-level details or other compromised hosts not covered by EDR, and doesn't directly address the network communication pattern of encrypted traffic.
- B. Manual review of firewall logs is time-consuming and provides less detail about the actual communication volume and duration compared to flow data.
- C. Full packet capture is resource-intensive, and deep packet inspection is ineffective for encrypted traffic without the keys, which the scenario implies are unavailable.
NetFlow Analysis
A network protocol developed by Cisco for collecting IP traffic information and monitoring network flow statistics.
- Captures metadata about network conversations (who, what, when, how much).
- Does not capture the actual payload content.
- Crucial for network visibility, anomaly detection, and incident response, especially with encrypted traffic.
Memory trick: Flows for metadata, PCAP for full details, IDS for signatures, EDR for endpoints.