Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications. The definition of a proxy can also be expanded to encompass trust relationships between networks in peer-to-peer, mesh, or trusted connections between networks consisting of hosts or systems that regularly communicate with each other. The network may be within a single organization or across multiple organizations with trust relationships. Adversaries could use these types of relationships to manage command and control communications, to reduce the number of simultaneous outbound network connections, to provide resiliency in the face of connection loss, or to ride over existing trusted communications paths between victims to avoid suspicion. (Citation: Enterprise ATT&CK January 2018)

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is related to Remote Terminal Unit (RTU)
is related to Safety Controller
is related to Distributed Control System (DCS) Controller
is related to Routers
is related to Jump Host
is related to Switch
is related to Human-Machine Interface (HMI)
is related to Field I/O
is related to Programmable Automation Controller (PAC)
is related to Application Server
is related to Workstation
is related to Firewall
is related to Control Server
is related to Data Historian
is related to Programmable Logic Controller (PLC)
is related to Virtual Private Network (VPN) Server
is related to Intelligent Electronic Device (IED)
is related to Data Gateway
is blocked by SSL/TLS Inspection
is blocked by Network Intrusion Prevention
is blocked by Filter Network Traffic
is blocked by Detection of Connection Proxy
is blocked by Network Allowlists
Impressum German English