Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. Protocols such as HTTP/S(Citation: CrowdStrike Putter Panda) and WebSocket(Citation: Brazking-Websockets) that carry web traffic may be very common in environments. HTTP/S packets have many fields and headers in which data can be concealed. An adversary may abuse these protocols to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by Network Intrusion Prevention
is blocked by Detection of Web Protocol-Based C2 Over HTTP, HTTPS, or WebSockets
is blocked by Filter Network Traffic
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Covert Channel Analysis
is blocked by Malicious Code Protection (Anti-Malware)
is blocked by Boundary Protection
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
is blocked by Network Connection Termination
is blocked by Session Integrity
is blocked by Domain Name Service (DNS) Resolution
is blocked by Architecture & Provisioning for Name / Address Resolution Service
is blocked by Secure Name / Address Resolution Service (Recursive or Caching Resolver)
is blocked by Out-of-Band Channels
Impressum German English