Detection: Prohibited Network Traffic Allowed

Description

The following analytic detects instances where network traffic, identified by port and transport layer protocol as prohibited in the "lookup_interesting_ports" table, is allowed. It uses the Network_Traffic data model to cross-reference traffic data against predefined security policies. This activity is significant for a SOC as it highlights potential misconfigurations or policy violations that could lead to unauthorized access or data exfiltration. If confirmed malicious, this could allow attackers to bypass network defenses, leading to potential data breaches and compromising the organization's security posture.

 1
 2| tstats `security_content_summariesonly`
 3  count min(_time) as firstTime
 4        max(_time) as lastTime
 5        values(All_Traffic.src_port) as src_port
 6        values(All_Traffic.action) as action
 7        values(All_Traffic.rule) as rule
 8
 9FROM datamodel=Network_Traffic WHERE
10
11All_Traffic.action IN ("allowed", "allow")
12[
13    
14| inputlookup interesting_ports_lookup where is_prohibited="true"
15    
16| table dest_port transport
17    
18| dedup dest_port transport
19    
20| rename dest_port as All_Traffic.dest_port
21    
22| rename transport as All_Traffic.transport
23]
24
25by All_Traffic.src_ip All_Traffic.dest_ip
26   All_Traffic.dest_port All_Traffic.dvc
27   All_Traffic.transport All_Traffic.vendor_product
28
29
30| lookup update=true interesting_ports_lookup dest_port as All_Traffic.dest_port transport as All_Traffic.transport OUTPUT app is_prohibited note
31
32
33| `security_content_ctime(firstTime)`
34
35| `security_content_ctime(lastTime)`
36
37| `drop_dm_object_name("All_Traffic")`
38
39| `prohibited_network_traffic_allowed_filter`

Data Source

Name Platform Sourcetype Source
Cisco Secure Firewall Threat Defense Connection Event Other 'cisco:sfw:estreamer' 'not_applicable'

Macros Used

Name Value
security_content_ctime convert timeformat="%Y-%m-%dT%H:%M:%S" ctime($field$)
prohibited_network_traffic_allowed_filter search *
prohibited_network_traffic_allowed_filter is an empty macro by default. It allows the user to filter out any results (false positives) without editing the SPL.

Annotations

- MITRE ATT&CK
+ Kill Chain Phases
+ NIST
+ CIS
- Threat Actors
ID Technique Tactic
T1048 Exfiltration Over Alternative Protocol Exfiltration
Actions on Objectives
DE.AE
CIS 13

Default Configuration

This detection is configured by default in Splunk Enterprise Security to run with the following settings:

Setting Value
Disabled true
Cron Schedule 0 * * * *
Earliest Time -70m@m
Latest Time -10m@m
Schedule Window auto
Creates Finding (Notable) No
Creates Intermediate Finding (Risk Event) Yes
Anomaly detections generate Intermediate Findings (Risk Events). They do not generate a Finding (Notable) directly.

Implementation

In order to properly run this search, Splunk needs to ingest data from firewalls or other network control devices that mediate the traffic allowed into an environment. This is necessary so that the search can identify an 'action' taken on the traffic of interest. The search also requires the Network_Traffic data model be populated.

Known False Positives

The "interesting_ports_lookup" lookup considers communication to ports like 20, 21 for FTP, 23 for Telnet, 110 for POP3, etc. as prohibited traffic. Which may result in a lot of alerts in certain environments that still rely on these ports for legitimate traffic. Tune as needed.

Associated Analytic Story

Intermediate Findings

Message Entity Field Entity Type Risk Score
Potentially Prohibited Network Traffic on Port [$dest_port$] via Protocol [$transport$] allowed from [$src_ip$]. src_ip system 20

Threat Objects

Field Type
dest_ip ip_address

References

Detection Testing

Test Type Status Dataset Source Sourcetype
Validation ✅ Passing N/A N/A N/A
Unit ✅ Passing Dataset not_applicable cisco:sfw:estreamer
Integration ✅ Passing Dataset not_applicable cisco:sfw:estreamer

Replay any dataset to Splunk Enterprise by using our replay.py tool or the UI. Alternatively you can replay a dataset into a Splunk Attack Range


Source: GitHub |

Version: 15