Base64 encoded HTTP traffic.

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Content translations are temporarily unavailable due to site maintenance. We apologize for any inconvenience. Visit our blog to learn more.

Base64 encoded HTTP traffic.

L3 Networker

Hi,

I was reading the 2011-2012 buyers giude. There is a statement that describes Base64 encoded HTTP messages , used in command and control traffic for malware.

The bot sets the User-Agent header value to “inter easy” and also receives a scrambledBase64 encoded command which means “sleep”: <!-- 2upczxAX.3

Most network security controls would pass this bot’s traffic withno complaints, as it appears to resemble common Web applicationtraffic. If a firewall was capable of analyzing all HTTP andHTTPS traffic and determine that the traffic was anomalous insome way, either based on behavior patterns of browsing, or theunusual request and response strings or patterns, then this couldpotentially be blocked. However, even most intrusion detectionand prevention devices today would rely on a standard signaturebasedmethod to detect this, and most likely wouldn’t.

How does Palo Alto firewalls deal with such traffic ? I guess it would have to rely on signatures itself right ? , But the Botnet detection logic would let you see if these patterns would be going to known malware links? . I am trying to get past markeing and understand how it really works.

One more question , If I set up my own websever at home and connected to that on IP address, Will Palo flag that as unusual trafiic ? and where can I see that? and how do I reliably block that ?

Thanks ,

Sunil

1 REPLY 1

L6 Presenter

@sunilsadanandan:

In the first scenario you describe, we would most likely write a signature for the user-agent string.

In the second scenario we could allow, alert or block the traffic to your web server at home based upon URL filtering. Since your server at your house would probably not be categorized by any URL filtering service it would probably match the "unknown" category.

-Benjamin

  • 2694 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!