Name:Prohibited Network Traffic Allowed id:ce5a0962-849f-4720-a678-753fe6674479 version:15 date:None author:Rico Valdez, Splunk status:production type:Anomaly Description:The following analytic detects instances where network traffic, identified by port and transport layer protocol as prohibited in the "lookup_interesting_ports" table, is allowed.
It uses the Network_Traffic data model to cross-reference traffic data against predefined security policies.
This activity is significant for a SOC as it highlights potential misconfigurations or policy violations that could lead to unauthorized access or data exfiltration.
If confirmed malicious, this could allow attackers to bypass network defenses, leading to potential data breaches and compromising the organization's security posture. Data_source:
search:| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(All_Traffic.src_port) as src_port values(All_Traffic.action) as action values(All_Traffic.rule) as rule
FROM datamodel=Network_Traffic WHERE
All_Traffic.action IN ("allowed", "allow") [
| inputlookup interesting_ports_lookup where is_prohibited="true"
| table dest_port transport
| dedup dest_port transport
| rename dest_port as All_Traffic.dest_port
| rename transport as All_Traffic.transport ]
by All_Traffic.src_ip All_Traffic.dest_ip All_Traffic.dest_port All_Traffic.dvc All_Traffic.transport All_Traffic.vendor_product
| lookup update=true interesting_ports_lookup dest_port as All_Traffic.dest_port transport as All_Traffic.transport OUTPUT app is_prohibited note
how_to_implement:In order to properly run this search, Splunk needs to ingest data from firewalls or other network control devices that mediate the traffic allowed into an environment.
This is necessary so that the search can identify an 'action' taken on the traffic of interest.
The search also requires the Network_Traffic data model be populated. known_false_positives:The "interesting_ports_lookup" lookup considers communication to ports like 20, 21 for FTP, 23 for Telnet, 110 for POP3, etc. as prohibited traffic. Which may result in a lot of alerts in certain environments that still rely on these ports for legitimate traffic. Tune as needed. References: -https://securityscorecard.com/blog/ftp-security-risks/ -https://secoraconsulting.com/blog/telnet-security-risks/ drilldown_searches: name:'View the detection results for - "$src_ip$"' search:'%original_detection_search% | search src_ip = "$src_ip$"' earliest_offset:'$info_min_time$' latest_offset:'$info_max_time$' name:'View risk events for the last 7 days for - "$src_ip$"' search:'| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$src_ip$") | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' earliest_offset:'7d' latest_offset:'0' analytic_story:['Prohibited Traffic Allowed or Protocol Mismatch', 'Ransomware', 'Command And Control', 'Cisco Secure Firewall Threat Defense Analytics']