QuestionQ4

Intrusion Detection and Packet Analysis

An analyst will capture traffic from an air-gapped network that does not use DNS. The analyst needs to identify unencrypted Syslog data in transit. Which of the following is the most efficient for this purpose?

  • A tcpdump –s0 –i eth0 port 514
  • B tcpdump –nnvvX –i eth0 port 6514
  • C tcpdump –nX –i eth0 port 514
  • D tcpdump –vv –i eth0 port 6514
Explanation

UDP port 514 is the standard Syslog transport port, whereas port 6514 is designated for secure Syslog transports. The -n flag avoids DNS and service-name resolution, which is appropriate for an air-gapped network, and -X displays packet payload in hexadecimal and ASCII so plaintext Syslog messages can be inspected. RFC 5426: Transmission of Syslog Messages over UDP

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!