LoFP LoFP / the \"interesting_ports_lookup\" lookup considers communication to ports like 20, 21 for ftp, 23 for telnet, 110 for pop3, etc. as prohibited traffic. which may result in a lot of alerts in certain environments that still rely on these ports for legitimate traffic. tune as needed.

Techniques

Sample rules

Prohibited Network Traffic Allowed

Description

The following analytic detects instances where network traffic, identified by port and transport layer protocol as prohibited in the “lookup_interesting_ports” table, is allowed. It uses the Network_Traffic data model to cross-reference traffic data against predefined security policies. This activity is significant for a SOC as it highlights potential misconfigurations or policy violations that could lead to unauthorized access or data exfiltration. If confirmed malicious, this could allow attackers to bypass network defenses, leading to potential data breaches and compromising the organization’s security posture.

Detection logic


| tstats `security_content_summariesonly`
  count min(_time) as firstTime
        max(_time) as lastTime
        values(All_Traffic.src_port) as src_port
        values(All_Traffic.action) as action
        values(All_Traffic.rule) as rule

FROM datamodel=Network_Traffic WHERE

All_Traffic.action IN ("allowed", "allow")
[
    
| inputlookup interesting_ports_lookup where is_prohibited="true"
    
| table dest_port transport
    
| dedup dest_port transport
    
| rename dest_port as All_Traffic.dest_port
    
| rename transport as All_Traffic.transport
]

by All_Traffic.src_ip All_Traffic.dest_ip
   All_Traffic.dest_port All_Traffic.dvc
   All_Traffic.transport All_Traffic.vendor_product


| lookup update=true interesting_ports_lookup dest_port as All_Traffic.dest_port transport as All_Traffic.transport OUTPUT app is_prohibited note


| `security_content_ctime(firstTime)`

| `security_content_ctime(lastTime)`

| `drop_dm_object_name("All_Traffic")`

| `prohibited_network_traffic_allowed_filter`