T1071
Application Layer Protocol
Adversaries may communicate using application layer protocols to avoid detection by blending in with existing traffic.
ATT&CK / Command and Control
APT groups commonly use HTTPS for C2 communications, making traffic analysis difficult as it blends with legitimate web traffic.
Defense strategies
- SSL/TLS inspection
- DNS monitoring
- Network segmentation
- Proxy authentication
Detection methods
- Analyze traffic patterns
- Monitor for beaconing behavior
- Track unusual protocol usage
- Detect domain fronting
D3FEND mappings
4