Note: only capture and analyse traffic on networks you own or have permission to monitor.
In this article, I have delved into the depths of Wireshark scripting once again and discovered some unconventional techniques to unravel hidden threats and identify suspicious activities.
Revealing Covert Channels:
Covert channels are stealthy communication paths that bypass traditional security measures. To expose these hidden channels, you can leverage Wireshark scripting and Python’s flexibility.
The following toy script looks for one hard-coded string in HTTP payloads. It is only a demonstration of the idea:
import pyshark
#Open the captured packets file
cap = pyshark.FileCapture("packets.pcapng")
#Detect suspicious covert channels
for pkt in cap:
if "HTTP" in pkt:
payload = pkt.http.file_data
if payload and payload.startswith("CovertChannel"):
print(f"Covert Channel Detected: {payload}")
It only matches the literal text "CovertChannel", so it would never find a real covert channel. Real detection needs traffic baselines and statistical analysis. Treat this as a starting point for learning.
Uncovering DNS Tunneling:
DNS tunneling is a technique used to bypass network security by encapsulating data within DNS requests and responses. Let’s shed light on these covert channels.
The following toy script flags DNS queries containing the word "tunnel". It is a simple string match, not a real detector:
import pyshark
#Open the captured packets file
cap = pyshark.FileCapture("packets.pcapng")
#Detect potential DNS tunnels
for pkt in cap:
if "DNS" in pkt and hasattr(pkt.dns, "qry_name"):
if "tunnel" in str(pkt.dns.qry_name):
print("Potential DNS Tunnel Detected!")
By parsing DNS packets and inspecting the requested domain names (questions), you can pinpoint suspicious queries that may indicate the presence of a DNS tunnel. Real DNS tunnels do not announce themselves with the word "tunnel", so real detection looks at things like query length, entropy and volume. This script only illustrates where to start.
Utilising Statistical Anomaly Detection:
Intrusion detection can be enhanced by leveraging statistical anomaly detection techniques. Wireshark scripting, combined with Python’s statistical libraries, can help us identify deviations from normal network behavior.
Consider the following script that applies anomaly detection to packet sizes:
import pyshark
import numpy as np
from scipy.stats import zscore
#Open the captured packets file
cap = pyshark.FileCapture("packets.pcapng")
#Extract packet sizes
packet_sizes = [int(pkt.length) for pkt in cap]
#Detect anomalous packet sizes
z_scores = zscore(packet_sizes)
anomalies = np.where(z_scores > 3)[0]
if len(anomalies) > 0:
print("Anomalous Packet Sizes Detected!")
By calculating z-scores for packet sizes and comparing them to a threshold, it can identify packets that deviate significantly from the expected range. This script allows you to spot abnormal packet size patterns, potentially indicating network anomalies or malicious activities.
Port Scan Detector:
A port scanner detector is essential for network security as it helps identify unauthorised scanning activities. By detecting port scans, it enables administrators to pinpoint potential vulnerabilities in their systems and take appropriate measures to mitigate risks.
This proactive script aims to cover these bases:
import pyshark
#Open the captured packets file
cap = pyshark.FileCapture("packets.pcapng")
#Track the destination ports each source IP has contacted
scan_counter = {}
#Detect port scans
for pkt in cap:
if "TCP" in pkt and "IP" in pkt:
src_ip = pkt.ip.src
dst_ip = pkt.ip.dst
dst_port = pkt.tcp.dstport
scan_counter.setdefault((src_ip, dst_ip), set()).add(dst_port)
#Identify potential port scanning activities
for (src_ip, dst_ip), ports in scan_counter.items():
if len(ports) > 5: #Adjust the threshold as per your needs
print(f"Possible Port Scanning Detected: {src_ip} --> {dst_ip} ({len(ports)} different ports)")
The script examines each TCP packet and records which destination ports each source IP has tried on each target. A scan touches many different ports, so if one source contacts more ports than a predefined threshold, an alert is printed. Normal traffic usually touches only a few ports, though busy servers and slow scanners can still fool this simple check.
Exposing DNS Cache Poisoning Attacks:
Network’s DNS Infrastructure is obviously crucial, these attacks can lead to incorrect DNS responses. They can also lead to redirecting users to malicious websites, intercepting their communications or compromising their data.
The script below is a simple starting point. It only flags DNS requests of type ANY, which are sometimes used in reconnaissance and amplification attacks. It cannot detect cache poisoning itself, which needs analysis of DNS responses:
import pyshark
#Open the captured packets file
cap = pyshark.FileCapture("packets.pcapng")
#Track suspicious DNS requests
poisoning_attempts = []
#Detect DNS cache poisoning attacks
for pkt in cap:
if "DNS" in pkt and hasattr(pkt.dns, "qry_type"):
if str(pkt.dns.qry_type) == "255": #255 is the ANY query type
qname = str(pkt.dns.qry_name)
if qname not in poisoning_attempts:
poisoning_attempts.append(qname)
#Display the identified DNS cache poisoning attempts
if poisoning_attempts:
print("Detected DNS ANY queries:")
for attempt in poisoning_attempts:
print(attempt)
else:
print("No DNS ANY queries detected.")
By parsing the captured packets, the script identifies DNS packets and examines the questions section for requests of any type. If a request for an ANY type is found, the script extracts the domain name and checks if it is already in the list of detected poisoning attempts. If not, it adds the domain name to the list.
Finally, the script displays the identified DNS cache poisoning attempts, or a message indicating that no attempts were detected leaving the following result:
Detecting hidden communication within seemingly harmless network traffic allows us to expose vulnerabilities that otherwise could go unnoticed. I hope that you found some use from these scripts and remember that you will be required to extensively change them to get some use from your own network!

Top comments (0)