Skip to content

Protocol Anomaly Detection

Definition

A detection method that compares observed network traffic against the formal specification of each protocol (its RFC or standard) and flags fields that hold values outside the defined valid range or carry non-zero content where zero is mandated.

Basis
Formal protocol specification, e.g. an RFC
Flags
Field values outside defined valid range
Also flags
Non-zero content in mandated-zero fields
Category
Network intrusion and covert-channel detection

Common questions

How does protocol anomaly detection differ from signature-based intrusion detection?+

Signature detection matches traffic against known attack patterns and misses novel techniques, while protocol anomaly detection flags anything that violates the protocol's own rules regardless of whether that specific misuse has been seen before, which makes it effective against unknown covert-channel techniques.

Why is protocol anomaly detection often used to find network steganography?+

Covert channels frequently hide data in fields the protocol reserves or leaves unused, such as padding or a supposedly zeroed identification field, and those exact deviations from specification are what protocol anomaly detection is built to catch.

Related terms

Covert Channel
Any communication path that was not intended by the system designer and that bypasses access-control or monitoring policies. Network covert channels are...
DNS Tunnelling
Encoding data inside DNS queries and responses to exfiltrate information or carry command-and-control traffic through a network that permits DNS but blocks...
Entropy Analysis
A statistical technique that measures the randomness of data in a field or stream. Protocol fields that should contain low-entropy predictable values...
Storage Channel
A covert channel that encodes information in the value of a protocol field, such as the IP Identification field or a DNS...
Timing Channel
A covert channel that encodes information in the intervals between network events, such as inter-packet delays, rather than in packet content. Timing...

Explained in

Your journey to becoming a forensic professional starts here.

Practice with mock tests, learn from structured notes, and get your questions answered by a global forensic community, all in one place.