Traffic Blocking
Definition
Adding firewall rules, null routes, or DNS sinkholes to deny communication between attacker-controlled infrastructure and the victim network. Effective against external command-and-control channels but not against attackers already operating from inside the network.
- Methods
- Firewall rules, null routes, DNS sinkholes
- Purpose
- Deny communication between attacker infrastructure and victim network
- Effective against
- External command-and-control channels
- Limitation
- Ineffective against attackers already operating internally
Common questions
Why does traffic blocking fail against an attacker already inside the network?+
Blocking targets communication to outside infrastructure, but an attacker who has already gained internal footholds or moved laterally does not need to reach outside the network to keep operating.
What is a DNS sinkhole used for in this context?+
It redirects queries for known malicious domains to a controlled server, which both blocks the connection and reveals which internal hosts are still trying to reach the attacker.
Related terms
- Attacker-Alerting Risk
- The risk that a containment action signals to the attacker that they have been detected, potentially triggering destructive countermeasures on systems they...
- Network Isolation
- Disconnecting a compromised host from all network interfaces while leaving it powered on. Preserves volatile memory contents but removes the attacker's communication...
- Short-Term Containment
- Immediate actions taken after incident confirmation to stop an attack from spreading, without waiting for full scope analysis. Distinguished from long-term containment,...
- VLAN Segmentation
- Moving a compromised device or subnet into a separate VLAN with restrictive access control lists, limiting lateral movement to other network segments...
- Volatile Evidence
- Data that exists only while a system is running: active processes, logged-in sessions, network socket state, decryption keys in memory, and command...