Protocols

Before the platforms, the telemetry protocols themselves are attackable. SNMP is the richest: a widely deployed, frequently weakly-authenticated protocol that reveals a device's entire state and, with write access, reconfigures it. Syslog is a trusting, usually unauthenticated ingestion path that an attacker spoofs, forges, and floods to poison the record operators and SIEMs rely on. And NetFlow/IPFIX collectors hold the map of who talks to whom across the network, valuable reconnaissance and a target for forged records. These are protocol-level attacks, independent of which platform consumes them.

Subtopics#

  • SNMP: device data disclosure, weak community strings, and write-access abuse.
  • Syslog: spoofing, injection, and flooding of the log stream.
  • NetFlow and IPFIX: harvesting and forging network flow telemetry.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more