Flow-export protocols, Cisco NetFlow, sFlow, and the IETF-standard IPFIX, have routers and switches summarize the conversations passing through them (source, destination, ports, protocol, byte and packet counts) and export those records to a collector over UDP. For an attacker the flow data is a ready-made map of the network's communication: who talks to whom, on which services, and how much, which is high-value reconnaissance obtained without touching the hosts. Harvesting that map from an exposed collector or its storage reveals the environment's structure and relationships. And because the export path is unauthenticated UDP, an attacker who can send to the collector forges flow records to inject false traffic, hide real flows, or mislead the capacity and security monitoring built on the data.
Subtopics#
- Collector data harvesting: reading the traffic map from a collector.
- Flow record spoofing: forging exported flow records.