ICMP Traffic Monitoring
Suricata continuously monitors ICMP traffic within the controlled network.
Establish visibility into ICMP communication.
Organizations use Linux servers to host applications, internal services, databases, monitoring platforms, and infrastructure components. Network communication involving these servers is normally monitored to identify suspicious or unauthorized activity.
ICMP (Internet Control Message Protocol) is commonly used for diagnostic operations such as ping and network troubleshooting. However, attackers can abuse ICMP packets to create a covert communication channel and transfer data through ICMP traffic.
This technique is known as ICMP tunneling.
Because ICMP traffic may be permitted by network security controls, malicious ICMP communication can sometimes blend with legitimate diagnostic traffic.
In this use case, a real Ubuntu Linux server is deployed inside an isolated VirtualBox laboratory. Kali Linux is used as the authorized security-testing system.
A controlled ICMP tunneling scenario is safely reproduced using ptunnel-ng, an open-source tool specifically designed to tunnel TCP connections through ICMP echo request and reply packets.
Suricata is deployed as the primary network detection mechanism. It monitors ICMP traffic and generates security events when the controlled tunneling behavior matches the configured detection conditions. Suricata supports ICMP-specific inspection fields such as ICMP type, code, identifier, sequence, and payload characteristics.
Wazuh is used as the SOC monitoring and alert-management platform. Relevant Suricata security events are collected and correlated by Wazuh.
OpenSearch is used for centralized security investigation and visualization of the resulting alerts and network telemetry. Wazuh provides documented integration paths for forwarding security data to OpenSearch.
The complete SOC workflow is: Ubuntu Server → Controlled ICMP Tunneling → Suricata Network Monitoring → Suspicious ICMP Detection → Wazuh Alert → OpenSearch Investigation → Source Attribution → Automated Response → Containment Validation → Continuous Monitoring
Ubuntu Linux is the target server environment. The server represents a typical enterprise Linux endpoint that communicates with other systems using normal network protocols.
ICMP traffic is not normally intended to transport application data. However, an attacker may abuse ICMP packets to carry information between systems.
The security problem is therefore:
The controlled attack scenario demonstrates how ICMP can be abused as a covert communication channel. ptunnel-ng is used to generate controlled ICMP-based communication. The tool specifically supports tunneling TCP connections through ICMP echo request and reply packets.
The primary security concept is Network Behavior Monitoring.
The objective is to distinguish legitimate ICMP diagnostic activity from suspicious ICMP communication that may represent tunneling.
The secure processing flow is:
Suricata continuously monitors ICMP traffic within the controlled network.
Establish visibility into ICMP communication.
ICMP traffic is analyzed for abnormal frequency, packet size, and communication patterns.
Identify behavior that differs from normal diagnostic activity.
Relevant ICMP packet characteristics are inspected.
Identify suspicious ICMP packets carrying unexpected data.
Detection conditions are configured for repeated or high-volume ICMP communication.
Identify potential tunneling behavior while reducing isolated false positives.
The source and destination systems involved in suspicious ICMP activity are identified.
Determine the systems participating in the suspicious communication.
Wazuh generates a security alert when the configured ICMP tunneling detection condition is satisfied.
Provide centralized SOC visibility.
OpenSearch is used to investigate the generated security events.
Reconstruct the activity and determine whether the event represents suspicious tunneling.
Wazuh Active Response can execute a predefined containment action against the controlled source.
Stop continued suspicious ICMP communication.
Related ICMP events are correlated by source, destination, and timestamp.
Understand the complete sequence of suspicious activity.
The controlled ICMP tunneling activity is repeated after containment.
Confirm that the response prevents continued tunneling activity.
Suricata is the primary network detection tool.
Wazuh is used as the centralized SOC detection and response platform.
OpenSearch is used for centralized investigation.
ptunnel-ng is used to reproduce controlled ICMP tunneling behavior.
tcpdump is used as a lightweight packet-level validation tool.
Ubuntu provides the controlled Linux server environment.
Kali Linux provides the controlled attack-simulation environment.
VirtualBox provides the isolated laboratory infrastructure.