Baleine sous graviers

forensics network FCSC 2023 solved on

star star

Description

The security team of a telecom operator faces a major problem. During the past few days, an alert in their IDS keeps getting raised by their behavioral analysis probe. The probe indicates that the traffic captured on some of the core network links is unusual.

Here is the operator’s core network topology:

topology

After several nights spent analyzing the traffic, our analysts did not find the cause of this alert.

You need to help them identify the cause of this unusual traffic from a set of pcap files containing the traffic captured on the interfaces of the core routers.

Note: The file r10_gi00.pcap is missing from the provided archive, but the resolution does not depend on this file.

Files

Author

Ludo

Flag

Share my success on Fediverse, Twitter, Linkedin, Facebook, or via email.

Submit your solution

You can submit your writeup for this challenge. Read the FAQ to learn how to proceed.

You need to be logged in to submit a writeup.

Writeups

There are no public solutions for this challenge yet, but you can submit yours after getting the flag.