ノースカロライナ州ローリーにあるTriangle FinTechで行われた侵入テスト中、倫理ハッカーのイーサンは同社の境界ファイアウォールの回避を試みた。彼は明らかに悪意のあるペイロードを送信する代わりに、トラフィックをポート80の標準的なWebリクエスト内にカプセル化し、通常のブラウジングアクティビティに紛れ込ませた。この手法により、彼のパケットは、詳細なアプリケーション検査を実施していない境界防御をすり抜けることができた。
イーサンが使用しているファイアウォール回避テクニックはどれでしょうか?
正解:A
The described technique is HTTP tunneling because Ethan is encapsulating his traffic inside standard web requests on port 80 to blend with normal browsing activity and bypass perimeter defenses that only perform basic port/protocol filtering. HTTP tunneling leverages the fact that many organizations allow outbound (and sometimes inbound) HTTP/HTTPS traffic through firewalls for business needs. If a firewall is not doing deep inspection (such as application-layer proxying, WAF inspection, or strict egress controls), encapsulated traffic can traverse allowed ports while carrying non-HTTP payloads inside the HTTP structure.
The scenario's core clues are: (1) "encapsulates his traffic inside standard web requests," (2) uses port 80, and (3) success depends on the firewall "not performing deep application inspection." These are exactly the conditions where HTTP tunneling is effective: the traffic appears as ordinary HTTP sessions, so the firewall treats it as permitted web traffic even though the content is being used as a carrier for another protocol or command channel.
Why the other options don't fit:
DNS tunneling (D) also encapsulates traffic, but it uses DNS queries/responses (typically UDP/TCP 53), not HTTP requests on port 80.
Tiny fragments (C) is an evasion method that breaks packets into very small fragments to confuse filtering
/IDS reassembly; the scenario is about encapsulation in web requests, not fragmentation.
Source routing (B) attempts to influence packet path using IP options; it is not described here and is commonly blocked/ignored in modern networks.
Therefore, the firewall evasion technique is A. HTTP Tunneling.