# 5 network traffic patterns that signal a security problem Attackers rotate tools, domains, and malware daily, and signature databases chase them from behind. Traffic patterns behave differently. The five patterns on this page follow from what an intrusion has to do to succeed, which is why they persist across malware families and years, and why they are detectable in the flow data your network devices already export. ## In this guide: - Five traffic patterns that reveal intrusions: beaconing, lateral movement, volume asymmetry, tunneling, and new destinations. - What each looks like in flow data, how to confirm it, and where to set your first thresholds. - Why baselining is the prerequisite for all five. ## 1. Beaconing In flow data, beaconing appears as small, similarly sized outbound connections from one internal host to one external destination at regular intervals. Every few seconds or minutes, a short conversation. Hour after hour. **Why it happens:** Implanted malware has to ask its operator for instructions. That check-in loop, the command-and-control heartbeat, is a structural requirement of remote control. MITRE ATT&CK catalogs the techniques involved under the Command and Control tactic. **How to confirm:** Pull the flow history for the suspect host and destination pair. Legitimate periodic traffic (NTP, update checks, monitoring agents) resolves to known infrastructure. Beaconing resolves to recently registered domains, bare IP addresses, or hosting with no business relationship to your organization. Interval regularity with small random offsets, called jitter, is itself a signal; well-behaved software rarely randomizes its timing. **Starting thresholds:** Alert on any internal host maintaining a recurring outbound connection to a single external destination for more than a few hours where the destination sits outside your known-services list. Tune the known-services list first, then tighten the duration. ## 2. Internal scanning and lateral movement Lateral movement appears as one internal host initiating connections to many internal addresses, or walking through ports across a subnet, in a short window. SMB on TCP 445 and RDP on TCP 3389 dominate, because those services move an attacker between machines in Windows environments. **Why it happens:** Intrusions rarely begin on the machine the attacker wants. Reaching domain controllers, file servers, and backups requires internal reconnaissance and hops. ATT&CK tracks this as Lateral Movement, with SMB and admin share abuse cataloged as technique T1021.002. **How to confirm:** Fan-out ratio is the telling metric. A workstation that normally talks to a dozen internal hosts suddenly connecting to two hundred is performing no task its user launched. Check whether connections walk sequential IP ranges, and whether authentication services spike alongside. **Starting thresholds:** Alert when an internal host contacts more than a defined number of distinct internal addresses within a few minutes, with separate, tighter thresholds for 445 and 3389. Exempt legitimate scanners (vulnerability management, patch systems) by IP group rather than loosening the rule. ## 3. Data volume asymmetry Exfiltration appears as outbound transfer volumes that dwarf a host's baseline, directed at destinations the host has never used, often outside working hours. Most user machines download far more than they upload. A workstation pushing tens of gigabytes outbound has inverted its natural ratio. **Why it happens:** Stolen data has to leave, whether toward attacker infrastructure or an abused cloud storage service. ATT&CK covers these behaviors under Exfiltration (TA0010). **How to confirm:** Compare the host's outbound volume against its own trailing baseline rather than a network-wide average. Identify the destination's owner through WHOIS and ASN lookup. Check timing: transfers at 2am from a workstation whose user works 9 to 5 deserve an explanation. **Starting thresholds:** Alert on outbound transfers exceeding a multiple of the host's own daily baseline, and on any first-time large transfer to a destination absent from the host's history. Servers with legitimate bulk upload duties (backup, replication) belong in their own IP groups with their own baselines. ## 4. Protocol and port mismatch In flow data, tunneling appears as protocols carrying volumes they were never meant to carry: DNS traffic measured in hundreds of megabytes, ICMP streams running for hours, or high-volume flows on ports matching no service you run. **Why it happens:** DNS and ICMP usually pass through security controls with little scrutiny, which makes them attractive covert channels. ATT&CK catalogs the pattern as Protocol Tunneling (T1572). **How to confirm:** DNS is the clearest case. A typical query and response together occupy a few hundred bytes, so hosts generating megabytes of DNS traffic per hour, or long query streams toward one external domain, are moving something other than name lookups. For odd ports, identify the destination and check whether any sanctioned application explains the flow. **Starting thresholds:** Alert on per-host DNS volume beyond a generous multiple of your observed norm, on ICMP flows exceeding trivial size, and on sustained high-volume flows to ports outside your documented service catalog. ## 5. Newly observed and low-reputation destinations In flow data, this pattern appears as connections to destinations your network has never contacted: fresh ASNs, unfamiliar geographies, and domains with the random character sequences typical of domain generation algorithms. **Why it happens:** Attacker infrastructure churns constantly as domains get flagged and taken down, and malware families use domain generation algorithms to produce disposable rendezvous points. The churn becomes the signal: your organization's set of legitimate destinations is far more stable than an attacker's infrastructure. **How to confirm:** Check domain registration age; attacker domains are frequently days old at first contact. Map the destination against your geographic and vendor footprint. Correlate with the other four patterns, since new-destination contact combined with beaconing or volume asymmetry raises confidence sharply. **Starting thresholds:** Maintain a first-seen destination log and alert when a first-seen destination coincides with any other pattern on this page. Alone, first contact is weak evidence; combined, it is strong. ## Baselining: The prerequisite for all five Every pattern above is defined as a deviation, which means detection quality is a function of baseline quality. Two to four weeks of flow history produces workable per-host and per-group baselines in most environments. Build IP groups that separate populations with different normals (workstations, servers, scanners, backup infrastructure) so each is measured against its own behavior, and revisit the groups on a schedule as the network changes. ## Detecting these patterns with ManageEngine NetFlow Analyzer ManageEngine NetFlow Analyzer collects flow data from your existing routers, switches, and firewalls and turns these five patterns into alerts. ### Feature highlights - **Baselines from history:** Per-interface and per-group traffic profiles built from retained flow data. - **Threshold and behavior alerting:** Volume, fan-out, and anomaly conditions with severity mapping. - **Context-rich alarms:** Each alarm links to the underlying conversations for one-click confirmation. - **Months of searchable history:** Investigations reach back as far as your retention policy. ## FAQs on suspicious traffic patterns ### What does beaconing look like in NetFlow data? Repeated small flows from one internal host to one external destination at near-regular intervals, sustained over hours, with consistent byte counts and timing too regular for human-driven traffic. Destination checks (registration age, ASN ownership) separate malware check-ins from legitimate telemetry. ### Can flow data detect insider threats? It detects insider actions that move data: volume spikes against personal baselines, transfers to unsanctioned cloud storage, activity outside working hours, and contact with destinations unrelated to the person's role. Intent requires investigation, but the movement of data is measurable. ### How long should I retain flow records for investigations? Incident response reporting consistently finds intrusions that dwell for weeks before discovery, so retention shorter than 90 days risks losing the start of the story. Many teams keep 6 to 12 months, which stays affordable because flow records are compact. ### What ports does lateral movement typically use? SMB on TCP 445 and RDP on TCP 3389 are the workhorses in Windows environments, with WinRM (5985, 5986) in scripted operations and authentication chatter on Kerberos (88) and LDAP (389) rising alongside. Watch for one host fanning out across many internal addresses on these ports. ### Do I need packet capture to detect these patterns? No. All five patterns are defined by connection behavior: timing, fan-out, volume, protocol proportions, and destination novelty. Every one of those dimensions lives in flow metadata. Packet capture adds payload evidence for later forensics and contributes little to initial detection. ## Author ![Monicaa](https://cdn.manageengine.com/itom/images/author/shynu.webp) **By Shynu M,** ManageEngine Team Lead product marketer for ManageEngine's FSO suite who enjoys turning the dense world of network traffic analysis into content practitioners actually use. Writes mostly about network monitoring and bandwidth management, and lately about where flow data fits in network detection and response.