Dan Saad Cybersecurity Portfolio
Title: Decoding the Traffic: A Deep Dive into Log Analysis for Incident Response
Role: Cybersecurity Analyst (Coursework Simulation)
Tools Used: tcpdump, Network Traffic Analysis, ICMP/UDP Protocol Analysis
The objective of this project was to demonstrate my ability to perform systematic log analysis to diagnose and resolve complex network service disruptions. In a real-world cybersecurity environment, the ability to translate raw, high-volume packet data into a coherent narrative is essential for minimizing downtime and identifying potential security threats. This project showcases my methodology in isolating network-layer issues, interpreting protocol-specific errors, and providing actionable remediation steps for stakeholders.
During this investigation, I was tasked with diagnosing a service outage for the domain www.yummyrecipesforme.com. Customers reported a “destination port unreachable” error, which served as the primary lead for the investigation.
Using the provided tcpdump logs, I conducted a multi-step analysis to identify the root cause:
I began by filtering the raw traffic to identify the primary protocols involved. By analyzing the flow of data, I successfully isolated the communication channels between the clients and the DNS servers. This allowed me to move past the “noise” of general network traffic to focus on the specific failure point.
The analysis revealed a recurring failure involving Port 53. Recognizing this as the standard port for DNS (Domain Name System), I determined that the issue was not a general internet connectivity problem but a specific failure in DNS resolution. The logs confirmed that the system was attempting to resolve the requested domain, but the requests were consistently failing to reach the server.
The “smoking gun” in the analysis was the presence of ICMP (Internet Control Message Protocol) error messages. I analyzed the “Destination Port Unreachable” messages and correlated them with the DNS traffic on Port 53. This provided a clear narrative of the failure:
Based on the detailed analysis in the Cybersecurity Incident Report, I identified two primary possibilities for the incident:
To resolve the issue and prevent recurrence, I proposed the following immediate actions to the IT team:
This project reinforced my ability to bypass symptoms and identify the underlying technical bottleneck. By focusing on log analysis, I demonstrated how a systematic approach—moving from broad traffic filtering to specific protocol analysis—can lead to a faster and more accurate resolution than manual troubleshooting alone.
Cybersecurity Incident Report: Network Traffic Analysis
Part 1: Provide a summary of the problem found in the DNS and ICMP traffic log. The UDP protocol reveals that:
3 attempts made:
This is based on the results of the network analysis, which show that the ICMP echo reply returned the error message:
The most likely issue is: The server may be under attack (potentially a DDoS or DNS flood) or there may be an issue with the firewall or network configurations incorrectly blocking internet traffic to port 53.
Part 2: Explain your analysis of the data and provide at least one cause of the incident. Time incident occurred: Initial incidents (customers of clients unable to access websites) occurred earlier in the day. After being informed, security team began to troubleshoot the issue (1:24 PM).
Explain how the IT team became aware of the incident: The IT team received reports from customers of clients that the website “www.yummyrecipesforme.com” was unreachable and that they received the “destination port unreachable” error after waiting for the page to load.
Explain the actions taken by the IT department to investigate the incident: The first step taken by the IT department was to attempt to replicate the issue — the investigator started by attempting to access the website, then used the network analyzer tool tcpdump to investigate the issue once the behavior was confirmed. After attempting to access the webpage again, the investigator analyzed the tcpdump log.
Note key findings of the IT department’s investigation (i.e., details related to the port affected, DNS server, etc.):
Note a likely cause of the incident: The IT department suspects two likely causes:
In both cases, a key next step will be to check the firewall configuration — if the service is under attack, then a more strict configuration can mitigate the DDoS or DNS flood attack, whereas if the issue is in an erroneously strict configuration, allowing clients and their customers access to port 53 should resolve the issue.