What is beaconing?¶
Beaconing is repeated outbound communication at regular or semi-regular intervals. Malware can use it to check in for tasks, but update, licensing, monitoring and cloud software also communicate periodically.
Measure the pattern properly¶
Preserve source device and process, destination, timestamps, protocol, DNS, request and response sizes and user-agent details. Calculate intervals across enough observations to distinguish a genuine pattern from a short coincidental sample.
Highly regular timing suggests automation, not necessarily malicious automation. Deliberate variation can make malicious check-ins irregular. Compare multiple devices: a shared schedule may reveal common legitimate deployment or common malicious configuration.
Link timing to purpose¶
Identify the executable and compare the destination and traffic with known software and organisational baselines. A pattern beginning after malware execution and followed by downloads or new processes carries different weight from a known updater.
The destination may be shared cloud infrastructure or a compromised host, so it does not identify an offender. Local process and resulting activity provide the more useful explanation.
Key takeaway
Use a sufficiently long timing pattern to identify possible beaconing, then establish the responsible process, purpose and effects before calling it malicious.