skip to content

How does an intruder already resident in a plant network end up holding a permanent permit in a flow-derived segment policy?

level: middleimportance: must knowfreq 46%

answer

  1. learned from a window that already contained them
  2. consistency is what the compiler rewards
  3. only denials generate tickets
  4. aggregation widens a session into a class
  5. the permit becomes documented and inherited

basics

~20 s

Their sessions run during the observation window, so the compiler writes them into the allow-list as ordinary flows. On enforcement day only missed legitimate flows break and get attention; the intruder's path breaks nothing, so nobody looks.

solid answer

~50 s

The recursion is the whole problem: you learn policy from a window that already contains the adversary. A jump host reaching the historian, and the historian reaching controllers, are just flows - steady, low volume, plausible ports - so they survive into the permit set. Then the feedback loop inverts. Enforcement day surfaces exactly the flows that were *not* learned: a quarter-end transfer, a vendor callback, a backup outside the window. Those break, someone shouts, an engineer fixes them. The intruder's path breaks nothing and receives no scrutiny. Worse, the permit is now written down, reviewed by nobody and inherited by the next engineer, who will not delete a line whose purpose is unknown. And because derived rules get widened for tidiness - a subnet instead of a host, a range instead of a port - the permit can grant re-entry paths that were never observed at all.

go deeper

for a junior

Recall the core trap in one sentence: policy learned from observed traffic permits whatever was running, including an intruder who was already inside.

for a middle

Explain the compiling and widening steps concretely, and why frequency-based ranking favours a resident adversary over a rare legitimate flow.

for a senior

Bring the operational loop: enforcement day only surfaces denials, so permitted intruder traffic gets no scrutiny, and the permit then hardens into an inherited rule nobody will delete.

for a principal

Own the assumption explicitly - either buy an assurance activity before the baseline is frozen, or state in writing that the policy inherits whatever was resident.

## The mechanism, step by step **1. The window contains the adversary.** Segmentation projects begin where the network is flat, and flat networks are where intruders survive longest. The probability that a multi-week baseline of an unsegmented plant estate contains no unauthorised session is not a probability anyone should assume away. **2. Their traffic is unremarkable in the export.** A flow record has no field that could betray them. A session from a remote-access jump host into the historian looks like an integrator doing support - because that is what it is imitating and often what the same path is used for. Onward traffic from the historian to controllers looks like the historian doing its job. Volume is modest, timing is regular, ports are plausible. Every heuristic a compiler could apply - frequency, byte count, persistence across days - *favours* the resident intruder over the rare legitimate flow. **3. The compiler treats frequency as evidence.** Most derivation pipelines rank by how consistently a flow appeared, and drop long-tail one-offs as noise. That is precisely backwards for this failure: an established foothold is consistent, and a genuine quarterly batch job is a one-off. **4. Widening amplifies it.** Nobody enforces a policy with 40,000 host-pair rules. They aggregate: a `/24` instead of a host, a port range instead of a port, "any ephemeral source port", sometimes bidirectional where only one direction was seen. Each generalisation permits traffic that was never observed. The intruder's single observed session can become a permitted class of sessions - which means eviction from that one host does not close the path, because the permit covers the neighbours too. ## Why nobody ever notices This is the part interviewers want, because it is about the operational loop rather than the technology. | On enforcement day | What happens | | --- | --- | | A legitimate flow that ran outside the window | Breaks, someone is paged, it is investigated and a permit is added | | A legitimate flow inside the window | Keeps working, nobody looks | | The intruder's session inside the window | Keeps working, nobody looks | All of your investigative attention is spent on denials. The permits attract none, and the adversary sits in the permitted set with everything else that works. The segment is then reported as a success, correctly, on the evidence anyone is looking at. ## The permit hardens After the project closes, the derived line has a second life. It is now *documented policy*, produced by a sanctioned exercise, with a change record behind it. The next engineer who reviews the rule base finds a permit between two plant hosts and no explanation. They will not delete it: the downside of deleting a real dependency in a plant is a stopped line and an angry production owner, while the downside of keeping an unexplained permit is invisible. So the line stays, and it stays for years. The learning step did not just permit the intruder - it laundered the permission into something defensible. ## What actually breaks the recursion You cannot fix this from inside the observation, because observation has no concept of legitimacy. The counters are all outside it: - **Establish cleanliness before you freeze the list.** If nobody has looked for a resident adversary, the baseline inherits whatever is there. A deliberate check of the estate before the window is treated as evidence is the only thing that changes the assumption - and if you cannot afford it, say the assumption out loud instead of pretending it away. - **Attribute the flows that cross the boundaries you care about.** You will not attribute 3,000 permits, but you can attribute the ones entering the control zone and the ones traversing remote-access paths, which is where this failure lands. - **Refuse the tidy widening on the flows that matter.** Aggregation is a capacity and readability decision; take it on intra-zone chatter, not on the paths into controllers. - **Watch permits, not only denials.** The derived set is a hypothesis about normal. If nothing ever reviews the traffic that is *permitted*, the only feedback the policy ever receives is from the flows it broke. ## The honest summary A flow-derived allow-list encodes the state of the network at the moment you looked, including the parts of that state you did not want. It converts an intruder's tolerated access into an authored, documented, inherited permission, and it does so silently, because the failure mode produces no outage and no alert.

  • Why does ranking derived flows by frequency make this worse rather than better?
    Because frequency rewards persistence, and an established foothold is persistent while genuinely rare legitimate flows are not. A pipeline that keeps consistent flows and drops long-tail ones preferentially keeps the intruder's session and discards the quarterly batch job - so the rules you kept are the ones you should have questioned, and the ones you dropped are the ones that will break production.
  • You evict the intruder from the compromised host after the policy is live. Is the path closed?
    Not necessarily. If the derived rule was widened - a subnet instead of a host, a port range instead of a single port, both directions instead of one - the permit still covers equivalent paths from neighbouring hosts. Eviction removes the occupant; the permit is what has to be narrowed or removed, and that needs an owner willing to say what the line is for.

It is like writing the guest list by photographing everyone who was already at the party. Anyone who gate-crashed early is now on the list, and the only people turned away next time are the ones who arrived late.

saying these in an interview costs you the question

  • Assumes the baseline period was clean
  • Thinks anomaly scoring on the same window would catch it
  • Treats consistent, long-running traffic as inherently legitimate
  • Aggregates rules to subnets and calls it equivalent
  • Reviews only what the policy denied, never what it permitted

context