This module covers techniques used to bypass network security controls. Attackers use evasion methods to avoid detection by IDS/IPS systems, firewall rules, and honeypots. Understanding these techniques is essential for both offensive security testing and defensive deployment.
The CEHStudy app carries 15 flashcards for Module 12 across 3 sections — pair each evasion technique with the control it defeats (signature matching, stateful inspection, rate thresholds, outbound-DNS rules); the exam grades the mapping, not the tool name.
Key Topics Covered
IDS vs IPS: detection vs prevention systems
Network-based (NIDS) vs host-based (HIDS) intrusion detection
Signature-based vs anomaly-based detection methods
Firewall evasion: fragmentation, tunneling, IP spoofing
Honeypot and honeynet types and detection
IPsec evasion techniques
Important Terms & Concepts
IDS (Intrusion Detection System): Monitors network traffic for suspicious activity and generates alerts. Does not block traffic — purely detection.
IPS (Intrusion Prevention System): Like IDS but actively blocks or drops malicious traffic in real-time. Can cause false positives that disrupt legitimate traffic.
NIDS (Network IDS): Monitors all traffic across the entire network at strategic points. Placed at the perimeter or on VLANs.
HIDS (Host IDS): Monitors activity on a single host — file integrity, system logs, running processes, registry changes.
Signature-Based Detection: Matches traffic against a database of known attack patterns. Misses zero-day attacks but has low false-positive rate.
Anomaly-Based Detection: Establishes a baseline of normal traffic and alerts on deviations. Detects unknown attacks but has higher false-positive rate.
Fragmentation Attack: Sending packet fragments that reassemble into an attack payload outside the IPS inspection window. Defeats signature-based IDS/IPS.
Honeypot: A decoy system designed to attract attackers and study their behavior. Low-interaction (simulated services) vs high-interaction (real systems).
How to Study This Module
Differentiate IDS from IPS — detection vs prevention
Know NIDS vs HIDS and signature-based vs anomaly-based detection
Memorize evasion techniques: fragmentation, tunneling, spoofing, IP address rotation
Understand honeypot types and how to detect them during penetration testing
Frequently Asked Questions
What is the difference between IDS and IPS? IDS only monitors and alerts on suspicious activity. IPS actively blocks or drops malicious traffic in real-time. Both are important but IPS can cause false positives.
How do you evade a firewall during scanning? Techniques include IP fragmentation, using DNS tunneling (port 53), encrypting traffic, slow scanning rates, decoy scanning (using multiple source IPs), and splitting payloads across fragments.
What is IDS and Firewall Evasion in Ethical Hacking?
Evading Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), firewalls and honeypots is a core domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. It covers the evasion techniques penetration testers and attackers use to operate without triggering alerts or being blocked — knowledge defenders need to tune their controls for detection. Module 12 accounts for approximately 10% of CEH v13 exam questions.
Key Concepts in Evading IDS, Firewalls & Honeypots
Signature-Based Evasion (Fragmentation & Encoding): Signature-based IDS/IPS match packet content against known attack patterns. The primary evasion is IP fragmentation: split a payload across fragments so the signature spans a fragment boundary and no single fragment matches — e.g., a SQL-injection signature looks for "UNION SELECT"; send "UNION" in fragment 1 and "SELECT" in fragment 2 and a shallow-parsing IDS sees neither. Encoding variations (URL encoding, hex, null-byte insertion) also defeat exact-string matching. Modern DPI-capable IDS reassemble fragments before matching, making simple fragmentation less effective — but it remains tested.
Protocol Tunneling & Allowlist Bypass: When a firewall only permits specific ports (DNS 53, HTTPS 443, ICMP), attackers tunnel through those channels: DNS tunneling encodes C2 data in query names (subdomain labels) and text records; ICMP tunneling carries data in ping payloads; SSH tunneling creates encrypted channels over port 22. The firewall sees only allowed-protocol traffic. Distinguish: fragmentation defeats signature matching at L3/L4; tunneling defeats port-based filtering by using an allowed port for different purposes. Both force the defender toward deep protocol inspection, not just port/protocol filtering.
Honeypot Detection & Response: A honeypot is a decoy that mimics a legitimate target to attract and study attackers. Low-interaction honeypots simulate services (fake banners, limited commands) and are detected by inconsistencies — too-perfect responses, no real OS artifacts, response-timing patterns. High-interaction honeypots run real operating systems with modified configurations. If you encounter one during a penetration test: (1) stop interacting to avoid legal liability, (2) document what was observed, (3) report to the client. Interacting without authorization may be unauthorized access even against a decoy — it is still a real system receiving your traffic.
NIDS vs HIDS Evasion Differences: NIDS monitors traffic at network points (span ports, TAPs) and only sees packets on the wire — evadable with encryption (SSL/TLS) or tunneling. HIDS monitors activity directly on the endpoint: file-system changes, process creation, registry modifications, log entries. HIDS is much harder to evade because the attacker must already be on the host to blind the agent. NIDS sees what's on the network (bypassable with encryption); HIDS sees what's happening on the system (hard to bypass without root/admin). Use both — what NIDS misses, HIDS may catch.
Common Exam Mistakes in Module 12
Swapping IDS and IPS in the stem: an IDS is passive and out-of-band — it monitors traffic or a single host (NIDS/HIDS) and raises alerts. An IPS sits inline and actively blocks: drops packets, resets connections, bans sources. Asking which device stops the traffic → IPS; asking who reports it → IDS.
Assuming fragmentation always defeats inspection: splitting a payload so no single fragment matches a signature only works when the sensor inspects before reassembly — the target OS then reassembles and executes the full payload. Nmap -f performs minimum fragmentation for exactly this test, and the countermeasure is reassemble-then-inspect at the sensor.
Reading honeypot tells as production quirks: low-fidelity honeypots (the honeyd class) leak incomplete service implementations, simplified response signatures, timing oddities, and the same MAC address behind multiple IP addresses. Exams ask which observation exposes a decoy — duplicate MAC across hosts is the classic tell, not unusual traffic volume.
Tools for IDS/IPS Evasion
Evasion and detection tools the CEH exam references for this domain, by job:
Nmap: the evasion workhorse — -f minimum fragmentation, --mtu custom fragment size, -D decoy scans (RND:N random sources included), --data-length random padding, and -S/-g to vary source IP and port
hping3: raw packet crafting with specific flag combinations to probe how an IPS responds to fragments, spoofed IPs, and unusual protocol mixes
Scapy: programmatic packet construction — junk-data injection, out-of-order packets, OS-fingerprint mimicry that canned scan flags cannot express
iodine / dnscat2: DNS tunneling tools that carry exfiltrated data, or a full TCP/IP tunnel, inside port-53 queries through firewalls that only permit outbound DNS
dns2tcp / dns2tcp-ng: encode traffic in DNS query names for exfiltration where DNS egress is the single allowed channel
honeyd: low-interaction honeypot emulator; knowing its tells (limited services, duplicate MACs) is the detection side of this module
Swiftenet: IDS/IPS evasion framework the exam lists for systematic sensor-bypass testing
Worked Example: One Beacon, Three Evasion Layers
An outbound beacon to a known command-and-control address is blocked at the perimeter. The attacker re-wraps it in DNS queries (iodine) — port 53 is allowed out, so the tunnel flows. Query timing is spread to stay below rate thresholds; when signature alerts fire on the tunnel pattern, the payload is fragmented across packets so no single fragment matches a rule.
The twist: the sensor log is full yet traffic still gets through — that device is an IDS: passive and out-of-band, reporting but not blocking. Move an IPS inline and it can drop packets and reset connections; when the attacker encrypts the payload to hide signatures, the defender's counter is TLS decryption at the inspection point plus anomaly detection. One attack, three different controls — that mapping is what the module tests.
How to Study IDS Evasion for the CEH v13 Exam
To study Module 12:
Create a matrix: Evasion Technique | Defeats Which Control | Why It Works | Modern Countermeasure — the exam matches techniques to the specific control they bypass and asks for the mechanism (e.g., fragmentation defeats signature-based IDS because the pattern spans a fragment boundary the IDS doesn't reassemble)
Memorize NIDS vs HIDS visibility: NIDS = network packets (bypassable with encryption/tunneling); HIDS = host processes and files (requires root to blind) — the exam asks which layer a technique defeats
Hands-on: in a VirtualBox lab, set a Suricata IDS on a span port between attacker and target VMs. Run Nmap with increasing evasion options (`-f`, `--data-length 200`, `-D RND:5`) and note in Suricata logs which scans alert and which pass silently. Document the exact flag that defeats detection
Frequently Asked Questions About IDS and Firewall Evasion
What is the difference between evading an IDS and evading a firewall on the CEH exam?
Evading an IDS means passing through without triggering alerts while maintaining connectivity: fragmentation (defeating signature matching), rate normalization (staying below anomaly thresholds), encryption (hiding content from NIDS), protocol tunneling (using allowed protocols). Evading a firewall means establishing a connection that access-control rules would normally block: IP spoofing (appearing as an allowed source), DNS/ICMP tunneling (allowed ports, different purposes), slow scanning (below rate limits), exploiting misconfigured rules. Key distinction: IDS evasion = avoid detection (not being seen); firewall evasion = gain access (passing through a control that would normally stop you). Similar techniques, different objectives.
Why is anomaly-based IDS harder to evade than signature-based IDS?
Signature-based IDS matches traffic against known patterns — evasion is straightforward by altering the payload (fragmentation, encoding, slight modification). Anomaly-based IDS builds a statistical baseline of normal behavior (protocol mix, packet-size distributions, connection rates, timing, geographic patterns) and alerts on deviation. Evading it means making malicious traffic statistically indistinguishable from normal: typical packet sizes, common protocols at normal rates, expected hours, legitimate session patterns — no specific signature to avoid, you must blend in completely. Anomaly-based IDS catches zero-day and novel attacks that signature systems miss, but produces more false positives. Well-maintained operations run both for complementary coverage.
Related CEH v13 Modules
Module 3: Scanning Networks — the scan types (SYN, connect, stealth, FIN, NULL) each carry different detection profiles that must be evaded before vulnerability assessment begins
Module 10: Denial-of-Service Attacks — volumetric attacks are distributed across many sources at below-threshold rates so each connection looks normal while the aggregate overwhelms the target