ALL PASS, NO FAIL!

CEH v13 Module 12: Evading IDS, Firewalls & Honeypots

This module covers techniques used to bypass network security controls. Attackers use evasion methods to avoid detection by IDS/IPS systems, firewall rules, and honeypots. Understanding these techniques is essential for both offensive security testing and defensive deployment.

The CEHStudy app carries 15 flashcards for Module 12 across 3 sections — pair each evasion technique with the control it defeats (signature matching, stateful inspection, rate thresholds, outbound-DNS rules); the exam grades the mapping, not the tool name.

Key Topics Covered

Important Terms & Concepts

IDS (Intrusion Detection System): Monitors network traffic for suspicious activity and generates alerts. Does not block traffic — purely detection.
IPS (Intrusion Prevention System): Like IDS but actively blocks or drops malicious traffic in real-time. Can cause false positives that disrupt legitimate traffic.
NIDS (Network IDS): Monitors all traffic across the entire network at strategic points. Placed at the perimeter or on VLANs.
HIDS (Host IDS): Monitors activity on a single host — file integrity, system logs, running processes, registry changes.
Signature-Based Detection: Matches traffic against a database of known attack patterns. Misses zero-day attacks but has low false-positive rate.
Anomaly-Based Detection: Establishes a baseline of normal traffic and alerts on deviations. Detects unknown attacks but has higher false-positive rate.
Fragmentation Attack: Sending packet fragments that reassemble into an attack payload outside the IPS inspection window. Defeats signature-based IDS/IPS.
Honeypot: A decoy system designed to attract attackers and study their behavior. Low-interaction (simulated services) vs high-interaction (real systems).

How to Study This Module

Frequently Asked Questions

What is the difference between IDS and IPS?
IDS only monitors and alerts on suspicious activity. IPS actively blocks or drops malicious traffic in real-time. Both are important but IPS can cause false positives.

How do you evade a firewall during scanning?
Techniques include IP fragmentation, using DNS tunneling (port 53), encrypting traffic, slow scanning rates, decoy scanning (using multiple source IPs), and splitting payloads across fragments.

Related Modules

What is IDS and Firewall Evasion in Ethical Hacking?

Evading Intrusion Detection Systems (IDS), Intrusion Prevention Systems (IPS), firewalls and honeypots is a core domain of the Certified Ethical Hacker v13 (CEH v13) exam administered by EC-Council. It covers the evasion techniques penetration testers and attackers use to operate without triggering alerts or being blocked — knowledge defenders need to tune their controls for detection. Module 12 accounts for approximately 10% of CEH v13 exam questions.

Key Concepts in Evading IDS, Firewalls & Honeypots

Common Exam Mistakes in Module 12

Swapping IDS and IPS in the stem: an IDS is passive and out-of-band — it monitors traffic or a single host (NIDS/HIDS) and raises alerts. An IPS sits inline and actively blocks: drops packets, resets connections, bans sources. Asking which device stops the traffic → IPS; asking who reports it → IDS.
Assuming fragmentation always defeats inspection: splitting a payload so no single fragment matches a signature only works when the sensor inspects before reassembly — the target OS then reassembles and executes the full payload. Nmap -f performs minimum fragmentation for exactly this test, and the countermeasure is reassemble-then-inspect at the sensor.
Reading honeypot tells as production quirks: low-fidelity honeypots (the honeyd class) leak incomplete service implementations, simplified response signatures, timing oddities, and the same MAC address behind multiple IP addresses. Exams ask which observation exposes a decoy — duplicate MAC across hosts is the classic tell, not unusual traffic volume.

Tools for IDS/IPS Evasion

Evasion and detection tools the CEH exam references for this domain, by job:

Worked Example: One Beacon, Three Evasion Layers

An outbound beacon to a known command-and-control address is blocked at the perimeter. The attacker re-wraps it in DNS queries (iodine) — port 53 is allowed out, so the tunnel flows. Query timing is spread to stay below rate thresholds; when signature alerts fire on the tunnel pattern, the payload is fragmented across packets so no single fragment matches a rule.

The twist: the sensor log is full yet traffic still gets through — that device is an IDS: passive and out-of-band, reporting but not blocking. Move an IPS inline and it can drop packets and reset connections; when the attacker encrypts the payload to hide signatures, the defender's counter is TLS decryption at the inspection point plus anomaly detection. One attack, three different controls — that mapping is what the module tests.

How to Study IDS Evasion for the CEH v13 Exam

To study Module 12:

  1. Create a matrix: Evasion Technique | Defeats Which Control | Why It Works | Modern Countermeasure — the exam matches techniques to the specific control they bypass and asks for the mechanism (e.g., fragmentation defeats signature-based IDS because the pattern spans a fragment boundary the IDS doesn't reassemble)
  2. Memorize NIDS vs HIDS visibility: NIDS = network packets (bypassable with encryption/tunneling); HIDS = host processes and files (requires root to blind) — the exam asks which layer a technique defeats
  3. Hands-on: in a VirtualBox lab, set a Suricata IDS on a span port between attacker and target VMs. Run Nmap with increasing evasion options (`-f`, `--data-length 200`, `-D RND:5`) and note in Suricata logs which scans alert and which pass silently. Document the exact flag that defeats detection
  4. Review related modules: Module 3 (Scanning Networks) for the scan techniques needing evasion, and Module 10 (DoS Attacks) for shaping DoS traffic under rate-based detection

Frequently Asked Questions About IDS and Firewall Evasion

What is the difference between evading an IDS and evading a firewall on the CEH exam?

Evading an IDS means passing through without triggering alerts while maintaining connectivity: fragmentation (defeating signature matching), rate normalization (staying below anomaly thresholds), encryption (hiding content from NIDS), protocol tunneling (using allowed protocols). Evading a firewall means establishing a connection that access-control rules would normally block: IP spoofing (appearing as an allowed source), DNS/ICMP tunneling (allowed ports, different purposes), slow scanning (below rate limits), exploiting misconfigured rules. Key distinction: IDS evasion = avoid detection (not being seen); firewall evasion = gain access (passing through a control that would normally stop you). Similar techniques, different objectives.

Why is anomaly-based IDS harder to evade than signature-based IDS?

Signature-based IDS matches traffic against known patterns — evasion is straightforward by altering the payload (fragmentation, encoding, slight modification). Anomaly-based IDS builds a statistical baseline of normal behavior (protocol mix, packet-size distributions, connection rates, timing, geographic patterns) and alerts on deviation. Evading it means making malicious traffic statistically indistinguishable from normal: typical packet sizes, common protocols at normal rates, expected hours, legitimate session patterns — no specific signature to avoid, you must blend in completely. Anomaly-based IDS catches zero-day and novel attacks that signature systems miss, but produces more false positives. Well-maintained operations run both for complementary coverage.

Related CEH v13 Modules