During a network traffic review, an analyst notices encrypted traffic to an unusual external IP address on TCP port 53. What is the most likely anomaly this indicates?
Attackers frequently use DNS tunneling to bypass firewalls by encapsulating non-DNS protocols and encrypted payloads inside DNS packets. Because TCP port 53 allows for larger, reliable data streams compared to UDP, persistent encrypted traffic on this port is a classic indicator of an active data exfiltration channel.
Why this answer
Port 53 is used for DNS, which typically uses UDP. Encrypted traffic on TCP/53 suggests DNS tunnelling, where data is exfiltrated inside DNS queries and responses.