callback jitter

0001-01-01

callback jitter in a command and control context is a random value added to the callback interval with the intent of evading detection.

For example, a network security solution may attempt to detect callbacks by searching for patterns of connections at set intervals. If the software notices that a connection is being made exactly every 60 minutes to a host, this may be an implant calling back to its command and control server and an alert will be generated. Adding a jitter value of a random value within +/- 10 minutes may cause the implant to call back at 55 minutes and 49 seconds or 1 hour 4 minutes and 9 seconds, breaking up the time-based pattern.