4 ms·
Interesting. Wouldn't existing intrusion detection systems fire alerts on seeing random DNS queries from a host to `domain.tld`?
by xtacy 7y ago
Interesting. Wouldn't existing intrusion detection systems fire alerts on seeing random DNS queries from a host to `domain.tld`?
- spydum 7y agoThey should - high entropy dns names and frequent subdomains should be indicators to watch for. The bad news is they can be noisy and not get the attention they deserve (never saw a SOC that wasn't swimming in alerts).
- 3fe9a03ccd14ca5 7y agoI’ve never seen anyone try and setup alerts for random DNS queries. If you’re in the position to know what domains are good, then why not simply use a whitelist? Besides, even if you saw these queries you’d have no easy way of know I’d they were malicious or not.
- LIV2 7y agoSome IDS systems do it for you I was using Darktrace at my last job and it would tell us when servers started querying domains they don't usually query so there are products that do it
- 3fe9a03ccd14ca5 7y agoThose systems usually flag based on a known set of “bad” domains, which wouldn’t stop this attack (they could just register a few new domains before starting the attack).
- cortesoft 7y agoDepends on what a host is supposed to do. A mail server is going to make a lot of random DNS queries.