Talk With an Expert

Is Anyone Out There? Monitoring DNS for Misuse

Is Anyone Out There? Monitoring DNS for Misuse (PDF, 2.03MB)Published: 30 Dec, 2016
Created by:
Kaleb Fornero

In the early 1980's, a system was born by which millions of users would unlock the untold amounts of computer information located around the world. The creation of the Domain Name System (DNS) not only allowed for the traversal of the Internet with userfriendly URLs, but also created a means of misuse, a means of deception. This paper will outline the way in which DNS may be abused for command and control channels as well as data exfiltration by deconstructing deceptive packets and outlining the anomalies within them. With this analytical information, the development of active network monitoring rules will be provided to detect these irregularities and identify DNS exploitation.