Decoding the DNS: A New Arena in Cyber Defence

How_DNS_Works.jpg

How Domain Name System (DNS) Works

Any company with a large DNS Domain Name System infrastructure will find it difficult to understand what is happening in real time. This is down to the sheer volume of data involved – you could be looking for patterns in millions if not billions of requests to and around your network.However, new tools are emerging which capitalise on advanced big data techniques to analyse DNS data in depth, opening up the possibilities for using DNS data as an intelligence gathering mechanism in the war against cyber-crime.

Before now, the insights that can be found amongst the four billion DNS queries that the UK zone receives on a daily basis have largely been hidden because tools capable of analysing traffic across periods of more than a few minutes didn't exist. But with new DNS analytics and visualisation tools that have the capacity to store and analyse DNS queries data in-depth, we've begun to uncover techniques for identifying patterns of use that indicate malicious activity or cyber security vulnerabilities. Here are two:

Identifying botnets and spam

One example of cyber intelligence that can be gained from DNS analysis relates to botnets. Botnets continue to contribute to DDoS attacks and spam runs. Recent research from Kaspersky found that over 23,000 botnet-assisted DDoS attacks were reported in Q1 of this year alone. Spam email also continues to cause problems – despite recently dropping to a 12 year low spam still represents almost half of all emails sent.
DNS data can reveal previously hidden tell tale signs that computers on your network have become part of a botnet. A typical spam run centres on mass mailing to a list which almost inevitably will contain many invalid or expired domains. DNS analysis can reveal abnormally large numbers of requests for domains that do not exist, suggesting that machines on the network have been compromised.
By recognising specific infections early, it's possible to quickly clean up or at least isolate the infected machines and reduce the amount of spam crossing your network. The bigger your infrastructure, the more helpful such techniques are.

Limiting the spread of malware

The fight against malware is another area which can be assisted by DNS analysis. When it comes to Malware Index Case detection, DNS analysis has enabled the identification of a particularly aggressive piece of malware by tracking infected machines which were using something called a Domain Generation Algorithm (DGA), an algorithm that generates a number of random domains for botnets to communicate with.
DGA works by using an algorithm that generates a number of domains that changes periodically, and is often spread over many jurisdictions which means it is hard to predict. This allows the cyber-criminal to communicate with a large army of machines but reduces the risk of a white-hat adversary taking back control, as instead of having a single point of vulnerability, the cyber-criminal has many domains to hide behind.
DGAs are used by many pieces of malware, and tend to have two characteristics: They look like random strings and are in use for only a fixed period of time, commonly 24 hours. This means that a machine on your network that's trying to resolve a set of domains which don't look like humanly readable words i.e. iaurghriugharui.co.uk, may well be an infected machine.
If the set of domains changes on a daily basis, then this is even stronger evidence. By analysing DNS data, security professionals can find, predict and sinkhole the traffic of most DGAs by looking into a company's recursive DNS traffic.
 With cyber-criminals constantly finding new and intelligent ways in which to infiltrate a company's network, the ability to analyse DNS data opens up a whole new avenue of protection for organisations.
Decoding the DNS gives businesses another tool in their arsenal, one which was previously significantly more limited than it is now. If your organisation has a large DNS infrastructure but you haven't previously been able to extract meaningful intelligence from DNS data, now may be the time to consider reassessing your options.
SC Magazine: http://bit.ly/1ia9wO6

 

 

 

« A New Design for Cryptography’s Black Box
DEMOS: The Road to Representivity »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

ZenGRC

ZenGRC

ZenGRC - the first, easy-to-use, enterprise-grade information security solution for compliance and risk management - offers businesses efficient control tracking, testing, and enforcement.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

ON-DEMAND WEBINAR: What Is A Next-Generation Firewall (and why does it matter)?

Watch this webinar to hear security experts from Amazon Web Services (AWS) and SANS break down the myths and realities of what an NGFW is, how to use one, and what it can do for your security posture.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

ACME Communications

ACME Communications

ACME Communications specialises in the field of data centre, implementation, maintenance & operation and all aspects of other IT service.

TraceSecurity

TraceSecurity

TraceSecurity, a leading pioneer in cloud-based security solutions, provides IT governance, risk and compliance (GRC) management solutions.

Advenica

Advenica

Advenica develops, manufactures and sells innovative cybersecurity solutions for encryption and secure information exchange.

NetExtend

NetExtend

NetExtend services include backup and recovery, endpoint protection, network monitoring, cloud portal and billing and payment solutions.

Dragos

Dragos

Dragos has built the first industrial cybersecurity ecosystem, the ultimate security defense.

Trustlook

Trustlook

Trustlook's SECUREai engine delivers the performance and scalability needed to provide total threat protection against malware and other forms of attack.

Sabasai

Sabasai

Sabasai specialises in all aspects of insider threat management from training and education to building security frameworks and insider threat programs to on-site risk & vulnerability assessments.

Ekran System

Ekran System

Ekran System is an advanced insider threat detection solution for companies of any size.

Magtech Solutions

Magtech Solutions

Magtech Solutions is a one-stop IT Solutions provider offering Cloud Computing, IT Security, Unified Email Solutions and ERP systems.

Government CSIRT - Chile

Government CSIRT - Chile

Government CSIRT is the Computer Security Incident Response Team for State networks and government cyberspace in Chile.

Cybersecurity Professionals

Cybersecurity Professionals

Search vacancies from top cyber security jobs worldwide on CyberSecurity Professionals. View IT security jobs or upload your CV to be seen by recruiters from industry leading firms.

BlackCloak

BlackCloak

BlackCloak provides Concierge Cyber Security for high-net-worth individuals and corporate executives to protect them from cybercrime, reputational risks, hacking and identity theft.

National Coordinator for Security and Counterterrorism (NCTV) - Netherlands

National Coordinator for Security and Counterterrorism (NCTV) - Netherlands

The NCTV serves the Netherlands’ national security. We protect national interests, identify threats and strengthen resilience.

Zeta Sky

Zeta Sky

Zeta Sky offers a full range of IT and cyber-security services for your business.

InfoSecTrain

InfoSecTrain

InfoSecTrain are a leading training and consulting organization dedicated to providing top-tier IT security training and information security services to organizations and individuals across the globe

Cyber Explorers

Cyber Explorers

Cyber Explorers is a fun, free and interactive learning platform for future digital superstars. An exciting addition to UK curriculum delivery or after school activities.