Passive DNS Analysis Using Bro-IDS

Abdulla Dakhgan, Ali Mohammed Hadi, Jaafer Al Saraireh, Doaa Alrababah · 2017

The DNS system provides rich and interesting data that can be analyzed in order to extract beneficial information that could be used for different security measures. However, DNS has been used widely by adversaries to achieve their malicious goals. Different types of attacks are carried out using the DNS traffic such as Fast flux, DNS cache poisoning and spoofing, and amplification of DNS for DDoS attack. This paper tries to answer the question: why should organizations consider monitoring their DNS traffic and how they can benefits from implementing a passive DNS system within the environment. This paper presents a case study of analyzed DNS traffic using Bro-IDS and Microsoft Excel to calculate statistics and extract passive DNS data. The analysis results shows extracted statistics focusing on hosts, ports, protocols, visited domains, and number of queries.

Read the paper · More papers on PaperTik