Malware Increasingly Uses DNS As Command and Control Channel to Avoid Detection

Status
Not open for further replies.

Ink

Administrator
Thread author
Verified
Jan 8, 2011
22,490
Malware Increasingly Uses DNS As Command and Control Channel to Avoid Detection, Experts Say

Most malware-generated traffic that passes through these channels can be detected and blocked at the network level by firewalls or intrusion prevention systems.

However, that's not the case for DNS (Domain Name System) and attackers are taking advantage of that, said Ed Skoudis, founder of Counter Hack Challenges and SANS fellow, during a presentation on new attack techniques at the conference.

The DNS protocol is normally used for a precise critical function -- the translation of host names into IP addresses and vice-versa. Because of this, DNS traffic doesn't get filtered or inspected by traffic monitoring solutions and is allowed to flow freely through most networks.

As DNS queries gets passed from one DNS server to another until they reach the authoritative servers for the respective domains, network-level IP blocklists are useless at blocking them.
Skoudis has seen malware that receives instructions via DNS responses being involved in two recent large-scale breaches that resulted in the compromise of millions of accounts. He expects more attackers to adopt this stealthy technique in the following months.

Read more
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top