Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic. Commands to the remote system, and often the results of those commands, will be embedded within the protocol traffic between the client and server. The DNS protocol serves an administrative function in computer networking and thus may be very common in environments. DNS traffic may also be allowed even before network authentication is completed. DNS packets contain many fields and headers in which data can be concealed. Often known as DNS tunneling, adversaries may abuse DNS to communicate with systems under their control within a victim network while also mimicking normal, expected traffic.(Citation: PAN DNS Tunneling)(Citation: Medium DnsTunneling) DNS beaconing may be used to send commands to remote systems via DNS queries. A DNS beacon is created by tunneling DNS traffic (i.e. [Protocol Tunneling](https://attack.mitre.org/techniques/T1572)). The commands may be embedded into different DNS records, for example, TXT or A records.(Citation: OilRig Uses Updated BONDUPDATER to Target Middle Eastern Government) DNS beacons may be difficult to detect because the beacons infrequently communicate with infected devices.(Citation: DNS Beacons) Infrequent communication conceals the malicious DNS traffic with normal DNS traffic.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by Filter Network Traffic
is blocked by Network Intrusion Prevention
is blocked by Behavioral Detection of DNS Tunneling and Application Layer Abuse
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Covert Channel Analysis
is blocked by Malicious Code Protection (Anti-Malware)
is blocked by Access Enforcement
is blocked by Boundary Protection
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
is blocked by Network Connection Termination
is blocked by Session Integrity
is blocked by Domain Name Service (DNS) Resolution
is blocked by Architecture & Provisioning for Name / Address Resolution Service
is blocked by Secure Name / Address Resolution Service (Recursive or Caching Resolver)
is blocked by Out-of-Band Channels
is blocked by Information Output Filtering
is blocked by Input Data Validation
Impressum German English