Analytics // Security Monitoring
5/3/2013
08:56 PM
Connect Directly
RSS
E-Mail
50%
50%

Got Malware? Three Signs Revealed In DNS Traffic

Monitoring your network's requests for domain lookups can reveal network problems and potential malware infections

Companies focus much of their energy on hardening computer systems against threats and stopping attempts to breach their systems' security -- and rightfully so. However, companies should always assume that the attackers have already successfully compromised systems and look for the telltale signs of such a breach.

Because malware is increasingly using a variety of domain techniques to foil takedown efforts and make their command-and-control servers harder to locate, DNS traffic becomes a good indicator of compromise, say security experts. Monitoring the network for strange DNS behavior can help pinpoint infections, says Patrick Foxhoven, chief technology officer of emerging technologies for cloud security firm Zscaler.

"DNS is the way that most modern malware is connecting back to their operators' command-and-control infrastructure," he says. "DNS allows them to create or register a domain or a random set of domains and continue changing which IP those domains resolve to. Having visibility at the DNS level is huge."

Domain-name service traffic is so ubiquitous that many companies do not think about analyzing domain lookups and responses to find network problems and malware infection. Moreover, collecting the data and analyzing it presents challenges and can slow down the infrastructure, says Stephen Newman, vice president of products for network-security firm Damballa.

"There are some challenges there, some rather difficult challenges," Newman says. "Unfortunately, these DNS systems that are out there really don't support logging very well. It is very difficult for enterprises to extract out and store the DNS activity that has occurred."

[Trade-offs are a fact of life for network defenders, but attackers have to abide them as well. Understanding attackers' problems can help companies better use them to their advantage. See The Attacker's Trade-Off: Stealth Versus Resilience.]

Yet for companies that can collect and analyze the data, DNS can become an important component of their security-monitoring systems. From fast-flux domains to domain-generation algorithms, here are a few signs of malware as seen through DNS traffic.

1. Young domains
When employees' systems look up domains that are less than a week -- or a day -- old, companies should start investigating, Zscaler's Foxhoven says. Young domains are a solid sign that a machine has been infected with malware.

Companies can either monitor and investigate the traffic or just block the requests, Foxhoven says.

"Maybe the solution for your company is that you do not want to allow traffic to go to a site that is less than 24 hours old," he says. "There are a lot of domain names that are new, and they are hosting malicious content."

2. Esoteric domains
Not just age, but the uniqueness of a domain can be a tip that some unsavory activity is going on, Damballa's Newman says. If only a handful of employees appear to be going to a relatively unknown site, that could indicate that their machines have been compromised, he says.

"If you just have one or two domains that only a few devices are querying, that is a good thing to start looking at," he says.

As with young domains, esoteric domains can escape IP blacklists that might otherwise signal the company that the domain is hosting a malicious Web site.

3. Lookup failures
Finally, if a computer has a large number of failed domain lookups, that could also be a sign that something is wrong, Newman says. Domain-generation algorithms, which attempt to foil defenders by generating thousands of possible domain names every day in a digital shell game, have a recognizable traffic pattern, he says.

"If we see a device that tries 1,000 different domains and only one or two are valid, then we will focus on that device," Newman says.

By only registering one or two of the domains generated by the algorithm, the attacker uses the technique to keep defenders guessing.

While DNS can be an effective technique, both Damballa and Zscaler stress that it is only one part of the picture. Both companies treat DNS as only one of the indicators of malicious activity, not as a single sure sign of infection.

"If you have access to DNS, you can add a lot of security value," Foxhoven says. "Yet it's still only one part of the equation."

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message. Robert Lemos is a veteran technology journalist of more than 16 years and a former research engineer, writing articles that have appeared in Business Week, CIO Magazine, CNET News.com, Computing Japan, CSO Magazine, Dark Reading, eWEEK, InfoWorld, MIT's Technology Review, ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
TrevorHawthorn
50%
50%
TrevorHawthorn,
User Rank: Apprentice
5/6/2013 | 8:12:33 PM
re: Got Malware? Three Signs Revealed In DNS Traffic
I wrote a blog post on how to use Splunk to log and analyze suspicious DNS requests that may be of interest here: http://stratumsecurity.com/201...
dangleebits2
50%
50%
dangleebits2,
User Rank: Apprentice
5/4/2013 | 5:35:43 PM
re: Got Malware? Three Signs Revealed In DNS Traffic
There are at least 22 Indicators for DNS http://bigsnarf.wordpress.com/...
Register for Dark Reading Newsletters
Partner Perspectives
What's This?
In a digital world inundated with advanced security threats, Intel Security seeks to transform how we live and work to keep our information secure. Through hardware and software development, Intel Security delivers robust solutions that integrate security into every layer of every digital device. In combining the security expertise of McAfee with the innovation, performance, and trust of Intel, this vision becomes a reality.

As we rely on technology to enhance our everyday and business life, we must too consider the security of the intellectual property and confidential data that is housed on these devices. As we increase the number of devices we use, we increase the number of gateways and opportunity for security threats. Intel Security takes the “security connected” approach to ensure that every device is secure, and that all security solutions are seamlessly integrated.
Featured Writers
White Papers
Cartoon
Current Issue
Dark Reading's October Tech Digest
Fast data analysis can stymie attacks and strengthen enterprise security. Does your team have the data smarts?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3409
Published: 2014-10-25
The Ethernet Connectivity Fault Management (CFM) handling feature in Cisco IOS 12.2(33)SRE9a and earlier and IOS XE 3.13S and earlier allows remote attackers to cause a denial of service (device reload) via malformed CFM packets, aka Bug ID CSCuq93406.

CVE-2014-4620
Published: 2014-10-25
The EMC NetWorker Module for MEDITECH (aka NMMEDI) 3.0 build 87 through 90, when EMC RecoverPoint and Plink are used, stores cleartext RecoverPoint Appliance credentials in nsrmedisv.raw log files, which allows local users to obtain sensitive information by reading these files.

CVE-2014-4623
Published: 2014-10-25
EMC Avamar 6.0.x, 6.1.x, and 7.0.x in Avamar Data Store (ADS) GEN4(S) and Avamar Virtual Edition (AVE), when Password Hardening before 2.0.0.4 is enabled, uses UNIX DES crypt for password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force a...

CVE-2014-4624
Published: 2014-10-25
EMC Avamar Data Store (ADS) and Avamar Virtual Edition (AVE) 6.x and 7.0.x through 7.0.2-43 do not require authentication for Java API calls, which allows remote attackers to discover grid MCUser and GSAN passwords via a crafted call.

CVE-2014-6151
Published: 2014-10-25
CRLF injection vulnerability in IBM Tivoli Integrated Portal (TIP) 2.2.x allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Follow Dark Reading editors into the field as they talk with noted experts from the security world.