DNS Tunnelling
Definition
Encoding data inside DNS queries and responses to exfiltrate information or carry command-and-control traffic through a network that permits DNS but blocks other protocols. Indicators include unusually long domain names, high-entropy subdomains, and query volumes far above what name resolution alone would generate.
- Technique
- Encoding data inside DNS queries and responses
- Purpose
- Data exfiltration or covert command-and-control
- Common indicator
- Unusually long, high-entropy subdomains
- Second indicator
- Query volume far above normal name resolution
Common questions
Why do attackers choose DNS instead of a normal network channel?+
DNS traffic is almost always permitted outbound through firewalls because name resolution is essential to normal operation, so it is rarely blocked or closely inspected by default. That makes it an attractive channel for exfiltrating data or maintaining command-and-control from a network that otherwise restricts outbound connections.
How do investigators distinguish DNS tunnelling from legitimate high-volume DNS traffic?+
Legitimate DNS traffic from content delivery networks or software update checks tends to query a limited, predictable set of domains with normal-looking labels. Tunnelling traffic typically shows random-looking subdomains, unusually large query and response sizes, and a narrow set of destination domains queried repeatedly, which log analysis and entropy scoring can flag.
What DNS record types are commonly abused for tunnelling?+
TXT and NULL records are common because they can carry more arbitrary data than an A record, but CNAME and MX records have also been used. Any record type that returns attacker-controlled text back to the client can be repurposed to carry a covert response payload.
Related terms
- A Record
- A DNS resource record that maps a domain name to an IPv4 address. The primary attribution record in most investigations. An AAAA...
- Beaconing
- Periodic outbound connections from a compromised host to a command-and-control server, typically at regular intervals. The regularity of the interval, measured in...
- Covert Channel
- Any communication path that was not intended by the system designer and that bypasses access-control or monitoring policies. Network covert channels are...
- Domain Generation Algorithm (DGA)
- Code embedded in malware that produces a large set of pseudo-random domain names on a scheduled basis. The malware tries each until...
- Entropy Analysis
- A statistical technique that measures the randomness of data in a field or stream. Protocol fields that should contain low-entropy predictable values...
- Fast-Flux
- An evasion technique in which a domain's A records cycle through a large pool of IP addresses with very short TTL values....
- Network Flow (NetFlow/IPFIX)
- A summary record of a network conversation, storing source IP, destination IP, source port, destination port, protocol, byte count, and timestamps, without...
- Packet Capture (PCAP)
- The interception and recording of network packets as they traverse an interface. The raw data is stored in PCAP format and analysed...
- Passive DNS
- A historical database of DNS resolutions collected by sensors at recursive resolvers or network taps. Passive DNS shows which IP addresses a...
- Port Number
- A 16-bit integer in the TCP or UDP header that identifies the application-layer service at each endpoint. Well-known ports are assigned by...
- Protocol Anomaly Detection
- A detection method that compares observed network traffic against the formal specification of each protocol (its RFC or standard) and flags fields...
- Storage Channel
- A covert channel that encodes information in the value of a protocol field, such as the IP Identification field or a DNS...
Explained in these topics
- DNS and Domain InvestigationA technique that encodes data inside DNS query strings or TXT/CNAME response records to carry non-DNS traffic through firewalls that permit DNS. Used for data...
- Network Protocols and Traffic Interpretation
- Network Steganography and Covert ChannelsA technique that encodes arbitrary data inside DNS query and response labels, using an attacker-controlled authoritative server to relay the covert communicati...