Fast-Flux
Definition
An evasion technique in which a domain's A records cycle through a large pool of IP addresses with very short TTL values. Double-flux additionally rotates the NS records. Both techniques make takedown significantly harder.
- Field
- DNS and domain investigation, cybercrime infrastructure
- Mechanism
- A records cycle rapidly through many IPs, short TTL
- Double-flux
- Also rotates the NS records
- Effect
- Makes takedown and IP-based blocking significantly harder
Common questions
Why does fast-flux defeat simple IP-blocking defences?+
Because the domain resolves to a new IP address every few minutes from a large rotating pool, often built from compromised hosts, blocking or blacklisting one IP has almost no effect since the malicious domain has already moved to another address by the time the block is applied.
What investigative approach works against fast-flux infrastructure instead?+
Investigators focus on the domain registration and the controlling infrastructure behind the rotation, such as the registrar, DNS provider, or command-and-control backend, and pursue takedown at that level, since chasing individual fast-changing IPs one at a time is not effective.
Related terms
- A Record
- A DNS resource record that maps a domain name to an IPv4 address. The primary attribution record in most investigations. An AAAA...
- DNS Tunnelling
- Encoding data inside DNS queries and responses to exfiltrate information or carry command-and-control traffic through a network that permits DNS but blocks...
- Domain Generation Algorithm (DGA)
- Code embedded in malware that produces a large set of pseudo-random domain names on a scheduled basis. The malware tries each until...
- Passive DNS
- A historical database of DNS resolutions collected by sensors at recursive resolvers or network taps. Passive DNS shows which IP addresses a...
- WHOIS
- A query protocol that returns registration data for a domain, including registrant name, organisation, email, nameservers, and registration and expiry dates. Since...