{"id":488,"date":"2017-05-03T13:16:32","date_gmt":"2017-05-03T13:16:32","guid":{"rendered":"http:\/\/blog.siteuptime.com\/?p=488"},"modified":"2017-08-21T20:46:53","modified_gmt":"2017-08-21T20:46:53","slug":"dns-monitoring-how-to-check-your-traffic-for-threats","status":"publish","type":"post","link":"https:\/\/www.siteuptime.com\/blog\/2017\/05\/03\/dns-monitoring-how-to-check-your-traffic-for-threats\/","title":{"rendered":"DNS Monitoring: How to Check Your Traffic for Threats"},"content":{"rendered":"<p>Cybercriminals are becoming more sophisticated in their attacks.<\/p>\n<p>The Domain Name System (DNS) serves as a website&#8217;s identity and is the core component of its security architecture.<\/p>\n<p>Unless your website has the appropriate DNS monitoring in place, there&#8217;s no reason why you cannot become a cybercriminal&#8217;s next victim.<\/p>\n<p>We are offering informative tips on how to prevent security threats.<\/p>\n<h2>Why Do Cyber Criminals Target DNS?<\/h2>\n<p>Unfortunately, cybercriminals will target a vulnerable internet service or protocol, including a website&#8217;s DNS.<\/p>\n<p>They can then register disposable domain names for a spam campaign or botnet administration.<\/p>\n<p>What&#8217;s more, an attacker could use the domains to host malware or phishing downloads.<\/p>\n<p>Malicious queries can also exploit a nameserver or disrupt a name solution.<\/p>\n<p>Sadly, the cyber-attacks can potentially destroy a website&#8217;s performance, function, and reputation.<\/p>\n<p>The servers of Dyn are a perfect example.<\/p>\n<p>The company controls some of the internet&#8217;s DNS infrastructure. It experienced a cyber attack that brought down much of America and Europe&#8217;s internet on October 21st, 2016.<\/p>\n<p>The new Mirai botnet attack has been classed as <a href=\"https:\/\/www.theguardian.com\/technology\/2016\/oct\/26\/ddos-attack-dyn-mirai-botnet\">the largest kind in its history<\/a>.<\/p>\n<p>A variety of high-profile websites experienced a\u00a0downtime, such as Twitter, The Guardian, CNN, Netflix, and Reddit.<\/p>\n<p>While it may be a feat to prevent every potential DNS threat affecting a website, it&#8217;s essential to <a href=\"http:\/\/blog.siteuptime.com\/2012\/09\/20\/5-ways-to-reduce-downtime-from-cyber-attacks\/\">take action to avoid falling victim to a cyber attack<\/a>.<\/p>\n<h2>Why DNS Monitoring?<\/h2>\n<p>More than a quarter of companies haven&#8217;t established responsibility for their DNS security, despite the fact <a href=\"http:\/\/www.information-age.com\/growing-threat-ddos-attacks-dns-123459033\/\">DNS attacks have increased by more than 200%<\/a>.<\/p>\n<p>To prevent a\u00a0website from becoming a cyber attack target, you must embark with regular DNS monitoring.<\/p>\n<p>A DNS log monitors every connection your website makes with a visiting device.<\/p>\n<p>To maintain website security, it&#8217;s essential to embark with DNS monitoring to inspect the traffic between a device and your local recursive resolver.<\/p>\n<p>The forensic analysis can ensure you:<\/p>\n<ul>\n<li>Identify the websites visited by an employer<\/li>\n<li>Discover the malware\/botnets connected to the C&amp;C servers<\/li>\n<li>Detect a DDOS attack<\/li>\n<li>Pinpoint the Domain Generation Algorithm (DGA) and malicious domains accessed<\/li>\n<li>Identify the dynamic domains accessed<\/li>\n<\/ul>\n<p>When analyzing the DNS log, it&#8217;s essential to verify each domain against the DGA and malicious domain database.<\/p>\n<p>If you&#8217;re unsure of where to start with DNS Monitoring, we&#8217;re offering six security systems to help you proactively protect your website.<\/p>\n<h2>1. Firewalls<\/h2>\n<p>Firewalls have the potential to expose DNS threats, so they&#8217;re an effective tool for DNS monitoring.<\/p>\n<p>Most firewalls will allow webmasters to define rules to prevent <a href=\"http:\/\/searchsecurity.techtarget.com\/definition\/IP-spoofing\">IP spoofing<\/a>.<\/p>\n<p>For example, you could enter a rule that denies DNS queries from IP addresses outside an allocated number space. This could prevent a nameserver from exploitation in a <a href=\"http:\/\/blog.siteuptime.com\/2017\/01\/28\/how-dos-protection-can-reduce-website-downtime\/\">DDoS attack<\/a>.<\/p>\n<p>It&#8217;s also beneficial to enable DNS traffic inspection for suspicious byte patterns or irregular DNS traffic, so you can take the steps to block a nameserver software exploit attack.<\/p>\n<h2>2. Traffic Analyzers<\/h2>\n<p>One of the best ways to identify harmful malware traffic is a passive traffic analysis.<\/p>\n<p>A traffic analyzer will allow you to both capture and filter DNS traffic between a device and your local recursive resolver, which you can then save to a PCAP file.<\/p>\n<p>Webmasters must create scripts to search the PCAP file to identify specific suspicious activities.<\/p>\n<h2>3. Passive DNS Replication<\/h2>\n<p>Passive DNS replication allows a webmaster to use sensors at the local recursive resolvers.<\/p>\n<p>This creates a database containing each DNS transaction, such as the query or response, through a resolver or set of resolvers.<\/p>\n<p>The replication can be instrumental in identifying one or more malware domains, particularly in cases when the malware operates algorithmically generated domain names (AGDA).<\/p>\n<h2>4. Intrusion Detection Systems<\/h2>\n<p>An effective intrusion detection system allows you to create rules that allow reporting on DNS requests from unauthorized networks.<\/p>\n<p>It is beneficial to compose rules to either count or report:<\/p>\n<ul>\n<li>NXDomain responses<\/li>\n<li>DNS queries via TCP<\/li>\n<li>Responses that contain resource records with short TTLs<\/li>\n<li>Unusually large DNS responses<\/li>\n<li>DNS queries to non-standard ports<\/li>\n<li>plus more<\/li>\n<\/ul>\n<p>All DNS queries should be carefully reviewed.<\/p>\n<p>The intrusion detection systems can be integrated into firewalls, which will allow you to deny or permit rules for many of the checks listed above.<\/p>\n<h2>5. DNS Monitoring with Local Resolver Logs<\/h2>\n<p>Your local resolver logs are probably the most obvious and essential way to embark with DNS monitoring.<\/p>\n<p>By enabling resolver logging, you can use a variety of tools to collect DNS server logs whilst exploring known malicious domains, such as OSSEC.<\/p>\n<h2>6. A Secure Registrar<\/h2>\n<p>Most websites are registered via a registrar company.<\/p>\n<p>Unfortunately, if a cyber-attacker can compromise the account with the registrar, they can gain control over your domain name.<\/p>\n<p>This means they can point the registrar to their chosen server, including their nameservers.<\/p>\n<p>What&#8217;s more, they can transfer the domain to either a new owner or an offshore registrar &#8211; which means you might be unable to recover the domain.<\/p>\n<p>Many intelligent cyber attackers may target an account&#8217;s password, or they may even launch a cyber attack on the registrar&#8217;s tech support.<\/p>\n<p>You&#8217;ll want to avoid registrar hijacking, so you should select a registrar that provides heightened security precautions.<\/p>\n<p>Look for services like multi-factor authentication.<\/p>\n<h2>Suspicious Signs to Analyze<\/h2>\n<p>It is important to pay close attention to any potential signs of malicious activity on your network.<\/p>\n<p>We recommend analyzing the composition characteristics and length of DNS responses. This could help to identify malicious intent.<\/p>\n<p>If the response messages are unusually large, this could be an amplification attack.<\/p>\n<p>You should also review the answer or additional sections of the response message, which could be a sign of cache poisoning.<\/p>\n<h2>Conclusion<\/h2>\n<p>The biggest risk to a website is ignorance, which will not be bliss when you suffer a cyber attack.<\/p>\n<p>There are various forms of DNS monitoring that will allow you to expose threats and <a href=\"http:\/\/blog.siteuptime.com\/2015\/11\/03\/keep-website-secure\/\">keep your website secure<\/a>.<\/p>\n<p>It is up to a website admin to determine the right strategy to detect suspicious or malicious activity on your network.<\/p>\n<p>While DNS monitoring doesn&#8217;t sound like a fun thing to do, it is essential for the security of your website.<\/p>\n<p>Ensure you <a href=\"https:\/\/siteuptime.com\/compare.php\" target=\"_blank\" rel=\"noopener noreferrer\">take the necessary steps<\/a> to stop a cyber criminal in their tracks.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Got a website? You need to keep your DNS monitoring on point to protect your interests. Here&#8217;s our step-by-step guide on how to do it.<\/p>\n","protected":false},"author":1,"featured_media":489,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[107],"tags":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v15.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>DNS Monitoring: How to Check Your Traffic for Threats | SiteUptime Blog<\/title>\n<meta name=\"description\" content=\"Got a website? You need to keep your DNS monitoring on point to protect your interests. Here&#039;s our step-by-step guide on how to do it.\" \/>\n<meta name=\"robots\" content=\"index, nofollow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.siteuptime.com\/blog\/2017\/05\/03\/dns-monitoring-how-to-check-your-traffic-for-threats\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"DNS Monitoring: How to Check Your Traffic for Threats | SiteUptime Blog\" \/>\n<meta property=\"og:description\" content=\"Got a website? You need to keep your DNS monitoring on point to protect your interests. Here&#039;s our step-by-step guide on how to do it.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.siteuptime.com\/blog\/2017\/05\/03\/dns-monitoring-how-to-check-your-traffic-for-threats\/\" \/>\n<meta property=\"og:site_name\" content=\"SiteUptime Blog\" \/>\n<meta property=\"article:published_time\" content=\"2017-05-03T13:16:32+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2017-08-21T20:46:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.siteuptime.com\/blog\/wp-content\/uploads\/2017\/05\/dns-monitoring.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1687\" \/>\n\t<meta property=\"og:image:height\" content=\"1127\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\">\n\t<meta name=\"twitter:data1\" content=\"SiteUptime Blog Team\">\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\">\n\t<meta name=\"twitter:data2\" content=\"4 minutes\">\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.siteuptime.com\/blog\/#organization\",\"name\":\"Site Uptime\",\"url\":\"https:\/\/www.siteuptime.com\/blog\/\",\"sameAs\":[],\"logo\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.siteuptime.com\/blog\/#logo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.siteuptime.com\/blog\/wp-content\/uploads\/2016\/11\/logo.png\",\"width\":268,\"height\":67,\"caption\":\"Site Uptime\"},\"image\":{\"@id\":\"https:\/\/www.siteuptime.com\/blog\/#logo\"}},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.siteuptime.com\/blog\/#website\",\"url\":\"https:\/\/www.siteuptime.com\/blog\/\",\"name\":\"SiteUptime Blog\",\"description\":\"Website Monitoring\",\"publisher\":{\"@id\":\"https:\/\/www.siteuptime.com\/blog\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":\"https:\/\/www.siteuptime.com\/blog\/?s={search_term_string}\",\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.siteuptime.com\/blog\/2017\/05\/03\/dns-monitoring-how-to-check-your-traffic-for-threats\/#primaryimage\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/www.siteuptime.com\/blog\/wp-content\/uploads\/2017\/05\/dns-monitoring.jpg\",\"width\":1687,\"height\":1127,\"caption\":\"DNS Monitoring\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.siteuptime.com\/blog\/2017\/05\/03\/dns-monitoring-how-to-check-your-traffic-for-threats\/#webpage\",\"url\":\"https:\/\/www.siteuptime.com\/blog\/2017\/05\/03\/dns-monitoring-how-to-check-your-traffic-for-threats\/\",\"name\":\"DNS Monitoring: How to Check Your Traffic for Threats | SiteUptime Blog\",\"isPartOf\":{\"@id\":\"https:\/\/www.siteuptime.com\/blog\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.siteuptime.com\/blog\/2017\/05\/03\/dns-monitoring-how-to-check-your-traffic-for-threats\/#primaryimage\"},\"datePublished\":\"2017-05-03T13:16:32+00:00\",\"dateModified\":\"2017-08-21T20:46:53+00:00\",\"description\":\"Got a website? You need to keep your DNS monitoring on point to protect your interests. Here's our step-by-step guide on how to do it.\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.siteuptime.com\/blog\/2017\/05\/03\/dns-monitoring-how-to-check-your-traffic-for-threats\/\"]}]},{\"@type\":\"Article\",\"@id\":\"https:\/\/www.siteuptime.com\/blog\/2017\/05\/03\/dns-monitoring-how-to-check-your-traffic-for-threats\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.siteuptime.com\/blog\/2017\/05\/03\/dns-monitoring-how-to-check-your-traffic-for-threats\/#webpage\"},\"author\":{\"@id\":\"https:\/\/www.siteuptime.com\/blog\/#\/schema\/person\/3dcceb15bb9a56849e01dcfdfdf88750\"},\"headline\":\"DNS Monitoring: How to Check Your Traffic for Threats\",\"datePublished\":\"2017-05-03T13:16:32+00:00\",\"dateModified\":\"2017-08-21T20:46:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.siteuptime.com\/blog\/2017\/05\/03\/dns-monitoring-how-to-check-your-traffic-for-threats\/#webpage\"},\"publisher\":{\"@id\":\"https:\/\/www.siteuptime.com\/blog\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.siteuptime.com\/blog\/2017\/05\/03\/dns-monitoring-how-to-check-your-traffic-for-threats\/#primaryimage\"},\"articleSection\":\"Website Security\",\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.siteuptime.com\/blog\/#\/schema\/person\/3dcceb15bb9a56849e01dcfdfdf88750\",\"name\":\"SiteUptime Blog Team\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\/\/www.siteuptime.com\/blog\/#personlogo\",\"inLanguage\":\"en-US\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/a2273a2a463e223b14b604e611fe28bf?s=96&d=mm&r=g\",\"caption\":\"SiteUptime Blog Team\"},\"sameAs\":[\"http:\/\/www.siteuptime.com\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","_links":{"self":[{"href":"https:\/\/www.siteuptime.com\/blog\/wp-json\/wp\/v2\/posts\/488"}],"collection":[{"href":"https:\/\/www.siteuptime.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.siteuptime.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.siteuptime.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.siteuptime.com\/blog\/wp-json\/wp\/v2\/comments?post=488"}],"version-history":[{"count":2,"href":"https:\/\/www.siteuptime.com\/blog\/wp-json\/wp\/v2\/posts\/488\/revisions"}],"predecessor-version":[{"id":491,"href":"https:\/\/www.siteuptime.com\/blog\/wp-json\/wp\/v2\/posts\/488\/revisions\/491"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.siteuptime.com\/blog\/wp-json\/wp\/v2\/media\/489"}],"wp:attachment":[{"href":"https:\/\/www.siteuptime.com\/blog\/wp-json\/wp\/v2\/media?parent=488"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.siteuptime.com\/blog\/wp-json\/wp\/v2\/categories?post=488"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.siteuptime.com\/blog\/wp-json\/wp\/v2\/tags?post=488"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}