[Bro] How to check the length of NDS request packets?

Vern Paxson vern at berkeley.edu
Fri Jun 9 19:05:24 PDT 2017


> I am going to write a script that detects DNS tunneling.

BTW, if it's not on your radar you should check out our paper on doing this:

	http://www.icir.org/vern/papers/covert-dns-usec13.pdf

In generally, finding tunneling is much more involved than looking for
long lookups, for example.

		Vern


More information about the Bro mailing list