Friday, August 17, 2012

Dr. J's Poor Man DNS Anomaly Detection using Bro

Dr. Johannes Ullrich of the SANS Internet Storm Center posted a great DNS Anomaly Detection script based on the query logs coming from his DNS server. We can do the same thing with Bro's dns.log (where Bro captures all the DNS queries it sees on the network):
http://code.google.com/p/security-onion/wiki/DNSAnomalyDetection

No comments:

Search This Blog

Featured Post

Security Onion 2.4.150 Hotfix 20250522 now available!

Last week, we released version 2.4.150: https://blog.securityonion.net/2025/05/security-onion-24150-celebrating.html This week, an upstream ...

Popular Posts

Blog Archive