Page 75 - CSI - Cisco Security Instroduction - BT
P. 75
Gather Intelligence & Enforce Security at the DNS Layer
Any Device Recursive DNS Authoritative DNS
root
com.
domain.com.
Request Patterns Authoritative Logs
Used to detect: Used to find:
• Compromised systems • Newly staged infrastructures
• Command & control callbacks • Malicious domains, IPs,
• Malware & phishing attempts ASNs
• Algorithm-generated domains • DNS hijacking
• Domain co-occurrences • Fast flux domains
• Newly registered domains • Related domains
78