Sensors can inspect DNS response packets to detect known and zero-day callback activities.
- For the known botnets, Sensors inspect the DNS response packets for C&C server domains according to the callback detectors.
- For the detection of zero-day callback activities, Sensors perform complex heuristic analyses of DNS response traffic. This way, Sensors can detect the following types of callback activities:
- IP addresses and domains related to a Fast Flux Service Network (FFSN).
- Domain names generated by bots infected with Domain Generation Algorithm (DGA).
The following Sensor models on version 9.1 and later can inspect DNS response packets for callback activities:
- All M-series Sensors
- All NS-series Sensors
- All Virtual IPS Sensors
Because the DNS packets might get load-balanced across Sensors in an XC Cluster Load Balancer solution, FFSN and DGA detection is not guaranteed for XC Cluster deployments. The Sensors in an XC Cluster Load Balancer solution, attempt to detect FFSN and DGA on a best-effort basis only.
Note
You can edit the attack definitions related to DNS inspection in the required IPS policies. Alternatively, you can edit the attack definitions in Master Attack Repository to affect all IPS policies.