10-04-2017 03:51 AM - edited 03-08-2019 05:44 PM
HI all,
I have noticed that I have many drops in Firesight Management Centre connection table.
The drops are between my Internal DNS and ISP's dns servers.
They are documented as "Malware-Other dns request with long hostname segment - possible data exfiltration attempt"
Periodically i have DNS issues where internal clients web browsing is slow of fails altogether.
Im unsure whether the browing issues are related to the connection table drops.
Any thoughts would be appreciated.
thanks
Ian
10-08-2017 01:07 AM
hello,
I think both would be related. Because if your internal DNS server is doing recursive query to your ISP DNS server which might be getting blocked, slow internet for users whose queries aren't solved would be expected.
Also the rule
rule |
alert udp $HOME_NET any -> $EXTERNAL_NET 53 (msg:"MALWARE-OTHER dns request with long host name segment - possible data exfiltration attempt"; sid:30881; gid:3; rev:4; classtype:attempted-recon; metadata:engine shared, soid 3|30881, service dns; )
|
is a pre-processor rule so you might want to investigate and check why the traffic is being blocked in first place.
Rate if its helpful.
Yogesh
10-09-2017 01:54 AM
Hi Yogesh,
Thanks for your input.
The internal DNS servers are protected by Sophos and the server team are adamanet that there are no issues with the Internal DNS servers are blame Firesight for the DNS problems.
Im unsure how to progress this and wonder whether I should disable this rule or not.
Ian
10-10-2017 06:35 PM
I too would like some further understanding as to why these happen in almost every deployment with this rule enabled in the IPS.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide