nimbus icon indicating copy to clipboard operation
nimbus copied to clipboard

DNS Logging: DNS Manipulation Intent

Open shivaccuknox opened this issue 1 year ago • 0 comments

An adversary can piggyback user data within DNS requests, so that the DNS server retrieves the user data for further processing.

The detection technique involves logging the DNS requests

The adapter used is KubeArmor, and the API logging work [https://github.com/5GSEC/nimbus/issues/112] item tracks the adapter/security engine work

This detection technique is not part of the MITRE FiGHT

shivaccuknox avatar May 21 '24 14:05 shivaccuknox