4.9 • 696 Ratings
🗓️ 21 September 2023
⏱️ 6 minutes
🧾️ Download transcript
Click on a timestamp to play from that location
0:00.0 | Hello and welcome to the Thursday, September 21st, 2023 edition of the Sansonet Stormontas Stormcast. |
0:08.7 | My name is Johannes Ulrich, and I'm recording from Jacksonville, Florida. |
0:15.0 | DNSTTLs. |
0:16.6 | That's a quick diary I wrote today to look at, well, normal data. |
0:21.8 | As security analysts, we often focus on, well, malicious data and malicious traffic. |
0:27.8 | But in order to really find these anomalies that lead us to this malicious traffic, |
0:32.1 | we first have to understand what's normal. |
0:35.2 | So I'm trying to do a little serious here over the next few weeks or months, |
0:39.9 | depending on long it will take me, to talk about some of the parameters to look at. |
0:44.3 | And one parameter that's sort of interesting is this TTL, the time to live, that's being returned |
0:51.8 | with DNS responses. Best to collect that data between |
0:57.1 | authoritative name servers and your recursive name server, then you get the actual |
1:02.6 | TTL as the authoritative name server intended it. If you do use like a forwarding setup, then |
1:09.9 | the TTLs can be a little bit more iffy |
1:13.4 | because, well, they may already be reduced somewhat by the recursive name server that |
1:18.9 | you are forwarding your queries to. |
1:21.9 | What did I see for the TTLs? |
1:23.3 | Well, nothing out of the ordinary, and that's kind of a good thing. The fastest TTLs were for your |
1:31.5 | A and quad A records. Interesting that quad A was a little bit longer than the A records. Also, |
1:40.2 | the name server record was by far the longest-lived records. And that's certainly something to look for for name server records with a short detail. |
1:50.0 | That's often an indicator for malicious name servers going back to malware from years and years ago, |
1:57.0 | like for example, Fast Flux. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2025.