ISC StormCast for Tuesday, November 14th, 2023
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)
SANS ISC Handlers
4.9 • 754 Ratings
🗓️ 14 November 2023
⏱️ 5 minutes
🧾️ Download transcript
Summary
Transcript
Click on a timestamp to play from that location
| 0:00.0 | Hello and welcome to the Tuesday, November 14th, 2020, |
| 0:04.5 | edition of the San Antonio Storm Center's Stormcast. |
| 0:08.5 | My name is Johannes Ulrich. |
| 0:10.2 | And today'm recording from Jacksonville, Florida. |
| 0:14.7 | Manuel today wrote a quick reminder that's, well, also one of my favorite topics, |
| 0:20.0 | DNS logs and how important they are |
| 0:22.5 | to detect intrusions. In particular, Manuel here is looking at the command control channels |
| 0:30.1 | that often use sort of some custom made-up names that the attacker registered. Now, yes, you have some sophisticated attackers that try to mimic specific well-known domain names |
| 0:45.0 | and try to kind of fly under the radar that way. |
| 0:48.1 | But quite often attackers are using essentially sort of random strings of letters and numbers in order to use these names |
| 0:57.0 | then as a domain name for their command and control channel. That of course is not that |
| 1:03.2 | difficult to spot what Manuel here is doing is looking at the frequency distribution of letters, |
| 1:09.9 | which prioritizes these random host names |
| 1:14.5 | because they usually have few duplicates, |
| 1:17.6 | and with that, you know, is able, in this case, |
| 1:20.2 | to spot pretty quickly and pretty easily relevant domain name. |
| 1:26.4 | Now, just one little trick here that Manuel isn't mentioning, if you do want to extract |
| 1:31.7 | things like, you know, here IP addresses and host names or domain names from a file like |
| 1:38.6 | this, from a PCAP, if you don't have an existing tool, it actually T-Shark works really well for this if you just want to |
| 1:46.6 | extract the relevant fields. Take a look at the dash capital T and then fields option and then you |
| 1:53.1 | can just list individual fields. And then we have a somewhat concerning paper about the security |
| 1:59.5 | of SSH from four researchers at the University of California, San Diego. |
... |
Please login to see the full transcript.
Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.
Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.
Copyright © Tapesearch 2026.

