meta_pixel
Tapesearch Logo
Log in
SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

ISC StormCast for Wednesday, December 18th 2019

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

SANS ISC Handlers

Tech News, News

4.9754 Ratings

🗓️ 18 December 2019

⏱️ 6 minutes

🧾️ Download transcript

Summary

Daily 5 min cyber security news summary. News, patches, vulnerabilities and trends in information and network security. Discovering DNS over HTTPS; Ring Camera Weaknesses; WhatsApp Bug;

Transcript

Click on a timestamp to play from that location

0:00.0

Hello, welcome to the Wednesday, December 18th, 2019 edition of the Sands and the Storm Center's

0:07.0

Stormcast. My name is Johannes Ulrich. And I'm recording from Jacksonville, Florida.

0:13.0

I took a closer look today at the DNS over HDPS implementation between Firefox and Cloudflare and publish some sort of initial

0:25.2

results of some experiments here.

0:28.6

First of all about identifying these connections.

0:32.1

Now the idea here is of course that if you don't necessarily know the IP address, the user is connecting to,

0:40.0

for example, they're using their own DNS over HDPS endpoint.

0:44.3

Well, yes, you can sort of profile the connections and figure out that they're probably

0:49.7

doing DNS over HTPS.

0:51.8

One sort of giveaway is that the payload sizes for the TCP packets with DNS

0:59.1

or HTTP are a lot smaller on average than the ones for regular HTTP traffic. Regular

1:08.0

HTTP traffic, if you're downloading files and such, you're typically downloading

1:11.9

more data for a particular request, which means that pretty much the segment size, so the

1:18.7

amount of data being sent in each packets fills the entire MTO. So it's around 1,400 plus

1:26.4

bytes of payload length. For DNS over HTPS, you typically

1:32.5

deal with shorter transactions. So what you will see is shorter packets, typically less than

1:40.1

500 bytes in length. And an interesting sort of three spike pattern here that I found

1:47.3

when I looked at the size frequency will probably have more about this on

1:52.7

Thursday including how to decode some possible queries and the like that may be

1:59.7

sent over HTTP.

2:02.0

Right now I'm focusing a little bit on the Firefox to Cloudflare connection because

2:05.9

that's sort of the most common and most mature implementation at this point probably, but

...

Please login to see the full transcript.

Disclaimer: The podcast and artwork embedded on this page are from SANS ISC Handlers, and are the property of its owner and not affiliated with or endorsed by Tapesearch.

Generated transcripts are the property of SANS ISC Handlers and are distributed freely under the Fair Use doctrine. Transcripts generated by Tapesearch are not guaranteed to be accurate.

Copyright © Tapesearch 2026.