DNS Attacks
DNS attacks abuse naming infrastructure to redirect traffic, exhaust resources, poison caches, or hide malicious infrastructure.
Mechanism
Examples include cache poisoning, DNS tunneling, malicious domain use, and DNS amplification. Each has different mechanics, so defenders should baseline normal resolver behavior and query patterns.
Indicators to watch
Unexpected resolver destinations, high NXDOMAIN rates, unusual record changes, long or high-entropy subdomains, abnormal query volume, and suspicious newly registered domains.
Concept diagram
Defensive controls
Use validated DNSSEC where appropriate, secure resolver configuration, response-rate controls, logging, threat intelligence, egress monitoring, and segmentation of recursive resolvers.
Recommended security control
DNS firewall / passive DNS monitoring
Perform DNS experiments only in a controlled lab resolver.
Defense tool
The administrator has not attached a tool yet. This slot will show “Build Soon” until a link or file is configured.
All attack descriptions are for defensive education. Test scanning, traffic generation, interception, wireless testing, and vulnerable applications only on systems and networks you own or are explicitly authorized to assess.