5GSEC / nimbus

Intent driven security automation framework
Apache License 2.0
19 stars 9 forks source link

DNS Logging: DNS Manipulation Intent #115

Open shivaccuknox opened 1 month ago

shivaccuknox commented 1 month ago

An adversary can piggyback user data within DNS requests, so that the DNS server retrieves the user data for further processing.

The detection technique involves logging the DNS requests

The adapter used is KubeArmor, and the API logging work [https://github.com/5GSEC/nimbus/issues/112] item tracks the adapter/security engine work

This detection technique is not part of the MITRE FiGHT