DoH Ruleset missing

Jonathan Lee via Snort-users <[email protected]> Thu, 20 Nov 2025 06:10:06 -0800
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
--===============5396381613174257448==
Content-Type: multipart/alternative;
	boundary="Apple-Mail=_A43DE92C-35AA-43E3-8187-899D65BC26AC"


--Apple-Mail=_A43DE92C-35AA-43E3-8187-899D65BC26AC
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
	charset=utf-8

Hello based on the following=20

=E2=80=9CNSA recommends that an enterprise network=E2=80=99s DNS =
traffic, encrypted or not, be sent only to the designated enterprise DNS =
resolver.=E2=80=9D

Building on that guidance, there should ideally be an RFC or =
standardized mechanism for locking down browsers and operating systems =
so they can use only approved DoH servers. With such controls in place, =
clients could be configured to direct all DNS queries to a local =
resolver (such as pfSense Unbound), while the firewall enforces that any =
DNS-over-HTTPS traffic is forwarded exclusively to an authorized =
upstream resolver. This would re-establish enterprise DNS security =
controls, especially given prior incidents where attackers have abused =
DoH for command-and-control purposes.



Since this does not currently exist when can the Snort user base expect =
DoH rules to help with security concerns of users bypassing official =
enterprise DNS servers?=

--Apple-Mail=_A43DE92C-35AA-43E3-8187-899D65BC26AC
Content-Transfer-Encoding: quoted-printable
Content-Type: text/html;
	charset=utf-8

<html aria-label=3D"message body"><head><meta http-equiv=3D"content-type" =
content=3D"text/html; charset=3Dutf-8"></head><body =
style=3D"overflow-wrap: break-word; -webkit-nbsp-mode: space; =
line-break: after-white-space;">Hello based on the =
following&nbsp;<div><br></div><div><p data-start=3D"115" =
data-end=3D"247">=E2=80=9CNSA recommends that an enterprise network=E2=80=99=
s DNS traffic, encrypted or not, be sent only to the designated =
enterprise DNS resolver.=E2=80=9D</p><p data-start=3D"249" =
data-end=3D"831">Building on that guidance, there should ideally be an =
RFC or standardized mechanism for locking down browsers and operating =
systems so they can use only approved DoH servers. With such controls in =
place, clients could be configured to direct all DNS queries to a local =
resolver (such as pfSense Unbound), while the firewall enforces that any =
DNS-over-HTTPS traffic is forwarded exclusively to an authorized =
upstream resolver. This would re-establish enterprise DNS security =
controls, especially given prior incidents where attackers have abused =
DoH for command-and-control purposes.</p><p data-start=3D"249" =
data-end=3D"831"><br></p><p data-start=3D"249" data-end=3D"831">Since =
this does not currently exist when can the Snort user base expect DoH =
rules to help with security concerns of users bypassing official =
enterprise DNS servers?</p></div></body></html>=

--Apple-Mail=_A43DE92C-35AA-43E3-8187-899D65BC26AC--

--===============5396381613174257448==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

--===============5396381613174257448==--