DoH Ruleset missing
Jonathan Lee via Snort-users <[email protected]> Thu, 20 Nov 2025 06:10:06 -0800
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
--===============5396381613174257448== Content-Type: multipart/alternative; boundary="Apple-Mail=_A43DE92C-35AA-43E3-8187-899D65BC26AC" --Apple-Mail=_A43DE92C-35AA-43E3-8187-899D65BC26AC Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 Hello based on the following=20 =E2=80=9CNSA recommends that an enterprise network=E2=80=99s DNS = traffic, encrypted or not, be sent only to the designated enterprise DNS = resolver.=E2=80=9D Building on that guidance, there should ideally be an RFC or = standardized mechanism for locking down browsers and operating systems = so they can use only approved DoH servers. With such controls in place, = clients could be configured to direct all DNS queries to a local = resolver (such as pfSense Unbound), while the firewall enforces that any = DNS-over-HTTPS traffic is forwarded exclusively to an authorized = upstream resolver. This would re-establish enterprise DNS security = controls, especially given prior incidents where attackers have abused = DoH for command-and-control purposes. Since this does not currently exist when can the Snort user base expect = DoH rules to help with security concerns of users bypassing official = enterprise DNS servers?= --Apple-Mail=_A43DE92C-35AA-43E3-8187-899D65BC26AC Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8 <html aria-label=3D"message body"><head><meta http-equiv=3D"content-type" = content=3D"text/html; charset=3Dutf-8"></head><body = style=3D"overflow-wrap: break-word; -webkit-nbsp-mode: space; = line-break: after-white-space;">Hello based on the = following <div><br></div><div><p data-start=3D"115" = data-end=3D"247">=E2=80=9CNSA recommends that an enterprise network=E2=80=99= s DNS traffic, encrypted or not, be sent only to the designated = enterprise DNS resolver.=E2=80=9D</p><p data-start=3D"249" = data-end=3D"831">Building on that guidance, there should ideally be an = RFC or standardized mechanism for locking down browsers and operating = systems so they can use only approved DoH servers. With such controls in = place, clients could be configured to direct all DNS queries to a local = resolver (such as pfSense Unbound), while the firewall enforces that any = DNS-over-HTTPS traffic is forwarded exclusively to an authorized = upstream resolver. This would re-establish enterprise DNS security = controls, especially given prior incidents where attackers have abused = DoH for command-and-control purposes.</p><p data-start=3D"249" = data-end=3D"831"><br></p><p data-start=3D"249" data-end=3D"831">Since = this does not currently exist when can the Snort user base expect DoH = rules to help with security concerns of users bypassing official = enterprise DNS servers?</p></div></body></html>= --Apple-Mail=_A43DE92C-35AA-43E3-8187-899D65BC26AC-- --===============5396381613174257448== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette --===============5396381613174257448==--