Re: DoH Ruleset missing

Joel Esler via Snort-users <[email protected]> Tue, 25 Nov 2025 10:15:38 -0500
Newsgroups gmane.comp.security.ids.snort.general
Message-ID <[email protected]>
--===============1310211850910882169==
Content-Type: multipart/alternative; boundary=Apple-Mail-C59FAE76-F9F8-467D-9DD6-BCFB4C155AC8
Content-Transfer-Encoding: 7bit


--Apple-Mail-C59FAE76-F9F8-467D-9DD6-BCFB4C155AC8
Content-Type: text/plain;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

Not sure the IDS is the proper place to handle this. Network firewall rules a=
nd DNS servers are probably the best place to handle this. =20

=E2=80=94=20
Sent from my =F0=9F=93=B1iPhone

> On Nov 24, 2025, at 21:03, Jonathan Lee via Snort-users <snort-users@lists=
.snort.org> wrote:
>=20
> =EF=BB=BFHello based on the following=20
>=20
> =E2=80=9CNSA recommends that an enterprise network=E2=80=99s DNS traffic, e=
ncrypted or not, be sent only to the designated enterprise DNS resolver.=E2=80=
=9D
>=20
> Building on that guidance, there should ideally be an RFC or standardized m=
echanism for locking down browsers and operating systems so they can use onl=
y approved DoH servers. With such controls in place, clients could be config=
ured to direct all DNS queries to a local resolver (such as pfSense Unbound)=
, while the firewall enforces that any DNS-over-HTTPS traffic is forwarded e=
xclusively to an authorized upstream resolver. This would re-establish enter=
prise DNS security controls, especially given prior incidents where attacker=
s have abused DoH for command-and-control purposes.
>=20
>=20
>=20
> Since this does not currently exist when can the Snort user base expect Do=
H rules to help with security concerns of users bypassing official enterpris=
e DNS servers?
>=20
> _______________________________________________
> Snort-users mailing list
> [email protected]
> Go to this URL to change user options or unsubscribe:
> https://lists.snort.org/mailman/listinfo/snort-users
>=20
>    To unsubscribe, send an email to:
>    [email protected]
>=20
> Please visit http://blog.snort.org to stay current on all the latest Snort=
 news!
>=20
> Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-=
etiquette

--Apple-Mail-C59FAE76-F9F8-467D-9DD6-BCFB4C155AC8
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html class=3D"apple-mail-supports-explicit-dark-mode"><head><meta http-equi=
v=3D"content-type" content=3D"text/html; charset=3Dutf-8"></head><body dir=3D=
"auto"><span style=3D"-webkit-text-size-adjust: auto; background-color: rgb(=
58, 58, 60);">Not sure the IDS is the proper place to handle this. Network f=
irewall rules and DNS servers are probably the best place to handle this. &n=
bsp;</span><br id=3D"lineBreakAtBeginningOfSignature"><div dir=3D"ltr"><div>=
<br></div>=E2=80=94&nbsp;<div><span style=3D"background-color: rgba(255, 255=
, 255, 0);">Sent from my =F0=9F=93=B1iPhone</span></div></div><div dir=3D"lt=
r"><br><blockquote type=3D"cite">On Nov 24, 2025, at 21:03, Jonathan Lee via=
 Snort-users &lt;[email protected]&gt; wrote:<br><br></blockquote>=
</div><blockquote type=3D"cite"><div dir=3D"ltr">=EF=BB=BF<meta http-equiv=3D=
"content-type" content=3D"text/html; charset=3Dutf-8">Hello based on the fol=
lowing&nbsp;<div><br></div><div><p data-start=3D"115" data-end=3D"247">=E2=80=
=9CNSA recommends that an enterprise network=E2=80=99s DNS traffic, encrypte=
d or not, be sent only to the designated enterprise DNS resolver.=E2=80=9D</=
p><p data-start=3D"249" data-end=3D"831">Building on that guidance, there sh=
ould ideally be an RFC or standardized mechanism for locking down browsers a=
nd operating systems so they can use only approved DoH servers. With such co=
ntrols in place, clients could be configured to direct all DNS queries to a l=
ocal resolver (such as pfSense Unbound), while the firewall enforces that an=
y DNS-over-HTTPS traffic is forwarded exclusively to an authorized upstream r=
esolver. This would re-establish enterprise DNS security controls, especiall=
y given prior incidents where attackers have abused DoH for command-and-cont=
rol purposes.</p><p data-start=3D"249" data-end=3D"831"><br></p><p data-star=
t=3D"249" data-end=3D"831">Since this does not currently exist when can the S=
nort user base expect DoH rules to help with security concerns of users bypa=
ssing official enterprise DNS servers?</p></div><span>______________________=
_________________________</span><br><span>Snort-users mailing list</span><br=
><span>[email protected]</span><br><span>Go to this URL to change u=
ser options or unsubscribe:</span><br><span>https://lists.snort.org/mailman/=
listinfo/snort-users</span><br><span></span><br><span> &nbsp; &nbsp;To unsub=
scribe, send an email to:</span><br><span> &nbsp; &nbsp;snort-users-leave@li=
sts.snort.org</span><br><span></span><br><span>Please visit http://blog.snor=
t.org to stay current on all the latest Snort news!</span><br><span></span><=
br><span>Please follow these rules: https://snort.org/faq/what-is-the-mailin=
g-list-etiquette</span><br></div></blockquote></body></html>=

--Apple-Mail-C59FAE76-F9F8-467D-9DD6-BCFB4C155AC8--

--===============1310211850910882169==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Snort-users mailing list
[email protected]
Go to this URL to change user options or unsubscribe:
https://lists.snort.org/mailman/listinfo/snort-users

	To unsubscribe, send an email to:
	[email protected]

Please visit http://blog.snort.org to stay current on all the latest Snort news!

Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette

--===============1310211850910882169==--