Re: DoH Ruleset missing
Joel Esler via Snort-users <[email protected]> Tue, 25 Nov 2025 10:15:38 -0500
| Newsgroups | gmane.comp.security.ids.snort.general |
|---|---|
| Message-ID | <[email protected]> |
--===============1310211850910882169== Content-Type: multipart/alternative; boundary=Apple-Mail-C59FAE76-F9F8-467D-9DD6-BCFB4C155AC8 Content-Transfer-Encoding: 7bit --Apple-Mail-C59FAE76-F9F8-467D-9DD6-BCFB4C155AC8 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Not sure the IDS is the proper place to handle this. Network firewall rules a= nd DNS servers are probably the best place to handle this. =20 =E2=80=94=20 Sent from my =F0=9F=93=B1iPhone > On Nov 24, 2025, at 21:03, Jonathan Lee via Snort-users <snort-users@lists= .snort.org> wrote: >=20 > =EF=BB=BFHello based on the following=20 >=20 > =E2=80=9CNSA recommends that an enterprise network=E2=80=99s DNS traffic, e= ncrypted or not, be sent only to the designated enterprise DNS resolver.=E2=80= =9D >=20 > Building on that guidance, there should ideally be an RFC or standardized m= echanism for locking down browsers and operating systems so they can use onl= y approved DoH servers. With such controls in place, clients could be config= ured to direct all DNS queries to a local resolver (such as pfSense Unbound)= , while the firewall enforces that any DNS-over-HTTPS traffic is forwarded e= xclusively to an authorized upstream resolver. This would re-establish enter= prise DNS security controls, especially given prior incidents where attacker= s have abused DoH for command-and-control purposes. >=20 >=20 >=20 > Since this does not currently exist when can the Snort user base expect Do= H rules to help with security concerns of users bypassing official enterpris= e DNS servers? >=20 > _______________________________________________ > Snort-users mailing list > [email protected] > Go to this URL to change user options or unsubscribe: > https://lists.snort.org/mailman/listinfo/snort-users >=20 > To unsubscribe, send an email to: > [email protected] >=20 > Please visit http://blog.snort.org to stay current on all the latest Snort= news! >=20 > Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-= etiquette --Apple-Mail-C59FAE76-F9F8-467D-9DD6-BCFB4C155AC8 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html class=3D"apple-mail-supports-explicit-dark-mode"><head><meta http-equi= v=3D"content-type" content=3D"text/html; charset=3Dutf-8"></head><body dir=3D= "auto"><span style=3D"-webkit-text-size-adjust: auto; background-color: rgb(= 58, 58, 60);">Not sure the IDS is the proper place to handle this. Network f= irewall rules and DNS servers are probably the best place to handle this. &n= bsp;</span><br id=3D"lineBreakAtBeginningOfSignature"><div dir=3D"ltr"><div>= <br></div>=E2=80=94 <div><span style=3D"background-color: rgba(255, 255= , 255, 0);">Sent from my =F0=9F=93=B1iPhone</span></div></div><div dir=3D"lt= r"><br><blockquote type=3D"cite">On Nov 24, 2025, at 21:03, Jonathan Lee via= Snort-users <[email protected]> wrote:<br><br></blockquote>= </div><blockquote type=3D"cite"><div dir=3D"ltr">=EF=BB=BF<meta http-equiv=3D= "content-type" content=3D"text/html; charset=3Dutf-8">Hello based on the fol= lowing <div><br></div><div><p data-start=3D"115" data-end=3D"247">=E2=80= =9CNSA recommends that an enterprise network=E2=80=99s DNS traffic, encrypte= d or not, be sent only to the designated enterprise DNS resolver.=E2=80=9D</= p><p data-start=3D"249" data-end=3D"831">Building on that guidance, there sh= ould ideally be an RFC or standardized mechanism for locking down browsers a= nd operating systems so they can use only approved DoH servers. With such co= ntrols in place, clients could be configured to direct all DNS queries to a l= ocal resolver (such as pfSense Unbound), while the firewall enforces that an= y DNS-over-HTTPS traffic is forwarded exclusively to an authorized upstream r= esolver. This would re-establish enterprise DNS security controls, especiall= y given prior incidents where attackers have abused DoH for command-and-cont= rol purposes.</p><p data-start=3D"249" data-end=3D"831"><br></p><p data-star= t=3D"249" data-end=3D"831">Since this does not currently exist when can the S= nort user base expect DoH rules to help with security concerns of users bypa= ssing official enterprise DNS servers?</p></div><span>______________________= _________________________</span><br><span>Snort-users mailing list</span><br= ><span>[email protected]</span><br><span>Go to this URL to change u= ser options or unsubscribe:</span><br><span>https://lists.snort.org/mailman/= listinfo/snort-users</span><br><span></span><br><span> To unsub= scribe, send an email to:</span><br><span> snort-users-leave@li= sts.snort.org</span><br><span></span><br><span>Please visit http://blog.snor= t.org to stay current on all the latest Snort news!</span><br><span></span><= br><span>Please follow these rules: https://snort.org/faq/what-is-the-mailin= g-list-etiquette</span><br></div></blockquote></body></html>= --Apple-Mail-C59FAE76-F9F8-467D-9DD6-BCFB4C155AC8-- --===============1310211850910882169== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _______________________________________________ Snort-users mailing list [email protected] Go to this URL to change user options or unsubscribe: https://lists.snort.org/mailman/listinfo/snort-users To unsubscribe, send an email to: [email protected] Please visit http://blog.snort.org to stay current on all the latest Snort news! Please follow these rules: https://snort.org/faq/what-is-the-mailing-list-etiquette --===============1310211850910882169==--