DNS Tunneling

Also known as:DNS Tunnel

DNS Tunneling: Transporting arbitrary data inside DNS queries and responses to bypass network boundaries. The technique serves both data exfiltrationData ExfiltrationUnauthorized transfer or theft of data from an organization. and covert command and controlCommand and ControlCommunication infrastructure used by attackers to control compromised systems..

How it works and where it fits

DNS is permitted in nearly every network, including those where only a proxy otherwise reaches outside. The attacker controls a domain and its authoritative server. Payload is encoded — usually Base32 or Base64 — and appended as subdomain labels to queries; responses carry data back in TXT, NULL, or CNAME records. Because a label is limited to 63 characters and the full name to 255, the stream is split into numbered chunks that the receiver reassembles.

Practical security relevance

Detection relies on characteristics legitimate DNS rarely shows: very many queries to the same domain, unusually long high-entropy labels, sequential chunk numbers, a high share of TXT queries, and a mismatch between query volume and actual connections. Effective countermeasures are enforced internal resolvers, logging and analysis of all queries, per-client rate limiting, and reputation plus anomaly checks at the domain level.

  • Data ExfiltrationData ExfiltrationUnauthorized transfer or theft of data from an organization.: Unauthorized transfer or theft of data from an organization.
  • Command and ControlCommand and ControlCommunication infrastructure used by attackers to control compromised systems.: Communication infrastructure used by attackers to control compromised systems.
  • Network ForensicsNetwork ForensicsReconstruction and analysis of security-relevant events based on network data.: Reconstruction and analysis of security-relevant events based on network data.
  • BeaconingBeaconingRegular communication between a compromised system and a command-and-control infrastructure.: Regular communication between a compromised system and a command-and-control infrastructure.