Additional information on GuardDuty DNS Findings

0

I am receiving DNS related GuardDuty findings for "querying algorithmically generated domains" that we suspect are not algorithmically generated.

An example URL is from the following Facebook page: https://www.facebook.com/SOMD-167556163301693/

The URL in question is http://stuckonmsdawn.com/

So my questions:

  1. Why is GuardDuty flagging this as algorithmically generated?
  2. Is there a way of checking with AWS whether they think a domain is algorithmically generated (or as part of a "Command & Control server" also) before actually making the DNS query itself?

Thanks

MaxEB
질문됨 2년 전988회 조회
1개 답변
1

There are 2 types of DGA related GuardDuty findings i.e. DGADomainRequest.B and DGADomainRequest.C!DNS.

For this finding EC2/DGADomainRequest.B: it is based on analysis of domain names using advanced heuristics and may identify new DGA domains that are not present in threat intelligence feeds. If you believe the domain has been incorrectly identified, please raise a technical support ticket with AWS support.

For this finding DGADomainRequest.C!DNS: it is based on known DGA domains from GuardDuty's threat intelligence feeds.

Please refer to this link for additional details of the DGA related findings.

profile pictureAWS
답변함 2년 전
  • Finding a lot of this lately, does not seem very intelligent. Lots of false positives.

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인