DiscoverAuditCasts with David Hoelzer#20: DNS Sinkhole for Malware Defense and Policy Enforcement
#20: DNS Sinkhole for Malware Defense and Policy Enforcement

#20: DNS Sinkhole for Malware Defense and Policy Enforcement

Update: 2011-11-02
Share

Description

BIND is usually the go-to DNS solution if you're looking to set up a DNS sinkhole to contain and identify malware. While I love BIND as much as the next guy, I find that it's a real pain in the neck to get everything set up just right and the maintenance involved in adding a new authoritative zone is just more than I'm willing to do.
As a solution to this, I've revived a tool that I wrote more than a decade ago for Internet usage policy enforcement. As it turns out, it already was a DNS sinkhole, I just never called it one!
Watch the episode for a demonstration and discussion and check out the blog article for more information and the source code: http://it-audit.sans.org/blog/2011/11/02/dns-sinkhole-for-malware-defense-and-policy-enforcement/
Comments 
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

#20: DNS Sinkhole for Malware Defense and Policy Enforcement

#20: DNS Sinkhole for Malware Defense and Policy Enforcement

david hoelzer