Security e-Series
1753943 Members
8986 Online
108811 Solutions
New Discussion

How to prevent DNS flooding

 
IPS_User
Occasional Visitor

How to prevent DNS flooding

I found that many DNS queries coming from Internet is sent to my DNS server every minutes. Although they query the valid domain name, the hostname is a fake & random generated value or the query type is ANY.

However, those traffic did not trigger any attack filter, and I am use 600 N series IPS, would you please tell me how I can prevent this attack?

 

3 REPLIES 3
cenk sasmaztin
Honored Contributor

Re: How to prevent DNS flooding

please try

filter 1350,1351,1352,1353,1354,1355

cenk

IPS_User
Occasional Visitor

Re: How to prevent DNS flooding

Thank you for your information, Cenk Sasmaztin!

All your mentioned filters are enabled, but no triggered.

cenk sasmaztin
Honored Contributor

Re: How to prevent DNS flooding

may be use snort rules for dns attack

download snort rules from snort web site and convert tipping point filter with dv converter tool

 

please watch my video

 

 

 

http://youtu.be/JatIvCv4zow

cenk