EDNS0 como Vetor Adversarial: Lacunas de Visibilidade Empírica em Ferramentas Populares de DPI e Detecção de Intrusão

  • Bruno Carvalho Alvarenga UFPR
  • André Ricardo Abed Grégio UFPR

Resumo


Opções carregadas no pseudo-registro OPT do EDNS0 constituem vetor adversarial para canais encobertos em tráfego DNS negligenciado pela literatura defensiva. A avaliação empírica de Suricata, Snort e Zeek em configuração padrão resulta em zero detecções contra seis técnicas adversariais (T1 a T6). A inspeção do código-fonte identifica a causa como lacuna estrutural do parser no Zeek 8.1.x. Endereçamos a lacuna com um plugin Spicy que expõe eventos por opção e por pseudo-RR OPT, e derivamos cinco heurísticas com precisão e revocação de 1,00. A portabilidade para Suricata revela um teto: a rule-language pura alcança precisão equivalente mediante ancoragem semântica, mas não reproduz revocação em enumeração multi-opção nem em heurísticas com estado por origem.

Referências

Aiello, M., Mongelli, M., and Papaleo, G. (2013). Basic Classifiers for DNS Tunneling Detection. In Proceedings of the 18th IEEE Symposium on Computers and Communications (ISCC), pages 880–885, Split, Croatia.

Born, K. and Gustafson, D. (2010). Detecting DNS Tunnels Using Character Frequency Analysis. arXiv:1004.4358 [cs.CR]. Apresentado em 9th Annual Security Conference, Las Vegas, NV. Disponível em: [link]. Acesso em: maio de 2026.

Buczak, A. L., Hanke, P. A., Cancro, G. J., Toma, M. K., Watkins, L. A., and Chavis, J. S. (2016). Detection of Tunnels in PCAP Data by Random Forests. In Proceedings of the 11th Annual Cyber and Information Security Research Conference (CISRC). ACM.

Contavalli, C., van der Gaast, W., Lawrence, D., and Kumari, W. (2016). Client Subnet in DNS Queries. RFC 7871, Internet Engineering Task Force.

Damas, J., Graff, M., and Vixie, P. (2013). Extension Mechanisms for DNS (EDNS(0)). RFC 6891, Internet Engineering Task Force.

Davis, J. and Deccio, C. (2021). A Peek into the DNS Cookie Jar: An Analysis of DNS Cookie Use. In Proceedings of the Passive and Active Measurement Conference (PAM), volume 12671 of Lecture Notes in Computer Science, pages 302–316. Springer.

Eastlake, D. and Andrews, M. (2016). Domain Name System (DNS) Cookies. RFC 7873, Internet Engineering Task Force.

Farrokhi, B. (2025). EDNS Client Subnet in Practice: Evaluating Public Resolver Behaviors. Disponível em: [link]. Acesso em: maio de 2026.

Internet Assigned Numbers Authority (2026). DNS EDNS0 Option Codes (OPT). Registro DNS Parameters. Disponível em: [link]. Acesso em: julho de 2026.

Internet Systems Consortium (2015). Partial EDNS Compliance Hampers Deployment of New DNS Features. ISC Blog. Disponível em: [link]. Acesso em: maio de 2026.

Internet Systems Consortium (2026). EDNS Compliance Reports. Disponível em: [link]. Acesso em: maio de 2026. Relatórios automatizados periódicos sobre conformidade EDNS de servidores autoritativos e resolvedores recursivos, publicados desde 2016.

Kumari, W., Hunt, E., Arends, R., Hardaker, W., and Lawrence, D. (2020). Extended DNS Errors. RFC 8914, Internet Engineering Task Force.

Lambion, D., Josten, M., Olumofin, F., and De Cock, M. (2020). Malicious DNS Tunneling Detection in Real-Traffic DNS Data. In Proceedings of the 2020 IEEE International Conference on Big Data (Big Data), pages 5736–5738. IEEE.

Le Pochat, V., Van Goethem, T., Tajalizadehkhoob, S., Korczyński, M., and Joosen, W. (2019). Tranco: A Research-Oriented Top Sites Ranking Hardened Against Manipulation. In Proceedings of the 26th Annual Network and Distributed System Security Symposium (NDSS).

Mahdavifar, S., Salem, A. H., Victor, P., Razavi, A. H., Garzon, M., Hellberg, N., and Lashkari, A. H. (2021). Lightweight Hybrid Detection of Data Exfiltration using DNS based on Machine Learning. In Proceedings of the 11th International Conference on Communication and Network Security (ICCNS), pages 80–86, Weihai, China. ACM. Dataset CIC-Bell-DNS-EXF 2021 disponível em [link].

Mayrhofer, A. (2016). The EDNS(0) Padding Option. RFC 7830, Internet Engineering Task Force.

Nadler, A., Aminov, A., and Shabtai, A. (2019). Detection of Malicious and Low Throughput Data Exfiltration over the DNS Protocol. Computers & Security, 80:36–53.

Paxson, V. (1999). Bro: A System for Detecting Network Intruders in Real-Time. Computer Networks, 31(23–24):2435–2463.

Rijs, S. (2014). Combating DNS Amplification Using Cookies. Master’s thesis, University of Amsterdam, OS3 Master’s Programme. Supervisor: Roland van Rijswijk-Deij. Disponível em: [link].

Sommer, R., Amann, J., and Hall, S. (2016). Spicy: A Unified Deep Packet Inspection Framework for Safely Dissecting All Your Data. In Proceedings of the 32nd Annual Computer Security Applications Conference (ACSAC), pages 558–569. ACM.

ttpreport (2025). SiphonDNS: Covert Data Exfiltration via DNS. Blog post e ferramenta. Disponível em: [link] e [link]. Acesso em: maio de 2026.

Waleed, A., Jamali, A. F., and Masood, A. (2022). Which Open-Source IDS? Snort, Suricata or Zeek. Computer Networks, 213:109116.

Weber, J. (2019). DNS Capture: UDP, TCP, IP-Fragmentation, EDNS, ECS, Cookie. weberblog.net. Disponível em: [link]. Acesso em: maio de 2026.

Wouters, P. (2016). CHAIN Query Requests in DNS. RFC 7901, Internet Engineering Task Force.

Wouters, P., Abley, J., Dickinson, S., and Bellis, R. (2016). The edns-tcp-keepalive EDNS0 Option. RFC 7828, Internet Engineering Task Force.

Žiža, K., Tadić, P., and Vuletić, P. (2023). DNS Exfiltration Detection in the Presence of Adversarial Attacks and Modified Exfiltrator Behaviour. International Journal of Information Security, 22(6):1865–1880.
Publicado
01/09/2026
ALVARENGA, Bruno Carvalho; GRÉGIO, André Ricardo Abed. EDNS0 como Vetor Adversarial: Lacunas de Visibilidade Empírica em Ferramentas Populares de DPI e Detecção de Intrusão. In: SIMPÓSIO BRASILEIRO DE CIBERSEGURANÇA (SBSEG), 26. , 2026, Armação dos Búzios/RJ. Anais [...]. Porto Alegre: Sociedade Brasileira de Computação, 2026 . p. 565-580. DOI: https://doi.org/10.5753/sbseg.2026.29268.