Short Name |
DNS:QUERY:NULL-QUERY |
---|---|
Severity |
High |
Recommended |
Yes |
Recommended Action |
Drop Packet |
Category |
DNS |
Keywords |
dns null query |
Release Date |
2004/01/29 |
Update Number |
1213 |
Supported Platforms |
di-5.3+, idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This protocol anomaly is a DNS request in which the question, answer, additional, and name server counts are zero. Detecting this anomaly can indicate a malicious user trying to crash the DNS server.
A DNS query that contains all counters equaling 0, or exceptionally large counter numbers, is a protocol anomaly.