{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T16:05:53Z","timestamp":1775837153778,"version":"3.50.1"},"reference-count":28,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2022,3,7]],"date-time":"2022-03-07T00:00:00Z","timestamp":1646611200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Digital Threats"],"published-print":{"date-parts":[[2022,9,30]]},"abstract":"<jats:p>\n            The\n            <jats:bold>Domain Name System<\/jats:bold>\n            (\n            <jats:bold>DNS<\/jats:bold>\n            ) is known to be one of the most widely abused protocols by threat actors to use in unconventional ways to hide under normal traffic. Apart from threat actors, DNS is being actively used or rather misused by many other service providers, vendors, and so on, to provide the intended services. An in-depth examination of the DNS logs collected over a long period revealed some very interesting legitimate use cases of the DNS protocol by the industry and other players, apart from its normal name resolution service function. We coin the term \u201cOff-label use of DNS\u201d to represent those use cases. Legitimate here simply means using DNS for non-malicious purposes other than what it was traditionally designed for, which is for providing domain resolution; a dictionary service mapping domain names to corresponding IP addresses. One of the main reasons DNS is used, or possibly misused, for these off-label use cases is the speed of data transfer and reduced overhead in terms of bandwidth. These off-label use cases of DNS can often leak important information about the clients and software they are running and can be leveraged in a variety of ways by the network security defenders\/analysts to improve their detection on the network. This research will detail some of those legitimate off-label use cases and how they can be leveraged by the analysts to detect malware trends in the network and much more just by analyzing an enterprise's DNS logs.\n          <\/jats:p>","DOI":"10.1145\/3491261","type":"journal-article","created":{"date-parts":[[2021,10,29]],"date-time":"2021-10-29T16:36:22Z","timestamp":1635525382000},"page":"1-13","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["\u201cOff-Label\u201d Use of DNS"],"prefix":"10.1145","volume":"3","author":[{"given":"Fatema Bannat","family":"Wala","sequence":"first","affiliation":[{"name":"University of Delaware, Berkeley CA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6218-1327","authenticated-orcid":false,"given":"Chase","family":"Cotton","sequence":"additional","affiliation":[{"name":"University of Delaware, Newark DE, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2022,3,7]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"Claranet Soho. 2014. Importance of DNS. Retrieved on 25 July 2020 https:\/\/www.claranetsoho.co.uk\/blog\/2014-06-05-importance-dns."},{"key":"e_1_3_2_3_2","unstructured":"2020. Run Docker Containers on Embedded Devices. Retrieved on 20th July 2019 https:\/\/www.balena.io\/os\/docs."},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1155\/2018.6137098"},{"key":"e_1_3_2_5_2","doi-asserted-by":"crossref","first-page":"36","DOI":"10.1016\/j.cose.2018.09.006","article-title":"Detection of malicious and low throughput data exfiltration over the DNS protocol","volume":"80","author":"Sabati Asaf","year":"2019","unstructured":"Asaf Sabati, Asaf Nadler, and Avi Aminov. 2019. Detection of malicious and low throughput data exfiltration over the DNS protocol. Elsevier Computers Security 80, 36\u201353.","journal-title":"Elsevier Computers Security"},{"key":"e_1_3_2_6_2","unstructured":"Fatema Bannat Wala. 2019. Antivirus-Detection. Retrieved on 20th July 2020 https:\/\/github.com\/fatemabw\/bro-inventory-scripts\/blob\/master\/scripts\/AV_detection.bro."},{"key":"e_1_3_2_7_2","article-title":"DNS as a Covert Channel Within Protected Networks","author":"Bromberger Seth","year":"2011","unstructured":"Seth Bromberger. 2011. DNS as a Covert Channel Within Protected Networks. NESCO.","journal-title":"NESCO"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/3377869"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2006.78"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2015.2458581"},{"key":"e_1_3_2_11_2","unstructured":"Nicholas Garcia. 2018. Alert: Hola VPN is Putting You In Danger. Retrieved on 20th July 2020 https:\/\/www.lifehack.org\/articles\/technology\/alert-hola-vpn-putting-you-danger.html."},{"key":"e_1_3_2_12_2","unstructured":"Nicholas Garcia. 2020. FAQs for Global Threat Intelligence File Reputation. Retrieved on 20th July 2020 https:\/\/kcm.trellix.com\/corporate\/index\/index?page=content&id=KB53735."},{"key":"e_1_3_2_13_2","unstructured":"Geoff Huston. 2019. DNS Wars. Retrieved on 20th July 2020 https:\/\/blog.apnic.net\/2019\/11\/04\/dns-wars\/."},{"key":"e_1_3_2_14_2","unstructured":"Geoff Huston. 2020. DNS evolution: Trust Privacy and Everything Else. Retrieved 27th Oct 2020 https:\/\/blog.apnic.net\/2020\/10\/27\/dns-evolution-trust-privacy-and-everything-else\/."},{"key":"e_1_3_2_15_2","first-page":"29","article-title":"How to prevent AS hijacking attacks","year":"2012","unstructured":"Johann Schlamp, Georg Carle, and Ernst W. Biersack. 2012. How to prevent AS hijacking attacks. In Proceedings of the 2012 ACM Conference on CoNEXT Student Workshop (CoNEXT Student\u201912). 29\u201330.","journal-title":"Proceedings of the 2012 ACM Conference on CoNEXT Student Workshop (CoNEXT Student\u201912)"},{"key":"e_1_3_2_16_2","doi-asserted-by":"crossref","first-page":"523","DOI":"10.1145\/2398776.2398831","article-title":"Content delivery and the natural evolution of DNS: Remote DNS trends, performance issues and alternative solutions","author":"Otto John S.","year":"2012","unstructured":"John S. Otto, Mario A. S\u00e1nchez, John P. Rula, and Fabi\u00e1n Ernesto Bustamante. 2012. Content delivery and the natural evolution of DNS: Remote DNS trends, performance issues and alternative solutions. In Proceedings of the 2012 Internet Measurement Conference (IMC\u201912). 523\u2013536.","journal-title":"Proceedings of the 2012 Internet Measurement Conference (IMC\u201912)"},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/3338840.3355672"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3231053.3231082"},{"key":"e_1_3_2_19_2","article-title":"Unconstrained endpoint security system: UEPTSS","volume":"10","year":"2018","unstructured":"Fatema Bannat Wala and Chase Cotton. Unconstrained endpoint security system: UEPTSS. International Journal of Network Security & Its Applications (IJNSA) 10 (2018).","journal-title":"International Journal of Network Security & Its Applications (IJNSA)"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-01244-0_5"},{"key":"e_1_3_2_21_2","unstructured":"Charlie Osborne. 2018. Researchers slam Hola VPN over absent encryption user IP leaks. Retrieved 20th July 2019 https:\/\/www.zdnet.com\/article\/researchers-slam-hola-vpn-over-absent-encryption-user-ip-leaks\/."},{"key":"e_1_3_2_22_2","unstructured":"Vern Paxson Scott Campbell Craig leres and Jason Lee. Bro Intrusion Detection System. Computer software. Vers. 00. DOE and NSF. 25 Jan. 2006. Web."},{"key":"e_1_3_2_23_2","unstructured":"Vern Paxson. 2018. Zeek: An Open Source Network Security Monitoring Tool. https:\/\/zeek.org\/."},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1303.3047"},{"key":"e_1_3_2_25_2","unstructured":"2019. Wawa Data Security Incident. Retrieved on 20th July 2020 https:\/\/www.wawa.com\/alerts\/data-security."},{"key":"e_1_3_2_26_2","unstructured":"Sam Heiney. 2019. Retrieved on 20th July 2021 https:\/\/blog.netop.com\/what-you-need-to-know-about-pos-security."},{"key":"e_1_3_2_27_2","unstructured":"2020. Retrieved on 20th July 2020 https:\/\/www.securitymagazine.com\/articles\/91745-rutters-suffers-pos-malware-attack-exposing-payment-cards."},{"key":"e_1_3_2_28_2","unstructured":"N. Balaji. 2020. Retrieved on 20th July 2020 https:\/\/cybersecuritynews.com\/alina-a-point-of-sale-pos-malware\/."},{"key":"e_1_3_2_29_2","first-page":"379","volume-title":"Proceedings of the 2014 ACM Conference on SIGCOMM (SIGCOMM\u201914)","year":"2014","unstructured":"Liang Zhu, Zi Hu, John S. Heidemann, Duane Wessels, Allison Mankin, and Nikita Somaiya. 2014. T-DNS: Connection-oriented DNS to improve privacy and security. In Proceedings of the 2014 ACM Conference on SIGCOMM (SIGCOMM\u201914). 379\u2013380."}],"container-title":["Digital Threats: Research and Practice"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3491261","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3491261","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T18:09:20Z","timestamp":1750183760000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3491261"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,7]]},"references-count":28,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2022,9,30]]}},"alternative-id":["10.1145\/3491261"],"URL":"https:\/\/doi.org\/10.1145\/3491261","relation":{},"ISSN":["2692-1626","2576-5337"],"issn-type":[{"value":"2692-1626","type":"print"},{"value":"2576-5337","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,3,7]]},"assertion":[{"value":"2021-02-22","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-09-16","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-03-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}