On The Vulnerability of Anti-Malware Solutions to DNS Attacks
Asaf Nadler, Ron Bitton, Oleg Brodt, Asaf Shabtai

TL;DR
This paper analyzes the security vulnerabilities of anti-malware solutions that communicate with remote services over the insecure DNS protocol, revealing risks of tampering and proposing countermeasures.
Contribution
It identifies the widespread use of DNS-based anti-malware communication, demonstrates vulnerabilities to DNS attacks, and suggests security improvements for anti-malware providers.
Findings
Almost three million machines use DNS-based anti-malware services.
Hundreds of millions of DNS requests carry sensitive information daily.
Attacks can alter file classification and leak sensitive data.
Abstract
Anti-malware agents typically communicate with their remote services to share information about suspicious files. These remote services use their up-to-date information and global context (view) to help classify the files and instruct their agents to take a predetermined action (e.g., delete or quarantine). In this study, we provide a security analysis of a specific form of communication between anti-malware agents and their services, which takes place entirely over the insecure DNS protocol. These services, which we denote DNS anti-malware list (DNSAML) services, affect the classification of files scanned by anti-malware agents, therefore potentially putting their consumers at risk due to known integrity and confidentiality flaws of the DNS protocol. By analyzing a large-scale DNS traffic dataset made available to the authors by a well-known CDN provider, we identify anti-malware…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsNetwork Security and Intrusion Detection · Advanced Malware Detection Techniques · Internet Traffic Analysis and Secure E-voting
