- play_arrow Overview
- play_arrow Juniper Advanced Threat Prevention Cloud Overview
- play_arrow Juniper Advanced Threat Cloud Prevention Setup
-
- play_arrow Juniper ATP Cloud Web Portal
- play_arrow Juniper ATP Cloud Web Portal Overview
-
- play_arrow Enroll SRX Series Firewalls in Juniper ATP Cloud Web Portal
- play_arrow Configure Juniper ATP Cloud Features
- play_arrow Allowlists and Blocklists
- play_arrow Email Scanning: Juniper ATP Cloud
- play_arrow File Inspection Profiles
- play_arrow Adaptive Threat Profiling
- play_arrow Feeds Configuration
- play_arrow Infected Hosts
- play_arrow Threat Intelligence Sharing
- play_arrow Misc Configurations
-
- play_arrow Administration
- play_arrow Juniper ATP Cloud Administration
- Modify My Profile
- Create and Edit User Profiles
- Set Password
- Application Tokens Overview
- Create Application Tokens
- Multi-Factor Authentication Overview
- Configure Multi-Factor Authentication for Administrators
- Set Up Single Sign-on with SAML 2.0 Identity Provider
- Configure SSO Settings
- View Audit Logs
-
- play_arrow More Documentation
- play_arrow ATP Cloud Tech Library Page Links
-
DNS DGA and Tunneling Detection Details
To access this page, click
.You can view details about DNS DGA and tunnel detections.
DGA
You can perform the following action in the DGA tab:
View details about the DGA-based detections. See Table 1.
View the threat sources if there is a C&C hit for a domain. Click domain name with DGA verdict to view the threat sources.
Report false positives. Choose this option to send a report to Juniper Networks, informing a false positive. Juniper will investigate the report; however, this does not change the verdict.
Export DGA detections as a CSV file to view and analyze the exported DGA detections as needed. You can either export all detections at once or for a specific timespan.
Select the time span to view the DGA detections for a specific period.
Field | Description |
---|---|
Domain | Displays the domain name where DGA hit occurs. |
DNS Record Type | Displays the DNS record type. Example: A (Host address), CNAME (Canonical name for an alias), SRV (location of service), and so on.
|
Last Hit Session ID | Displays the ID of the most recent domain hit. |
Last Hit Source IP | Displays the source IP address of the most recent domain hit. |
Last Hit Destination IP | Displays the destination IP address of the most recent domain hit. |
Total Hits | Displays the total number of hits on the domain. |
Verdict | Displays the confirmed DGA verdict provided by ATP Cloud.
|
Last Hit Time | Displays the date and time of the most recent domain hit. |
Tunnel
Use the Tunnel tab to monitor the DNS tunneling metadata provided by SRX Series Firewalls. Table 2 displays the DNS tunneling metadata.
You can perform the following action in the Tunnel tab:
View details about the DNS tunneling metadata provided by SRX Series Firewalls. Table 2 displays the DNS tunneling metadata.
Export DNS Tunnel detections as a CSV file to view and analyze the exported DNS tunneling detections as needed. You can either export all detections at once or for a specific timespan.
Select the time span to view the DNS tunneling detections for a specific period.
View detailed information about a DNS tunnel. Click on a domain name. See Table 3
- Download PCAP from the DNS Tunnel page. Select a client and click Download PCAP to download the packet capture details and view more information about the network.
Field | Description |
---|---|
Domain | Displays the domain name |
DNS Record Type | Displays the DNS record type. Example: A (Host address), CNAME (Canonical name for an alias), SRV (location of service), and so on.
|
Last Hit Session ID | Displays the session ID of the most recent domain hit. |
Tunnel Data | Displays the tunnel information shared by SRX Series Firewall |
Last Hit Source IP | Displays the source IP address of the most recent domain hit. |
Last Hit Destination IP | Displays the destination IP address of the most recent domain hit. |
Total Hits | Displays the total number of sessions that were hit. |
Last Hit Time | Displays the date and time of the most recent domain hit. |
Field | Description |
---|---|
Client IP Address | Displays the IP address of the host that has contacted the DNS domain. |
Device Name | Displays the name of the SRX Series Firewall in contact with the DNS domain |
Incoming Bytes | Displays the number of incoming bytes to the DNS tunnel. |
Outgoing Bytes | Displays the number of outgoing bytes from the DNS tunnel. |
Last Seen | The date and time of the most recent DNS tunnel hit. |
DNS DGA and tunnel detection is supported on Junos OS 21.2R1 and later releases.