NF – TLD domain – .cn DNS query

This alert is triggered when a DNS query is made from the home network to an external network for a domain ending with ".cn" (indicating a Chinese top-level domain)

Categories:

ID Number

5017803

Signature

alert udp $HOME_NET any -> $EXTERNAL_NET 53 (msg:"NF - TLD domain - .cn DNS query"; content:"|01 00 00 01 00 00 00 00 00 00|"; depth:10; offset:2; content:"|02|CN|00|"; fast_pattern; nocase; distance:0; reference:url,networkforensic.dk meadata:20042015; classtype:bad-unknown; sid:5017803; rev:4;)

Severity

Low

Recommendations/Investigative actions

Determine if access to Chinese domains is expected and necessary for your organization. If the query is not legitimate, investigate the source of the query to determine what caused it. If there is no business requirement for accessing Chinese domains, implement blocks or restrictions to mitigate potential security risks.