Design and Implementation of a DNS Sinkhole for Cyberattack Analysis

A DNS-based sinkhole is a DNS server that responds to a query with a falsified result. Doing so with a malicious intent would classify as DNS spoofing. However, sinkholes have also been used for non-malicious purposes. For example, the command and control (C&C) channel of a botnet can be interrupted by locally deploying a sinkhole [1][2].

Besides actively scrubbing traffic, a potential application is to analyze network traffic to gain insights on cyberattacks [3]. For that, there is a lack of solutions that provide integrated sinkholing and traffic analysis features. The goal of this thesis is to integrate a configurable and easy to use DNS sinkhole into the SecGrid traffic analysis platform [4]. Depending on the type of thesis, we will evaluate the prototype by analyzing a cyberattack in a practical case study.


