DNS: Null Query
This protocol anomaly is a DNS request in which the question, answer, additional, and name server counts are zero. Detecting this anomaly can indicate a malicious user trying to crash the DNS server.
Extended Description
A DNS query that contains all counters equaling 0, or exceptionally large counter numbers, is a protocol anomaly.
References
BugTraq: 99302
CVE: CVE-2017-9445
URL: http://www.networksorcery.com/enp/protocol/dns.htm http://www.dns.net/dnsrd/rfc http://www.javvin.com/protocolDNS.html
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
5.0