FINDING · DEFENSE

DNS-sly encodes downstream data by selecting A records from the IP address pool of CDN-hosted domains. For the top 25% of Alexa Top 500 domains, approximately one third of DNS responses contain more than 8 A records and ~15% contain 15 A records; the global IP pool has a median of ~2,000 IPs per domain (maximum ~16,000), enabling b = floor(log2(s!/(s-c)!)) bits per response.

From 2016-akbar-dns-slyDNS-sly: Avoiding Censorship through Network Complexity · §2.2 · 2016 · Free and Open Communications on the Internet

Implications

Tags

techniques
dpitraffic-shape
defenses
dns-tunnelingsteganography

Extracted by claude-sonnet-4-6 — review before relying.