Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
_kerberos._tcp.dc._msdcs.<br />
_kerberos._tcp.._sites.dc._msdcs.<br />
_kerberos._tcp.._sites.<br />
_kerberos._tcp.<br />
Typically these are queries for SRV records, although sometimes they are requests for SOA<br />
records. They appear to be related to Microsoft Active Directory services. 31<br />
5.4.6 Name includes _dns-sd at one level, oft<strong>en</strong> the 3 rd or 4 th level of the<br />
<strong>name</strong><br />
Patterns observed show many requests of the form:<br />
<br />
._dns-sd._udp.<br />
Occasionally two levels occur after ._udp.<br />
Typically these are lookups for PTR records, although sometimes they are queries for TXT<br />
records. They appear to be related to Apple’s service discovery service (Bonjour or multicast<br />
DNS).<br />
5.4.7 Name starts with “File moved-http://”<br />
The predominant form of DNS <strong>name</strong> that has be<strong>en</strong> observed in this category is of the form:<br />
<br />
File moved-http://www.whatismyip...Home.<br />
in which and are one- to three-digit numbers (presumably two quads of an IPv4<br />
address).<br />
These all appear to be queries for A records.<br />
5.4.8 Name includes _sip, _sipinternal, _sipinternaltls,<br />
_sipfederationtls, or _sips at the lowest level<br />
Patterns observed show many requests of the form:<br />
<br />
<br />
<br />
<br />
_sip._tcp.<br />
_sip._udp.<br />
_sip._tls.<br />
_sipinternal._tcp.<br />
31 The opcodes for these requests were not analyzed, but it is consist<strong>en</strong>t with Active Directory behavior<br />
that some requests are updates and therefore have “SOA” stored at the location in the packet that is<br />
id<strong>en</strong>tified with QTYPE for regular queries.<br />
Name Collision Study Report Page 50<br />
Version 1.5 2013.08.02