Environment
- CB Response Sensor: All Linux versions
- CB Response Server: All versions
Question
How does the Linux sensor perform DNS name resolution?
Answer
- The kernel captures DNS response packets for active processes, and transfers them to the sensor daemon.
- The daemon then parses the response, and updates its local sensor cache (not to be confused with the OS DNS cache).
- The daemon then performs a reverse lookup in its own cache for each netconn.
Additional Notes
If multiple hostnames are seen associated with a single address, that indicates that some process has performed a lookup for each host and they resolved to that address.
Related Content