How to Use DNS Analytics to Find the Compromised Domain in a Billion DNS Queries

October 12, 2018

Finding a needle in a haystack is hard, but it’s nothing compared to finding a single piece of hay in the haystack that was put there with malicious intentions.

As Verisign noted in its August 2018 “Domain Name Industry Brief,” there were around 339.8 million registered domains at the end of the second quarter, with approximately 7.9 million new domains registered in the last year. Additionally, public Domain Name System (DNS) providers log hundreds of billions of queries every day. Cloudflare reported that it serves 130 billion DNS queries per day, and in 2014, Google reported that it served more than 400 billion DNS queries per day. Furthermore, Let’s Encrypt issues around 600,000 digital certificates per day.

