IOT DNS Analysis

IOT devices are being added to networks at a blistering pace. Everything from smart plugs, light switches, light bulbs, appliances, thermostats, video doorbells, cameras, and many more.

In many cases, the installation procedure is simple; plug it in, pray, and it ‘should’ work. If it doesn’t, try it again and if that fails, blame the network because it worked at home.

When it comes to corporate environments there are so many things that can prevent a device from getting internet access. If you're lucky it will be something trivial like a TCP/UDP port number being blocked. Other times it becomes a more involved troubleshooting exercise and could be an IP address/DNS name is blocked or flagged as suspicious.

In this video, I take a trace of an Ethernet-attached camera and walk you through how I filtered out the camera traffic and what value we can get from the DNS requests made by it.

