Repository navigation
Add DNS query log parser (dnsmasq / Pi-hole) - #42
Conversation
New DnsParser in ax-normalize. DNS is a favorite covert channel, so beyond extracting the query we compute the features that expose tunnelling: qname_length and qname_entropy (Shannon entropy of the query name) feed point detection of DGA / exfil names (long, high-entropy), and timestamp_epoch feeds cadence on query timing (beaconing). qtype (e.g. TXT) and client round out each row. Parses the dnsmasq query line shape '<time> dnsmasq[pid]: query[TYPE] NAME from CLIENT'; non-query lines (forwarded/reply/cached/config) produce no rows. The BSD timestamp has no year, so it is parsed with a fixed sentinel year (UTC) — deterministic, never the wall clock. The query type must start uppercase, ruling out prose like 'query[0] x from y'. Detected by a parseable query line (scanning the first lines, since logs may open with non-query lines); STRONG; claims no extension (DNS logs are generically *.log). Input with no query lines is a clean Parse error. Mutation gate: 0 surviving mutants on the new file. The extensions() -> empty-slice mutant is a documented equivalent (same as the other signature-only parsers). Closes #19 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Warning Review limit reached
More reviews will be available in 42 minutes and 40 seconds. Learn how PR review limits work. Your organization has run out of usage credits. Purchase more in the billing tab. ⌛ How to resolve this issue?After more reviews become available, a review can be triggered using the We recommend that you space out your commits to avoid hitting the rate limit. 🚦 How do rate limits work?CodeRabbit enforces hourly rate limits for each developer per organization. Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available. Please see our Fair Usage Limits Policy for further information. ℹ️ Review info⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Plus Run ID: 📒 Files selected for processing (4)
✨ Finishing Touches🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Implements the DNS query log plugin — issue #19.
What
DNS is a favorite covert channel, so beyond extracting the query,
DnsParsercomputes the features that expose tunnelling:
qname_entropy(Shannon entropy of the query name) +qname_length→pointdetection of DGA / exfil names (long, high-entropy);timestamp_epoch→cadenceon query timing (beaconing);qtype(e.g.TXT) andclientround out each row.Parses the dnsmasq query line shape
<time> dnsmasq[pid]: query[TYPE] NAME from CLIENT; non-query lines (forwarded / reply / cached / config) produce no rows.The query type must start with an uppercase letter, ruling out prose like
query[0] x from y.Determinism
The dnsmasq BSD timestamp has no year, so it's parsed with a fixed sentinel year
in UTC — deterministic, never the wall clock (
Jan 1 00:00:00→ epoch0).Routing
open with non-query lines),
STRONG.*.log).Errors
Input with no query lines is a clean
AxError::Parse.Gates
fmt/clippy -D warnings/ full workspace tests green (both feature sets).dns.rs(entropy, epoch, andquery-parse logic all covered; the
extensions()empty-slice mutant is adocumented equivalent).
dns; high-entropy DGA/exfil names are flagged bypoint.modzonqname_entropy/qname_length(exit 1).Closes #19
🤖 Generated with Claude Code