Protecting Synology NAS From DNS Tunneling Attacks
A Synology NAS often contains some of an organization’s most valuable information, including backups, shared files, virtual machine data, business documents, and archived records. That makes protecting the device about more than preventing unauthorized logins. Businesses also need to consider what happens if an attacker compromises the NAS and attempts to quietly move data outside the network.
One technique that deserves attention is DNS tunneling. Attackers can abuse DNS traffic to communicate with compromised systems or potentially transfer encoded information through DNS requests. Because DNS is necessary for normal network operations, malicious traffic can sometimes blend into legitimate activity.
Protecting a Synology NAS therefore requires a layered strategy involving DSM security, network segmentation, outbound traffic controls, DNS monitoring, and enterprise firewall protections.
How a Compromised Synology NAS Could Become an Exfiltration Point
A NAS is typically considered a destination for data. Files are copied to it, users access shared folders, and backup applications write data to storage.
After compromise, however, an attacker may attempt to turn that relationship around.
Depending on the access obtained, malicious activity could potentially involve:
- Accessing sensitive, shared folders
- Collecting backup data
- Searching stored files for valuable information
- Establishing persistence
- Communicating with external infrastructure
- Attempting to exfiltrate stolen information
This is why protecting inbound access alone is insufficient.
Organizations should also consider what connections the NAS itself is permitted to initiate.
Understanding DNS-Based Command-and-Control Risks
DNS translates domain names into IP addresses, making it a fundamental part of almost every business network.
Attackers can attempt to exploit that trusted role.
In a DNS tunneling scenario, information may be encoded inside specially constructed DNS queries and responses. DNS can also potentially provide a communication channel between compromised devices and attacker-controlled infrastructure.
Warning Signs May Include
- Unusually long DNS queries
- Large numbers of requests to unfamiliar domains
- Repeated queries to unusual subdomains
- Abnormally high DNS traffic from the NAS
- Connections inconsistent with normal NAS operations
Individual DNS requests may appear harmless, which is why monitoring patterns over time is important.
Start by Securing Synology DSM
Network monitoring cannot compensate for weak NAS security.
Organizations should first reduce the likelihood that an attacker can compromise DSM.
Important DSM Security Practices Include
- Keep DSM and installed packages updated
- Disable services that are not required
- Remove or disable unused accounts
- Use strong, unique credentials
- Enable multi-factor authentication where appropriate
- Review administrator privileges
- Restrict management access
- Monitor login activity
Synology Security Advisor can also help identify certain configuration weaknesses and security concerns within the NAS environment.
Reducing the available attack surface makes it more difficult for attackers to establish the initial foothold needed for data exfiltration.
Segment Synology NAS Devices From the Rest of the Network
A business NAS should not necessarily have unrestricted communication with every workstation, server, IoT device, and network segment.
Network segmentation can place storage infrastructure within a dedicated VLAN or protected network zone.
Segmentation Can Help Control
- Which users can reach the NAS
- Which servers can access storage
- Which backup systems can communicate with it
- Which management devices can administer DSM
- Which networks the NAS can communicate with
If an employee workstation becomes compromised, segmentation can make lateral movement toward critical storage infrastructure more difficult.
It can also help contain an incident if the NAS itself becomes compromised.
Use Firewall Rules Around the NAS
Synology DSM includes firewall capabilities that can provide another layer of access control.
Administrators can create rules based on the services and network connections genuinely required by the environment.
However, NAS firewall configuration should complement rather than replace the organization’s perimeter and internal network controls.
A Layered Strategy Can Include
DSM firewall: Controls permitted access to NAS services.
Internal network firewall: Controls communication between VLANs and network segments.
Perimeter firewall: Controls connections between internal systems and external networks.
Together, these layers provide stronger protection than relying on a single firewall.
Limit Outbound Connections From NAS Devices
Outbound filtering is particularly important when considering data exfiltration.
Many networks carefully restrict incoming connections while allowing internal devices broad outbound Internet access.
For critical storage systems, that assumption deserves reconsideration.
A Synology NAS should generally communicate only with destinations and services required for legitimate operations.
Depending on the environment, legitimate outbound access might include approved update infrastructure, backup destinations, monitoring services, or other specifically authorized systems.
Why Restriction Matters
If malware compromises the NAS, unrestricted outbound access could make external communication easier.
Limiting unnecessary outbound connectivity creates another obstacle between the attacker and external infrastructure.
Control Which DNS Resolver the NAS Uses
Organizations can also control how NAS devices resolve DNS.
Instead of allowing the Synology NAS to communicate with arbitrary external DNS servers, businesses can require DNS requests to pass through approved internal resolvers.
Network firewall policies can then restrict direct DNS connections to unauthorized destinations.
This Provides Several Benefits
- Centralized DNS logging
- Easier anomaly detection
- Consistent DNS security policies
- Better visibility into requested domains
- Reduced opportunities to bypass enterprise DNS controls
Centralizing DNS traffic gives security teams a clearer picture of how critical storage systems communicate.
Monitor Suspicious Network Activity
Security controls are stronger when organizations can identify abnormal behaviour.
Teams should establish a baseline for normal Synology NAS network activity and investigate significant deviations.
Useful Indicators Can Include
- Unexpected DNS volume
- Requests to newly observed domains
- Repetitive unusual subdomains
- Unexpected outbound destinations
- Traffic occurring at unusual times
- Large or unexplained outbound transfers
- New services listening on the NAS
Firewall, DNS, SIEM, IDS/IPS, and endpoint or network-monitoring platforms can provide additional visibility.
The objective is not simply collecting logs. Organizations need a practical way to identify behaviour that differs from normal NAS operations.
Combine Synology Security With Enterprise Controls
Synology provides useful security capabilities within DSM, but protecting valuable business data should not depend entirely on the NAS itself.
A stronger architecture combines NAS-level protection with enterprise network controls.
A Layered Security Model Can Include
- Synology DSM security configuration
- Security Advisor
- DSM firewall policies
- Multi-factor authentication
- Network segmentation
- Enterprise DNS filtering
- Next-generation firewall controls
- IDS/IPS monitoring
- Centralized logging and SIEM
- Backup immutability and snapshots
- Offline or isolated backup copies
This approach assumes that no individual security control will stop every attack.
Protect Backups From the Same Compromise
Data exfiltration is only one possible objective after attackers compromise storage infrastructure.
They may also attempt to delete backups, encrypt shared folders, modify snapshots, or interfere with recovery systems.
Organizations should therefore maintain independent recovery layers.
Synology technologies such as snapshots, replication, and backup applications can contribute to this strategy when configured correctly. Critical information should also have additional copies that cannot be easily modified through the same compromised credentials or system.
A 3-2-1-1-0 backup strategy, for example, can add isolation and recoverability beyond the primary NAS.
Regularly Review NAS Network Permissions
Network environments change continuously.
New backup platforms are introduced, applications migrate, employees leave, and temporary firewall exceptions sometimes remain long after they are needed.
Businesses should periodically review:
- NAS firewall rules
- VLAN access
- Administrator accounts
- Outbound permissions
- DNS configuration
- Installed DSM packages
- Remote-access services
- Backup destinations
Removing unnecessary permissions reduces the number of paths attackers could potentially exploit.
Building a More Secure Synology Environment
DNS tunneling demonstrates why NAS cybersecurity needs to extend beyond passwords and inbound firewall rules. If attackers successfully compromise a storage device, controlling and monitoring what that device can communicate with becomes critical.
Synology security features can provide valuable protection at the device level, while segmentation, restricted outbound connectivity, controlled DNS resolution, firewall policies, and centralized monitoring add defenses around the NAS.
The result is a layered architecture designed not only to prevent compromise, but also to make command-and-control activity and data exfiltration more difficult.
About Epis Technology
Epis Technology helps businesses design, deploy, and secure Synology NAS environments as part of a broader data protection and cybersecurity strategy. From DSM hardening and network segmentation to firewall planning, backup architecture, monitoring, and disaster recovery, Epis Technology can help organizations reduce the risks surrounding critical storage infrastructure.
For businesses using Synology for backups, shared storage, Microsoft 365 protection, virtualization, or business continuity, Epis Technology can also evaluate how the NAS communicates with the wider network and identify opportunities to strengthen security. A properly designed Synology environment protects more than the storage appliance itself, it creates multiple defensive layers around the business data the NAS was deployed to protect.