{"id":4518,"date":"2015-12-09T14:00:28","date_gmt":"2015-12-09T14:00:28","guid":{"rendered":"http:\/\/www.intelligentcio.com\/me\/?p=4518"},"modified":"2015-12-09T14:00:28","modified_gmt":"2015-12-09T14:00:28","slug":"infoblox-introduces-dns-threat-analytics","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2015\/12\/09\/infoblox-introduces-dns-threat-analytics\/","title":{"rendered":"Infoblox introduces DNS Threat &#8216;behavioural&#8217; Analytics"},"content":{"rendered":"<p>Infoblox has\u00a0introduced Infoblox DNS Threat Analytics, a technology that applies behavioural analytics to DNS queries in real time to detect and actively block data exfiltration attempts using DNS as a communications pathway; stealing proprietary information through DNS has recently become commonplace among cyber criminals.<\/p>\n<p>This growing problem is creating concern among enterprises and service providers:<\/p>\n<ul>\n<li>Nearly half (46%) of large businesses have experienced DNS-based data exfiltration and 45% experienced DNS tunnelling in the previous year, according to a December 2014 survey.<\/li>\n<li>According to a 2015 report, the average total cost of a data breach to an enterprise is $3.8 million, including forensic efforts, resolution, and the consequences of customer defection.<\/li>\n<li>A data breach at a major US health insurance company reported earlier this year could ultimately cost the firm more than $100 million.<\/li>\n<\/ul>\n<p>Domain Name System (DNS) queries are typically small packets of data that make a simple request: translating a domain name such as <a href=\"http:\/\/media.ne.cision.com\/l\/cyiaylsq\/www.infoblox.com\/\" target=\"_blank\">www.infoblox.com<\/a> into an Internet Protocol (IP) address such as 54.235.223.101 that computers and endpoints understand. However, cyber criminals have learned to exploit DNS to smuggle out an organisation\u2019s data<strong>\u2014<\/strong>including highly sensitive information such as trade secrets and customer credit card numbers.<\/p>\n<p>Infoblox DNS Threat Analytics examines outgoing DNS traffic for characteristics that are associated with data exfiltration attacks in real time. These characteristics include:<\/p>\n<ul>\n<li><strong>Size:<\/strong> The query is larger than normal, or contains more information than normal.<\/li>\n<li><strong>Encryption:<\/strong> The query contains encrypted data.<\/li>\n<li><strong>Timing:<\/strong> The query is being repeated at precise intervals, unlike the intermittent DNS requests initiated by humans.<\/li>\n<\/ul>\n<p>Traditional reputation-based and signature-based security<strong>\u2014<\/strong>already built into Infoblox DNS security appliances<strong>\u2014<\/strong>can already block known threats that have been identified by threat intelligence researchers. Infoblox DNS Threat Analytics goes a step further with its ability to automatically block so-called zero-day threats<strong>\u2014<\/strong>attacks that haven\u2019t yet been discovered<strong>\u2014<\/strong>after analysing DNS queries and spotting suspicious behaviour. There\u2019s no need to install additional software on end-user devices or to deploy additional devices in the data centre. Infoblox DNS Threat Analytics can scale to provide enforcement across the network and provide visibility into infected devices or rogue employees trying to steal data. Infoblox can also notify other security systems when threats are detected, accelerating remediation.<\/p>\n<p>\u201cFor the Golden Nugget, data security is paramount to our success as a business,\u201d said Shannon Provence, executive director of IT at Golden Nugget Hotel &amp; Casino in Las Vegas. \u201cWe see value in\u00a0Infoblox DNS Threat Analytics because it provides real-time streaming\u00a0analytics on DNS queries.\u00a0In our recent evaluation, the analytics helped us identify threat patterns\u00a0that were otherwise hard to detect\u00a0using alternate solutions. Infoblox DNS Threat Analytics gave us more visibility than we ever had before and allowed us to quickly identify, evaluate, and block suspicious DNS-based activity before it became an issue or caused data loss.\u201d<\/p>\n<p>The unique real-time analysis and detection capability in Infoblox DNS Threat Analytics works as queries are being processed. This is essential to fast identification of indicators of compromise (IOC). Other off-line approaches such as gathering mountains of log data and analyzing these files after the fact can take weeks to months<strong>\u2014<\/strong>which is unacceptable in todays\u2019 high-stakes security environments.<\/p>\n<p>\u201cMost firewalls and other security solutions don\u2019t examine or understand the structure of DNS queries, a vulnerability that hasn\u2019t escaped the attention of cybercriminals,\u201d said Scott Fulton, executive vice president of products at Infoblox. \u201cInfoblox DNS Threat Analytics continues our leadership in delivering innovations in DNS security and helps our customers close the door on DNS as a channel for data theft.\u201d    \t<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Infoblox has\u00a0introduced Infoblox DNS Threat Analytics, a technology that applies behavioural analytics to DNS queries in real time to detect and actively block data exfiltration attempts using DNS as a communications pathway; stealing proprietary information through DNS has recently become commonplace among cyber criminals. This growing problem is creating concern among enterprises and service providers: [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":4520,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[809,38],"tags":[112,317,177,113,10],"class_list":["post-4518","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-more-news","category-networking","tag-analytics","tag-dns","tag-infoblox","tag-networking-2","tag-security-2"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/4518","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=4518"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/4518\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/4520"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=4518"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=4518"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=4518"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}