{"id":9614,"date":"2016-06-20T09:20:19","date_gmt":"2016-06-20T09:20:19","guid":{"rendered":"http:\/\/www.intelligentcio.com\/me\/?p=9614"},"modified":"2016-06-20T09:20:19","modified_gmt":"2016-06-20T09:20:19","slug":"results-of-the-infoblox-security-assessment-report-1q2016","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2016\/06\/20\/results-of-the-infoblox-security-assessment-report-1q2016\/","title":{"rendered":"Results of the Infoblox Security Assessment report 1Q2016"},"content":{"rendered":"<p>Infoblox has announced results of the Infoblox Security Assessment Report for the first quarter of 2016, which finds that 83%\u2014more than four out of five\u2014of enterprise networks tested by Infoblox show evidence of malicious DNS activity.<\/p>\n<p>Infoblox offers free security assessments to customers and prospective customers, identifying DNS queries inside an organisation\u2019s network that are attempting to reach known malicious or suspicious domains. External threat data from these evaluations is anonymised and aggregated to produce the Infoblox Security Assessment Report.<\/p>\n<p>In the first quarter of 2016, 519 files capturing DNS traffic were uploaded to Infoblox for assessment, coming from 235 customers across a wide range of industries and geographies. Infoblox found 83% of the files showed evidence of suspicious DNS activity.<\/p>\n<p>\u201cThis result is consistent with what security professionals have been saying for some time: Perimeter defence is no longer sufficient, because almost all large enterprise networks have been compromised to a greater or lesser extent,\u201d said<em> Craig Sanderson, senior director of security products at Infoblox.<\/em> \u201cThe new mandate for enterprise security teams is to quickly discover and remediate threats inside the network, before they cause significant damage.\u201d<\/p>\n<p>The specific threats found in files during the first quarter, by percentage, are:<\/p>\n<ul>\n<li>Botnets \u2013 54%<\/li>\n<li>Protocol anomalies \u2013 54%<\/li>\n<li>DNS tunneling \u2013 18%<\/li>\n<li>ZeuS malware \u2013 17%<\/li>\n<li>Distributed denial of service (DDoS) traffic \u2013 15%<\/li>\n<li>CryptoLocker ransomware \u2013 13%<\/li>\n<li>Amplification and reflection traffic \u2013 12%<\/li>\n<li>Heartbleed \u2013 11%<\/li>\n<\/ul>\n<p>\u201cThe prevalence of these attacks shows the value of DNS in finding threats aimed at disrupting organisations and stealing valuable data, as well as the extent to which organisational infrastructure can be hijacked to mount attacks on third parties,\u201d said <em>Sanderson.<\/em> \u201cThe good news is that DNS is also a powerful enforcement point within the network. When suspicious DNS activity is detected, network administrators and security teams can use this information to quickly identify and remediate infected devices\u2014and can use DNS firewalling as well to prevent malware inside the network from communicating with command-and-control servers.\u201d<\/p>\n<p>The full Infoblox Security Assessment Report for the first quarter of 2016 is available at <a href=\"http:\/\/www.infoblox.com\/resources\/report\/infoblox-security-assessment-report-2016-q1\">www.infoblox.com\/resources\/report\/infoblox-security-assessment-report-2016-q1<\/a>. Organisations seeking a free Infoblox security assessment should visit <a href=\"http:\/\/www.infoblox.com\/free-malware-report\">www.infoblox.com\/free-malware-report<\/a>.    \t<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Infoblox has announced results of the Infoblox Security Assessment Report for the first quarter of 2016, which finds that 83%\u2014more than four out of five\u2014of enterprise networks tested by Infoblox show evidence of malicious DNS activity. Infoblox offers free security assessments to customers and prospective customers, identifying DNS queries inside an organisation\u2019s network that are [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":9615,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,54,13],"tags":[2420,1801,177,2421,2422,2423],"class_list":["post-9614","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-research","category-top-stories","tag-dns-network","tag-enterprise-network","tag-infoblox","tag-infoblox-security-assessment-report","tag-malicious-dns-activity","tag-suspicious-dns-activity"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/9614","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=9614"}],"version-history":[{"count":0,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/9614\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/9615"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=9614"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=9614"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=9614"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}