Cyber SecurityRemote WorkRemote Working

DNS Protection – Why Firewalls Aren’t Enough

DNS Protection – Why Firewalls Aren’t Enough

DNS Protection - Why Firewalls Aren’t Enough

Delivering cyber resilience for businesses and other organisations requires a multifaceted cybersecurity strategy. The protections need to cover identity access & management, endpoints, malware defences, robust network edge protection via firewalls and intrusion systems, and many other technological and training based protections. The technology and people-focused security techniques combine into an overall strategy that prevents attacks from succeeding and allows for rapid detection and recovery if defences are breached.

This is especially true for MSPs who are providing security and other services to their clients. They have the issue of protecting multiple organisations.

DNS Infrastructure is Key

One aspect of the overall security landscape that is often overlooked is the protection of DNS infrastructure. DNS (Domain Name System) is the core 'contacts database' for the Internet. It translates human-friendly domain names (such as https://www.renaissance.ie) into network and machine-friendly numerical IP addresses that nodes on the internet use to locate each other and communicate.

Requests from servers and endpoints to translate domain names into IP addresses are passed to a DNS server that returns the IP address and other relevant information. The originating node then uses this IP address to set up a communication session with the target server or device. That's a simplification, but the details of DNS are not relevant to this article. What is relevant is that DNS traffic has now become a target for cybercriminals.

Traditionally DNS request traffic has not been encrypted. Cybercriminals are always searching for ways to bypass protections. ICANN, the organisation that controls and manages the root DNS infrastructure for the Internet, issued public advisories that show DNS is facing an "ongoing and significant risk". They urged domain name owners and DNS service providers to move to secure DNS transactions as soon as possible.

DNS Attacks

Attacks against DNS infrastructure are on the rise. A global 2018 survey carried out by EfficientIP reported that 77% of organisations surveyed had a DNS attack in the previous 12-month period.

The open nature of DNS means that it has attracted multiple attack types. These can range from hacking into DNS servers to change IP address records to point to criminals’ servers, or intercepting unencrypted DNS data on a network and tampering with it before passing back modified DNS responses that direct connections to malicious servers. All DNS hijacking and man-in-the-middle attacks aim to give criminals access to login details, email data, or other sensitive information. Cybercriminals have realised it's easier to compromise DNS records and traffic than to penetrate other defences or use Phishing to get information.

This means that the days of treating DNS as a ‘commodity part of the IT landscape that just does its thing in the background’ are over. Like every other aspect of IT provision, DNS needs to be protected.

Webroot DNS Protection

Webroot DNS Protection is a cloud-based DNS security service that provides comprehensive DNS traffic protection for all network node types without deploying and maintaining additional security hardware. By redirecting web traffic through a cloud-based DNS security solution, businesses and MSPs can stop DNS threats at the edge before they hit the network or endpoints. It complements firewalls and other network perimeter security to deliver maximal protection.

Webroot DNS Protection is easy to deploy, has a low management overhead, and it is future-proofed as it uses DNS over HTTPS (DoH) and supports IPv6 (the next version of IP that is slowly gaining traction). Some top-level features of Webroot DNS Protection include:

  • Cloud-based deployment - nothing to setup onsite. Simply redirect your DNS traffic to the cloud service and have encrypted DNS protection in minutes.
  • Block threat categories - over 80 groups of site types are available to be allowed or blocked. For example, known threats from sites that distribute malware can be blocked. Connection requests trying to reach them will not get a valid IP address returned, and a connection won't be established. This can also prevent installed malware from extricating data before it triggers ransomware encryption.
  • Reduce costs - Webroot DNS filtering stops known malware at the domain layer, so it never reaches your network. It saves you time and money while also minimising unproductive web usage.
  • Control Internet access - allow access for your users using pre-configured and custom policies by group, device or network address.
  • Comprehensive reporting - use drill-down reports to see all threats the business would have been susceptible to without having DNS Protection in place. Also get complete visibility into risk and usage.

Join us for a Webroot DNS Protection Webinar

Webroot and Renaissance will be hosting a Webinar on Thursday the 13th of May to outline and discuss DNS threats and how Webroot DNS Protection can mitigate them. Join us by registering for the webinar here. If you want to find out more about Webroot DNS Protection in the interim, see the product brief page or contact Renaissance.