1 2013 Infoblox Inc. All Rights Reserved. Securing the critical service - DNS



Similar documents
Securing Your Business with DNS Servers That Protect Themselves

Securing Your Business with DNS Servers That Protect Themselves

Infoblox Inc. All Rights Reserved. Talks about DNS: architectures & security

Protecting DNS Infrastructure Inside and Out

STARTER KIT. Infoblox DNS Firewall for FireEye

Defend Your Network with DNS Defeat Malware and Botnet Infections with a DNS Firewall

WHITEPAPER. Designing a Secure DNS Architecture

Enhancing Your Network Security

TECHNICAL WHITE PAPER. Infoblox and the Relationship between DNS and Active Directory

Load Balancing Security Gateways WHITE PAPER

Detect Malware and APTs with DNS Firewall Virtual Evaluation

Defend Your Network with DNS Defeat Malware and Botnet Infections with a DNS Firewall

How To Protect A Dns Authority Server From A Flood Attack

The F5 Intelligent DNS Scale Reference Architecture.

IxLoad-Attack: Network Security Testing

Cloud Security In Your Contingency Plans

Arbor s Solution for ISP

Availability Digest. Prolexic a DDoS Mitigation Service Provider April 2013

Scale your DNS Infrastructure Ensure App and Service Availability. Nigel Ashworth Solution Architect EMEA

2012 Infrastructure Security Report. 8th Annual Edition Kleber Carriello Consulting Engineer

WHITE PAPER. Creating a Best-of-Breed DDI Solution in a Microsoft Environment

The Hillstone and Trend Micro Joint Solution

DDoS Protection on the Security Gateway

Concierge SIEM Reporting Overview

Websense Web Security Solutions. Websense Web Security Gateway Websense Web Security Websense Web Filter Websense Express Websense Hosted Web Security

VALIDATING DDoS THREAT PROTECTION

SHARE THIS WHITEPAPER. Top Selection Criteria for an Anti-DDoS Solution Whitepaper

DDoS Threat Report. Chris Beal Chief Security Architect on Twitter

Top Five DNS Security Attack Risks and How to Avoid Them

Comprehensive Malware Detection with SecurityCenter Continuous View and Nessus. February 3, 2015 (Revision 4)

Technical Note. ForeScout CounterACT: Virtual Firewall

DDoS Attacks: The Latest Threat to Availability. Dr. Bill Highleyman Managing Editor Availability Digest

F5 Intelligent DNS Scale. Philippe Bogaerts Senior Field Systems Engineer mailto: Mob.:

Automated Mitigation of the Largest and Smartest DDoS Attacks

Protecting DNS Critical Infrastructure Solution Overview. Radware Attack Mitigation System (AMS) - Whitepaper

SonicWALL Unified Threat Management. Alvin Mann April 2009

Cisco RSA Announcement Update

Distributed Denial of Service (DDoS) attacks. Imminent danger for financial systems. Tata Communications Arbor Networks.

Protecting the Infrastructure: Symantec Web Gateway

Networking for Caribbean Development

Infoblox vnios Software for CISCO AXP

Sikkerhet Network Protector SDN app Geir Åge Leirvik HP Networking

Enterprise Buyer Guide

Business Case for a DDoS Consolidated Solution

1. Introduction. 2. DoS/DDoS. MilsVPN DoS/DDoS and ISP. 2.1 What is DoS/DDoS? 2.2 What is SYN Flooding?

Chapter 8 Security Pt 2

Guide to DDoS Attacks December 2014 Authored by: Lee Myers, SOC Analyst

Infoblox Grid TM. Automated Network Control for. Unifying DNS Management and Extending the Infoblox Grid TM to the F5 Global Traffic Manager

How valuable DDoS mitigation hardware is for Layer 7 Sophisticated attacks

WHITE PAPER. FortiGate DoS Protection Block Malicious Traffic Before It Affects Critical Applications and Systems

Protect your network: planning for (DDoS), Distributed Denial of Service attacks

How To Make A Cloud Bursting System Work For A Business

Reduce Your Network's Attack Surface

Security F5 SECURITY SOLUTION GUIDE

SANS Top 20 Critical Controls for Effective Cyber Defense

Are You Fully Prepared to Withstand DNS Attacks?

Websense Web Security Solutions. Websense Web Security Gateway Websense Web Security Websense Web Filter Websense Hosted Web Security

Load Balancing and Sessions. C. Kopparapu, Load Balancing Servers, Firewalls and Caches. Wiley, 2002.

SHARE THIS WHITEPAPER. On-Premise, Cloud or Hybrid? Approaches to Mitigate DDoS Attacks Whitepaper

Cisco Security Intelligence Operations

DNS Security: New Threats, Immediate Responses, Long Term Outlook Infoblox Inc. All Rights Reserved.

Application centric Datacenter Management. Ralf Brünig, F5 Networks GmbH Field Systems Engineer March 2014

Microsoft SharePoint 2013 with Citrix NetScaler

Stop DDoS Attacks in Minutes

INTRODUCTION TO FIREWALL SECURITY

DNS Firewalls with BIND: ISC RPZ and the IID Approach. Tuesday, 26 June 2012

On-Premises DDoS Mitigation for the Enterprise

Technology Blueprint. Protect Your . Get strong security despite increasing volumes, threats, and green requirements

How To Block A Ddos Attack On A Network With A Firewall

SECURITY ANALYTICS MOVES TO REAL-TIME PROTECTION

Protecting against DoS/DDoS Attacks with FortiWeb Web Application Firewall

Next Generation IPS and Reputation Services

Firewalls and Intrusion Detection

STOPPING LAYER 7 ATTACKS with F5 ASM. Sven Müller Security Solution Architect

Citrix NetScaler and Microsoft SharePoint 2013 Hybrid Deployment Guide

White Paper A10 Thunder and AX Series Load Balancing Security Gateways

Datacenter Transformation

Firewall Firewall August, 2003

How To Monitor Network Activity On Palo Alto Network On Pnetorama On A Pcosa.Com (For Free)

Complete Protection against Evolving DDoS Threats

Analyzing HTTP/HTTPS Traffic Logs

Monitor Network Activity

Attackers are highly skilled, persistent, and very motivated at finding and exploiting new vectors. Microsoft Confidential for internal use only

Gateway Security at Stateful Inspection/Application Proxy

How To Stop A Malicious Dns Attack On A Domain Name Server (Dns) From Being Spoofed (Dnt) On A Network (Networking) On An Ip Address (Ip Address) On Your Ip Address On A Pc Or Ip Address

V-ISA Reputation Mechanism, Enabling Precise Defense against New DDoS Attacks

Swordfish

Transcription:

1 2013 Infoblox Inc. All Rights Reserved. Securing the critical service - DNS Dominic Stahl Systems Engineer Central Europe 11.3.2014

Agenda Preface Advanced DNS Protection DDOS DNS Firewall dynamic Blacklisting High Performance DNS Caching DNSSEC 2 2013 Infoblox Inc. All Rights Reserved.

3 2013 Infoblox Inc. All Rights Reserved. Preface

The Problem DNS-based attacks are on the rise Traditional protection is ineffective against evolving threats DNS outage causes network downtime, loss of revenue, and negative brand impact Unprotected DNS infrastructure introduces security risks 4 4 2013 Infoblox Inc. All Rights Reserved.

Why is DNS an Ideal Attack Target? DNS is the cornerstone of the Internet, used by every business and government DNS protocol is stateless and hence vulnerable DNS as a protocol is easy to exploit Maximum impact with minimum effort 5 5 2013 Infoblox Inc. All Rights Reserved.

Advanced DNS Protection - DDOS 6 2013 Infoblox Inc. All Rights Reserved.

2013 DNS Threat is Significant Attacks against DNS infrastructure growing DNS-specific attacks up 200% in 2012 ICMP, SYN, UDP attacks growing significantly too DNS is #2 attack vector protocol HTTP 87% DNS 67% SMTP 25% HTTPS 24% SIP/VOIP 19% IRC 11% Other 7% 0% 20% 40% 60% 80% 100% Source: Arbor Networks Infrastructure Layer: 76.52% ACK: 1.69% CHARGEN: 3.37% FIN PUSH: 0.39% DNS: 8.94% ICMP: 11.41% RESET: 1.94% RIP: 0.13% RP: 0.39% SYN: 18.16% SYN PUSH: 0.13% TCP FRAGMENT: 0.65% UDP FLOODS: 14.66% UDP FRAGMENT: 14.66% Source: Prolexic Quarterly Global DDoS Attack Report Q3 2013 7 2013 Infoblox Inc. All Rights Reserved.

The Solution - Infoblox Advanced DNS Protection Unique Detection and Mitigation Intelligently distinguishes legitimate DNS traffic from attack traffic like DDoS, DNS exploits, tunneling Mitigates attacks by dropping malicious traffic and responding to legitimate DNS requests Centralized Visibility Centralized view of all attacks happening across the network through detailed reports Intelligence needed to take action Ongoing Protection Against Evolving Threats Regular automatic threat-rule updates based on threat analysis and research Helps mitigate attacks sooner vs. waiting for patch updates 8 2013 Infoblox Inc. All Rights Reserved.

Solution Components Infoblox Advanced DNS Protection Service Advanced DNS Protection activation Automatic updates for protection against new and evolving threats Support and Maintenance Infoblox Advanced Appliance PT-1400, PT-2200, PT-4000 DNS appliance purpose built with security in mind Enhanced processing and dedicated compute for threat mitigation Note: Customers who have IB-4030 Rev2 need to purchase a separate Adv. DNS Protection license. 9 9 2013 Infoblox Inc. All Rights Reserved.

Security Built-in to the DNS Infrastructure Use Cases Internet Enterprise Customers External authoritative DNS server Security Protection against all DNS threats Internal DNS- Enterprise / Universities with open networks DNS Server Standard Appliances DNS Server Advanced Appliances Serve DNS queries under attack Service Providers Recursive Caching Authoritative DNS services Traditional security appliances mitigate only partial attacks against DNS 10 2013 Infoblox Inc. All Rights Reserved.

Data for Reports Legitimate Traffic Fully Integrated into Infoblox Grid Infoblox Threat-rule Server Automatic updates New Block DNS attacks Infoblox Advanced DNS Protection (External Auth.) GRID Master New Infoblox Advanced DNS Protection (Internal Recursive) Reporting Server Reports on attack types, severity 11 2013 Infoblox Inc. All Rights Reserved.

Centralized Visibility: Reporting Intelligence Needed to Take Action Attack details by category, member, rule, severity, and time Visibility into source of attacks for blocking, to understand scope and severity Early identification and isolation of issues for corrective action 13 2013 Infoblox Inc. All Rights Reserved.

Service Providers Protection against attacks on caching and authoritative servers Authoritative DNS + DNS Caching (PT-4000) DNS Caching only (IB-4030) 1M qps 14 2013 Infoblox Inc. All Rights Reserved.

Advanced Appliances Come in Three Physical Platforms Advanced Appliances have next-generation programmable processors that provide dedicated compute for threat mitigation. The appliances offer both AC and DC power supply options. 15 2013 Infoblox Inc. All Rights Reserved.

DNS Firewall + FireEye Adapter 16 2013 Infoblox Inc. All Rights Reserved.

Conventional DNS - Security Gap in your network email Web Video Data Chat VoIP Malicious domain look-up Security infrastructure (Firewall, IPS/IDS, web gateway)! Conventional DNS Malware depends on DNS Protocol to find home Most often domain name is the only information available to identify malicious activity 17 2013 Infoblox Inc. All Rights Reserved.

How does the DNS Firewall work? Redirect 4 Infected Client Landing Page / Walled Garden Malicious link to www.badsite.com 3 5 Contact botnet Infoblox DNS Firewall / Recursive DNS Server 2 Dynamic Grid-Wide Policy Distribution Apply Policy Block / Disallow session 1 Dynamic Policy Update Infoblox DNS Firewall / Recursive DNS Server Malware Data Feed from Infoblox Infoblox DNS Firewall / Recursive DNS Server 6 Write to Syslog and send to Trinzic Reporting 18 2013 Infoblox Inc. All Rights Reserved. 18

Infoblox DNS Firewall Subscription Service Infoblox DNS Firewall / Recursive DNS Server Malware Droppers C&C + Botnet / DNS Servers 35+ sources (Public & Private) worldwide Inbound Attacks Correlation/compilation: Domains / URL s / IP s with bad reputation. Pushed every 2 hours via DNS NOTIFY Geographic Blocks Internal Black list RPZ can be acted upon 1st before hitting DNS Reputation RPZ 19 2013 Infoblox Inc. All Rights Reserved.

DNS Firewall - FireEye Adapter Rogue Portals 1 C & C / Proxy Portal IP s FireEye Compromised Web Server or Domain DNS Server W/ DNS Firewall 13.13.13.13 12.12.12.13. INTERNET INTRANET Block / Re-direct DNS Query 2 3 4 Play Malware Attack Detects & detonates advanced malware Infoblox Reporting Server ID infected device by IP, MAC address & device type for remediation Infected Enterprise End-point Malware / apps Initiate DNS requests for web domains 20 2013 Infoblox Inc. All Rights Reserved.

DNS Firewall - FireEye Adapter Reporting FireEye Alerts Date/Time Alert# Log Severity Type Visibility into traffic DNS Firewall is tracking & blocking 21 2013 Infoblox Inc. All Rights Reserved.

DNS Firewall - Reporting that drives remediation Identify device by IP Address, MAC Address, Host name, and Device Type. Security Policy Violations Report 22 2013 Infoblox Inc. All Rights Reserved.

DNS Firewall vs. other DDI vendors email Web Video Data Malicious domain Look-up Security infrastructure (Firewall, IPS/IDS, Web Gateway) Chat VoIP Complete solution vs. feature Pinpoint device by IP / MAC / Type Malware Data Feed Service Integrated reporting & IPAM vs. DIY log searches/correlation DNS-specific/expert-generated reputational feed vs. DIY ( Go fish! ) 23 2013 Infoblox Inc. All Rights Reserved.

High Performance DNS Caching 24 2013 Infoblox Inc. All Rights Reserved.

Introducing the Infoblox 4030 World s Most Manageable, Secure, and Scalable DNS Caching Device Carrier-grade appliance targeted to Service Providers Over 1M DNS Queries per second per appliance High performance, ruggedized server platform Optional AC or DC power Hot-swappable Power Supplies, Fan, RAID Disk Drives 25 2013 Infoblox Inc. All Rights Reserved.

26 2013 Infoblox Inc. All Rights Reserved. DNSSEC

The Infoblox DNSSEC Solution Makes the process of deploying and managing DNSSEC as simple as possible Single-click configuration Automatic and on-the-fly key generation and management Uses the latest technology and protocol features BIND 9.7.x with NSEC3 support HSM Module available for Safenet and Thales 27 2013 Infoblox Inc. All Rights Reserved.

Infoblox the Company 28 2013 Infoblox Inc. All Rights Reserved.

Infoblox Global Support Instant and hi-quality technical support 4 major Tech Support Centers around the globe with 24x7 coverage Santa Clara, United States Antwerp, Belgium Trivandrum, India Tokyo, Japan Multi-language support including Dutch, French, German, Japanese, Chinese, Korean, and Spanish 800+ Infoblox devices in our Santa Clara HQ lab Santa Clara Amsterdam Australia Hong Kong Nine global depots for NBD replacement Singapore Japan Indian China Canada 29 2013 Infoblox Inc. All Rights Reserved.

Infoblox is a Pioneer and Market Leader Pioneered Core Network Services Appliances: World s first DNS, DHCP and IPAM appliances 700+ employees with headquarters in Santa Clara, CA Offices/Partners in over 30 countries 4 TAC centers with 24/7 global support More than 6700 customers More than 35% of the Fortune 500 companies 55.000+ appliances shipped 30 30 2013 Infoblox Inc. All Rights Reserved.

Market Leaders Choose Infoblox 6,000+ Global Customers Telecom Retail Manufacturing Media and Internet Transportation Government Life Sciences Financial Services Education Energy Infoblox Alliance Partners 31 2013 Infoblox Inc. All Rights Reserved.

32 2013 Infoblox Inc. All Rights Reserved. Q&A