39:51Threat Intelligence and DNS for Rapid Cybersecurity Incident Response
Download resourcesAbout this session
Michael Katz, a security sales specialist at Infoblox, and Marc Bourget, a Montreal-based systems engineer, make the case that DNS is an underused source of threat intelligence and a dangerous, overlooked exfiltration channel. Katz opens with the top DNS security mistakes he sees, such as starting DNS security in the cloud, ignoring the DNS system, not logging queries and running wide-open open-source DNS, then argues that DNS, DHCP and IP address management (DDI) should anchor cyber strategy across identify, protect, detect and respond. He explains response policy zones as a mature, scalable way to carry threat intelligence (tens of millions of indicators with negligible performance cost) and eDNS0 as a way to preserve client source information in queries, and stresses feeding DNS logs to the SIEM. Bourget then demonstrates how easily data leaves over DNS: encoding a file, chunking it and sending it as ordinary DNS requests to an external server that reassembles it, and describes DNS tunnelling tools like Iodine that most next-generation firewalls only partially detect by signature.
DNS is one of the only foundational IT services with threat intelligence built into the standard. Despite this fact, even advanced cyberteams are not taking advantage of the tremendous capabilities DNS offers to detect and respond to threats. In this discussion, Infoblox will demonstrate how to perform threat detection and rapid response with DNS and why your current DNS infrastructure is susceptible to cybercriminals.
Key takeaways
- Start DNS security inside your perimeter, log DNS queries, and stop running wide-open open-source DNS in critical spots; the DNS system itself must be part of your DNS security.
- Use response policy zones to carry threat intelligence in DNS at scale, blocking, redirecting or log-only on tens of millions of indicators with minimal performance impact.
- Deploy eDNS0 so DNS queries preserve the client IP and MAC, giving fully correlated alerts instead of losing the source as queries recurse.
- Feed DNS logs (at least the response log) to the SIEM and make sure the SIEM team actually has DNS security alerts turned on.
- Watch for data exfiltration and tunnelling over DNS: any record type can smuggle chunked data out, and signature-only firewall DNS checks miss many tunnelling tools.

