166 terms · 75/46/45
Defense № 029 · class: resilience

DNS Security

DNS security encompasses technologies that protect DNS infrastructure and use DNS traffic as a control point for blocking access to malicious domains and detecting suspicious communications.

Term

description · examples · notes

DNS security encompasses technologies that protect DNS infrastructure and use DNS traffic as a control point for blocking access to malicious domains and detecting suspicious communications.

Description

DNS filtering can block access to known malicious domains, phishing sites, and command-and-control servers before a connection is established. DNS traffic analysis can reveal tunneling and data exfiltration via DNS queries.

This technology provides broad coverage because nearly all network traffic depends on DNS resolution, making it an effective point for enforcing security policies.

What people often say

  • DNS security only protects against phishing.
  • Changing the DNS server automatically provides full protection.

Covers / does not cover

Covers

  • Blocking access to known malicious domains
  • Detection of DNS tunneling and data exfiltration via DNS
  • Protection against user redirection to fake sites
  • Reducing the risk of malware communicating with command servers

Does not cover

  • Encrypted traffic that does not pass through the DNS control point
  • Attacks that do not use DNS for communication
  • Abuse of legitimate domains for malicious purposes
Composite

Threats

reduces 6

Techniques

neutralizes 8