Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Why Businesses Fail to Address DNS Security Exposures
Newest First  |  Oldest First  |  Threaded View
USEC
50%
50%
USEC,
User Rank: Apprentice
10/10/2019 | 11:41:34 AM
Source of Stats
Ronan - can you provide the source of the statistics in the article?
USEC
50%
50%
USEC,
User Rank: Apprentice
10/10/2019 | 11:40:20 AM
Source of stats
Ronan - love this article. I've read it probably 6 times since you posted it. So, thanks!

I wanted to ask for the data for for the statistics you mentioned, namely in the precentages year-over-year growth and of attack base. 

Thanks
RonanDavid
50%
50%
RonanDavid,
User Rank: Author
9/10/2019 | 12:09:10 PM
Re: I do think there needs to be more clarity as to how to address this problem

Thanks for your comment. The main purpose of the article is to shed some light on the DNS as a perfect tool to help increase security for enterprises. As part of the zero-trust approach, DNS can help in segmenting the application access and have a detailed view of the intent of user clients.

DNSSEC is effectively a good way to add integrity control on the DNS information transported. DNS over TLS would bring confidentiality at the transport level, but clients need to be updated first in the operating systems.

Flow analysis with advanced methods like neural networks or clustering is also an approach to look at. We at EfficientIP are investing a lot in these directions to increase our detection ability of bad domains (such as zero-day malicious domains or DGA) and non-conforming behavior of applications.

Trusting the DNS providers is probably not enough in the space of the enterprise. The distributed model of the DNS is not easy to centralize (nor a good option for Internet service continuity). Enterprises have not (and will not) moved all their workloads and data into cloud infrastructures- some require a higher level of control on their resources, some are not trusting providers for data security. Internal enterprise DNS is still a perfect way to increase security with filtering, segmenting the access to application and analyzing user behaviors. Feeding SIEM with events from the DNS, and some logs in special circumstances, provides a good way to enhance security for enterprise assets and data as a whole. This is the main purpose of security in IT.

tdsan
100%
0%
tdsan,
User Rank: Ninja
9/6/2019 | 4:30:22 PM
I do think there needs to be more clarity as to how to address this problem

Having a granular view of users and applications becomes a standard approach, not an exception. Almost all Internet connections are initiated through DNS, meaning DNS sees 95% of traffic going through the network. Analyzing the behavior of each user brings valuable data for detecting potential menaces hidden in the traffic. This surveillance of each client at such a detailed level is key to successful zero-trust strategy. Plus, administrators also should know the status of the network in real time at all times. 

Ok, this is good from a novice standpoint and it explains what we need from a 50K foot view, but how do we really solve the problem. Zero-trust strategy is good but how can you be Zero-Trust when data is coming from the internet that is constantly changing.

For me, there are a few things we did to help address this problem:
  • Implemented IPv6 to run in most if not all of our environment (enable AES256 VPN ESP/AH Connections to your offsite locations)
  • Implement DNSSEC as part of your DNS solution where keys are exchanged
  • Work with companies like Infobox to help address some of your issues
  • Implement ML as part of your cybersecurity strategy at the DNS and network layers

In addition, we need the DNS providers to come up with an IPv6 token based ML solution where the system puts the errant site in a black-list. this would help address 90% of the issues because the sites could be easily identified at all levels of the network because the token or SHA256 hash could be used to create an index (ex of hash - SHA256 F2A3E9E8B019D93818202BDF3AD362F4BAEC7C64589BC635B92E3A8DFD9AD391). This could be the index for Internet sites around the globe and the process can be associated with bad actors who are sending traffic using the 9 primary DNS sites, they could create a blacklist where the actors are stopped before submitting anything to the public.

T


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Enterprises are Attacking the Cybersecurity Problem
Concerns over supply chain vulnerabilities and attack visibility drove some significant changes in enterprise cybersecurity strategies over the past year. Dark Reading's 2021 Strategic Security Survey showed that many organizations are staying the course regarding the use of a mix of attack prevention and threat detection technologies and practices for dealing with cyber threats.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-41790
PUBLISHED: 2021-10-21
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 7.0.1.2. Script Action execution allows executing scripts uploaded outside of the Data Dictionary. This could allow a logged-in attacker to execute arbitrary code inside a sandboxed environment.
CVE-2021-41791
PUBLISHED: 2021-10-21
An issue was discovered in Hyland org.alfresco:share through 7.0.0.2 and org.alfresco:community-share through 7.0. An evasion of the XSS filter for HTML input validation in the Alfresco Share User Interface leads to stored XSS that could be exploited by an attacker (given that he has privileges on t...
CVE-2021-41792
PUBLISHED: 2021-10-21
An issue was discovered in Hyland org.alfresco:alfresco-content-services through 6.2.2.18 and org.alfresco:alfresco-transform-services through 1.3. A crafted HTML file, once uploaded, could trigger an unexpected request by the transformation engine. The response to the request is not available to th...
CVE-2021-23139
PUBLISHED: 2021-10-21
A null pointer vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an attacker to crash the CGI program on affected installations.
CVE-2021-42011
PUBLISHED: 2021-10-21
An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with escalated privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target syste...