IT attacks come in waves, with hackers picking up on trends like fashionistas spotting the latest clothes styles.
The latest is going after point of sales devices. Inevitably attackers will find another vulnerability, but for the time being thatโs one of the weakest vectors. IT security vendors are jumping to plug the holes.
The latest is Torontoโs BlueCat Networks, which makes IP address management solutions. On Wednesday it released Threatย Protectionย forย DNS/DHCPย Server, which the company creates a โDNS firewallโ that stopsย maliciousย activitiesย inย domain name serversย beforeย theyย canย reachย business-criticalย applicationsย orย data.
The software, which protects any device with a DNS address,ย canย be addedย toย existingย BlueCatย customersโย DNSย serversย orย canย beย purchasedย asย aย stand-aloneย solution.ย It canย alsoย beย integratedย withย security information and event management solutionsย includingย IBMย QRadarย andย HPย ArcSightย viaย pre-builtย connectors.
BlueCat said in a release that Threat Protection leveragesย coreย networkย servicesย toย addย aย newย layer ofย securityย acrossย allย connectedย devices.ย It can takeย actionย basedย onย up-to-the-minuteย dataย aboutย knownย sourcesย ofย maliciousย content through theย hostedย BlueCatย Securityย Feed.ย ย IT mangers can configureย policiesย toย allowย threatย requestsย toย beย blacklisted,ย black-holed,ย redirectedย or whitelisted.
Using DNS Zone Transfer, the DNS server will download security feed data to store locally on the server as a Response Policy Zone, BlueCat says. Updates are then downloaded periodically according to the refresh time of the BlueCat DNS Server Response Policy Zone. When a device attempts to connect to a malicious site, the DNS query occurs before the application request. This query signals the intent to connect and can expose unexpected or unwanted behaviors. Threat Protection can ๏ฌag the query and log the event. Base on policies set by administrators, the traffic can be held or released.
โTheย Domainย Nameย Systemย isย aย criticalย componentย ofย anyย defenseย in-depthย securityย strategy,โ BlueCat chief technology officer Andrew Werkin said in a statement.ย ย โThreatย Protectionย providesย additionalย valueย toย ourย customersย withoutย havingย toย purchaseย orย maintainย additionalย appliances.โ