• >
  • >
  • >
  • >
  • >
Infoblox > 实例探究 > DNS Firewall Protects a Global U.S. Defense Network from Millions of Malicious Queries Every Day

DNS Firewall Protects a Global U.S. Defense Network from Millions of Malicious Queries Every Day

Infoblox Logo
公司规模
Large Corporate
地区
  • America
国家
  • United States
产品
  • Infoblox DNS Firewall
  • Infoblox 4010 appliances
技术栈
  • DNS Security
  • Malware Data Feeds
实施规模
  • Enterprise-wide Deployment
影响指标
  • Customer Satisfaction
技术
  • 网络安全和隐私 - 网络安全
  • 网络安全和隐私 - 安全合规
适用行业
  • 国家安全与国防
适用功能
  • 商业运营
用例
  • 入侵检测系统
服务
  • 系统集成
关于客户
This large federal U.S. defense agency is responsible for providing forces and resources for planning and conducting cyberspace operations and defending its own networks. With hundreds of thousands of uniformed and non-uniformed employees around the world, the organization relies on a secure and available network that links hundreds of bases globally. The agency's mission is critical, requiring robust cybersecurity measures to protect against a high volume of malicious network traffic and ensure compliance with regulatory mandates.
挑战
The organization was experiencing millions of events per day, some known to be malicious and others unexplained but originating from malicious IP spaces or destined for countries known for nefarious activity. The agency struggled to maintain blacklists due to the volume of bad traffic. An audit in 2011 revealed only basic abilities to identify sources of communications to malicious destinations, which could be identified at the base level but not at the device level. The agency needed to pinpoint the IP addresses of infected devices and comply with regulatory mandates to inject blacklisting feeds from other agencies.
解决方案
The agency, already equipped with an extensive Infoblox installation, enhanced its network security by installing 36 Infoblox 4010 appliances running Infoblox DNS Firewall at regional boundaries and Grid Masters. The DNS Firewall provides a feed for current malware data and prevents DNS-exploiting malware from communicating with botnets or exfiltrating sensitive information. This solution allows the agency to disrupt and redirect outbound communications with command-and-control servers and botnets to internal servers for analysis. Additionally, malware data feeds from other agencies can be incorporated into the DNS Firewall feed for blocking, and already-infected devices can be identified and quarantined or remediated.
运营影响
  • The DNS Firewall helps pinpoint infected devices within the network, allowing for targeted remediation.
  • It prevents communications to malicious domains, enhancing the overall security posture of the agency.
  • The solution adds accurate and current malware data to blacklists, improving the agency's ability to block threats.
  • Outbound communications with command-and-control servers and botnets are disrupted and redirected for analysis.
  • Malware data feeds from other agencies are incorporated into the DNS Firewall feed, enhancing threat detection capabilities.
数量效益
  • 36 Infoblox 4010 appliances were installed across the network.
  • The agency's network spans hundreds of bases globally, requiring enterprise-wide deployment.

Case Study missing?

Start adding your own!

Register with your work email and create a new case study profile for your business.

Add New Record

相关案例.

联系我们

欢迎与我们交流!
* Required
* Required
* Required
* Invalid email address
提交此表单,即表示您同意 Asia Growth Partners 可以与您联系并分享洞察和营销信息。
不,谢谢,我不想收到来自 Asia Growth Partners 的任何营销电子邮件。
提交

感谢您的信息!
我们会很快与你取得联系。