Ignore DNS at your Peril

Learn more from Mathew Chase’s webinar on how busy IT executives can leverage DNS or read his thoughts on cybersecurity in our Cybersecurity Spotlight series.

It’s easy to ignore DNS.

Microsoft in particular has made it so. Microsoft DNS automatically deploys in the Active Directory environment, so you set up your servers and forget about it. And 90 percent of the time, it works.

But ‘90 percent of the time’ in a high-functioning IT organization is a horrible metric. When you actually do something important that is truly reliant upon DNS or DHCP, like run a call center, something that works 90 percent of the time is a huge problem.

DNS is the fundamental backplane of your network. It’s how everyone inside your organization accesses resources in and outside your network. All of your applications that have to talk to each other rely upon it. In complicated load balancing scenarios on a global network, DNS is crucial. And let’s not forget this important point: Active Directory doesn’t function without DNS. Period. All of your authentication systems for Microsoft components are built on underlying DNS records.

The people who have often best understood and paid attention to DNS are, unfortunately, primarily on the other side of the fence – hackers. In the early days, DNS was the quick way to conduct reconnaissance to map networks and identify hostnames and prime targets on a network. For many network administrators, DNS is just a means to an end: ‘I put in my DNS server and I’m done.’ That’s where their understanding of it frequently stops.

Ignoring DNS is something you do at your own peril.

When properly administered and configured, DNS yields very good information. It tells us what’s happening, where people are going and what they’re doing. In modern cybersecurity environments, we’re always concerned about a bad actor on our network. How do we determine when people are either compromised or acting in a way that is uncommon for them to act? DNS can provide valuable clues.

Every malicious web address starts with a DNS request. DNS firewalls are exceptionally good at disrupting these queries, whether through a threat feed or custom-built policies. DNS-based security also allows for visibility into the IP address space and DHCP, allowing network administrators to see who’s requesting IP addresses on the network and where they’re going with them.

Of course, any addition to the security stack begs the question of how it will be managed. Is the new solution going to take more people? How much more money is it going to cost me? And what’s my return on investment? Good solutions that can solve problems at a network level, and don’t require a lot of end user configuration, can really help improve your security posture. DNS, DHCP, and IP address management enterprise solutions provide that, along with all the reliability and redundancy required in stable operations. But from a security perspective, you gain network layer defenses with almost no impact to end users. The cost of administration to security benefit has always weighed in my favor.

Mathew Chase

Mathew most recently was vice president of IT for Inovalon, which provides cloud-based platforms and data analytics for the healthcare industry. He has deep experience with DNS and its implications for cybersecurity and other digital transformation initiatives. He got his start in IT in the mid-90’s at the Las Vegas Review-Journal, when he was pulled off his desktop publishing shift to help the newsroom become one of the first in the U.S. to produce their paper electronically. Career highlights include the IT operations manager for resident shows at Cirque du Soleil and the CIO for a U.S. government health insurance commission.


An avatar of the author

BlueCat provides core services and solutions that help our customers and their teams deliver change-ready networks. With BlueCat, organizations can build reliable, secure, and agile mission-critical networks that can support transformation initiatives such as cloud adoption and automation. BlueCat’s growing portfolio includes services and solutions for automated and unified DDI management, network security, multicloud management, and network observability and health.

Related content

Micetro 11.1 boosts DHCP management for Cisco Meraki SD-WAN

Learn how BlueCat Micetro 11.1 can help you overcome the limitations of Cisco Meraki SD-WAN devices to manage your distributed DHCP architecture.

Read more
Banner announcing BlueCat's acquisition of LiveAction, displaying both logos and the phrase "We're about to get bigger."

BlueCat acquires LiveAction to drive network modernization and optimization

BlueCat’s acquisition of LiveAction will allow customers to expand their view beyond DNS and dive deeper into the health of their network.

Read more

Simplify NIS2 compliance with DNS management

Learn whether the EU’s NIS2 requirements apply to your organization and about how DNS management and BlueCat can boost your path to compliance.

Read more

Detect anomalies and CVE risks with Infrastructure Assurance 8.4 

The Infrastructure Assurance 8.4 release features an anomaly detection engine for outliers and a CVE analysis engine to uncover device vulnerabilities.

Read more

Unlock the secrets to modernizing your IT network! Join our webinar on January 23 to learn how self-service DNS and DHCP can help you solve the cloud puzzle.