What BlueCat learned from five billion DNS queries 

BlueCat’s 2020 Networking Trends Report illustrates how CIOs can use DNS data to uncover efficiencies, minimize threats, and improve customer experience.

people in london
Key takeawaysThis key takeaway was generated through LLMs crawling the page and coming up with an overview of the content.

The article explains how CIOs and NetOps must leverage DNS data to support digital transformation by improving performance, security, and operational efficiency. Using analysis of over five billion DNS queries across North America and Asia, BlueCat’s 2020 Networking Trends Report shows DNS visibility can reveal application and cloud usage, identify degraded query resolution paths that add latency and WAN cost, and inform security policies. Key outcomes include optimized routing to reduce WAN costs and latency, richer business-focused KPIs for service delivery, and a cross-functional approach that aligns NetOps, security, and DevOps around DNS as a critical telemetry source.

How can DNS data help NetOps teams optimize network performance?

DNS data provides visibility into query patterns, resolution paths, and application or cloud service usage that NetOps teams can use to detect performance degradation and identify root causes. By analyzing where queries are routed and whether resolution paths are suboptimal — for example routing to a distant external resolver instead of a local path — teams can reconfigure routing to reduce latency and internal network load. The article cites a customer that redirected traffic from an external trusted service directly to the internet, cutting WAN costs and improving user experience. DNS insights also enable measuring adoption and ROI for cloud and application services.

What security benefits does periodic DNS traffic analysis provide?

Periodic analysis of DNS traffic, particularly internal DNS traffic, can surface indicators of malicious activity and other threats that may not be visible through other telemetry. DNS often contains contextual information threat hunters and security operators need for focused response, enabling targeted security policies to lock down critical systems. The article emphasizes that network teams typically collect and analyze DNS data, so a collaborative, cross-functional approach with security teams is required to map DNS findings against business requirements and translate them into effective containment and prevention policies.

What operational changes and KPIs should organizations consider when using DNS as a strategic asset?

Organizations should expand KPIs beyond legacy metrics like uptime and latency to include service-delivery and business-focused metrics derived from DNS data, such as application adoption, cloud service usage levels, and user behavior signals. DNS-derived metrics help quantify the NetOps team’s contribution to delivering services and improving customer experience, enabling measurement of ROI. Operationally, teams should develop cross-functional workflows so DNS data informs security, DevOps, and network decisions, and they should proactively optimize DNS resolution paths to reduce latency, lower WAN costs, and maintain the speed and agility demanded by business operations.

More than ever, CIOs are called to be more than just the heads of technology. They drive business initiatives by delivering services and applications.

These changes impact networking professionals as well. It forces them to deal with a much more complex network environment and a growing emphasis on speed and agility. To empower digital transformation, NetOps teams and CIOs need to find new ways to use data about the network at their disposal. With that information, they can optimize operations and improve network performance.

DNS data: An untapped resource

BlueCat’s 2020 Networking Trends Report illustrates how CIOs can use DNS data to uncover potential efficiencies, minimize security threats, and improve overall customer experience. The report analyzes more than five billion DNS queries spanning North America and Asia. When taken together, these queries provide visibility into network activity that can be used to find cost savings and operational efficiencies.

Here are some of the key recommendations and conclusions from the report:

Optimize performance with insights from DNS: With visibility into DNS queries, IT teams can discover network and query performance degradation, identify root cause, and speed up remediation. It allows organizations to gain meaningful insights into application and cloud service usage levels, to better understand user adoption and behaviors, and measure ROI.

Change KPIs of network performance: Legacy metrics such as uptime and latency are still relevant. But service delivery is a growing focus as IT departments move toward new business models. In this context, DNS data offers a wide range of meaningful business metrics that can assess the value of a NetOps team in delivering services.

Develop a cross-functional approach: DNS data often holds the context that threat hunters and security operators need for a smart, focused response to malicious activity. The ability to collect and analyze that data often originates with the network team, however. A collaborative, cross-departmental approach is required to truly reap the rewards of this valuable data set.

Leverage DNS data for security policies: Periodic analysis of DNS traffic (and internal DNS traffic in particular) can uncover significant threats to network security. That traffic should inform targeted security policies to lock down critical systems. Only by digging into the data and mapping it against business requirements can you discover how it can best serve network security in your particular context.

Tactical lessons

At a tactical level, BlueCat’s analysis revealed many insights that network teams can use to optimize performance and improve security.

Failure to optimize DNS query resolution paths

For example, BlueCat found that many organizations fail to optimize DNS query resolution paths. This adds significant latency to each query and unnecessary load to internal networks. The result is poor end-user experience, as queries are routed to a local external service that may actually be half a world away in the company’s primary data center.

One BlueCat customer found that 80% of all network traffic was being routed to external trusted services. They began routing it directly to the internet instead. As a result, they were able to optimally route network traffic, save on WAN costs, and improve user experience.

Leveraging DNS to improve network visibility

DNS can also be leveraged to improve network visibility. BlueCat’s researchers uncovered information surrounding cloud and application usage rates as well as what activities customers’ employees are performing online. Of the queries for non-business-related websites, roughly 54% of these domains were from social media sites. More than a quarter of the domains were for news sites.

When broken down by vertical, there were some noticeable differences. The education sector, for example, had higher use of social media than other sectors (accounting for nearly 61% of the vertical’s non-business activity). This same level of visibility can be used to determine what services and applications employees are using. In addition to determining worker productivity, knowing how regularly employees are using certain applications and services can help organizations uncover areas to improve for efficiencies and cost savings.

Driving NetOps 2.0

DNS underlies every action across the enterprise. It is a critical point of leverage for network administrators as they look to find their place in this new IT landscape. Using the right metrics and the right technology, NetOps teams can make DNS the common thread between security and DevOps teams. And it can help organizations maintain the speed and agility business operations demand.


Published in:


An avatar of the author

Mark is a Senior Product Marketing Manager at BlueCat Networks.

Related content

Close-up of interlocked metal chain links symbolizing connected network objects and relationships in IPAM

How to map your network with user-defined links in Integrity X

Map your network with user-defined links in Integrity X to define and manage custom relationships, such as dual-stack and NAT environments.

Read more
Flock of geese flying in formation across a blue sky, framed by a pink graphic border, symbolizing coordinated network migrat

Automate your DDI modernization path by migrating with Micetro

Automate cross-platform DNS and DHCP migration with Micetro to reduce risk, eliminate manual effort, and modernize infrastructure faster.

Read more
Three armored figures walking toward a futuristic Las Vegas skyline with pyramids, glowing orb, and "Welcome to Fabulous Las

Your journey to intelligent NetOps begins at Cisco Live

Visit BlueCat’s booth or book a meeting now to learn more about how our solutions can help you build a network that supports constant change.

Read more
Stacked colorful wooden directional arrows on a post by a calm seaside with distant hills and blue sky

Replace BIND and ISC with Micetro DNS/DHCP Server (MDDS)

Tired of patching and manually configuring BIND DNS and ISC DHCP? Discover how Micetro MDDS appliances can replace them for modern DDI.

Read more