BlueCat DNS Edge Delivers Visibility and Control to Network and Cybersecurity Teams

Key takeawaysThis key takeaway was generated through LLMs crawling the page and coming up with an overview of the content.

BlueCat announced new capabilities for BlueCat DNS Edge that leverage existing DNS infrastructure to detect and block internal and external cyber attacks, addressing a surge in DNS-based malware activity where 91% of malware uses DNS for command-and-control, exfiltration, or lateral movement. The software gives network and cybersecurity teams unprecedented visibility into pre-cache DNS queries and responses for every connected client, enabling detection of lateral movement, patient zero, and compliance with standards like NIST 800-53. Additional features include granular DNS policies, threat-feed ingestion, analytics to detect DNS tunneling and domain generation algorithms, Splunk integration, multi-namespace DNS-routing policies to reduce WAN and proxy load, and dashboard improvements for anomaly spotting.

How does BlueCat DNS Edge improve visibility into internal and external network activity compared to firewalls and web proxies?

BlueCat DNS Edge provides visibility into DNS queries and responses before they are cached, capturing the originating host, full query, and response for both internal and external requests. This level of pre-cache DNS data includes activity that firewalls and web proxies typically do not see, enabling detection of suspicious behavior, lateral movement, and identification of patient zero. That richer DNS telemetry also helps organizations meet monitoring and boundary protection compliance requirements such as NIST 800-53 by supplying detailed, per-client DNS activity across the network.

What detection and analytic capabilities does Edge use to identify DNS-based threats?

Edge employs smart analytics to identify patterns in DNS queries indicative of common exploits such as DNS tunneling, data exfiltration, and domain generation algorithms. Suspicious query data can be forwarded to SIEMs for correlation and further analysis, and Edge can ingest external threat intelligence feeds and apply blocklist policies. These combined analytics, threat-feed ingestion, and policy enforcement permit teams to detect malicious behavior on the network and integrate findings with broader security operations workflows, including a dedicated BlueCat DNS Edge for Splunk integration available on SplunkBase.

What operational benefits do the new multi-namespace DNS-routing policies and dashboard improvements provide?

The new multi-namespace DNS-routing policies give administrators flexibility to configure DNS resolution paths, which can reduce duplication across namespaces and offload traffic from the WAN and web proxies. This helps lighten infrastructure load while allowing more granular control over how queries are resolved across sites and zones. Dashboard improvements make it easier for administrators to spot anomalies in DNS query data, accelerating detection and response by surfacing suspicious patterns and operational metrics for faster troubleshooting and policy tuning.

With DNS exploit attacks surging, BlueCat releases new DNS security software that detects internal threats and secures vital assets.

TORONTO – May 23, 2018 – Today, BlueCat, the Adaptive DNS company, announced powerful new capabilities for BlueCat DNS Edge™ (Edge), a solution that leverages existing DNS infrastructure to help cybersecurity and networking teams detect and block cyber attacks. The new capabilities add a much-needed layer of defense for corporate networks under siege from an explosion of malware attacks and their skyrocketing cost. According to industry research, 91% of malware uses the DNS protocol for command and control, data exfiltration or lateral movement on a corporate network.

“Networking and cybersecurity teams are under pressure to gain control of their network infrastructure and greatly increase actionable cyber intelligence,” said Michael Harris, CEO of BlueCat. “The solution lies hidden in billions of DNS queries and responses. As the leading provider of Adaptive DNS solutions for the world’s largest organizations, BlueCat is in a unique position to help customers identify, control and reduce the attack surface – especially for exploits happening inside the firewall.”

Edge helps organizations:

  • Get unprecedented visibility into internal and external network activity for every connected client device, corporate application or service. With Edge, cybersecurity teams can access DNS data that today’s firewalls and web proxies will never see. This includes the originating host, query and response – before the cache, for both internal and external requests. This helps them observe suspicious activity, detect lateral movement and track down patient zero. It also makes it easy for cybersecurity teams to meet or exceed compliance standards for system monitoring and boundary protection like NIST 800-53.
  • Quickly establish smarter, more flexible policies to control internal and external DNS activity across the entire network. With Edge, network and security architects create granular policies based on a variety of factors such as the DNS query, device types (including IoT devices), sites and zones, and time of day. This flexibility helps cybersecurity teams establish least-privilege access at the DNS level to protect internal assets or lock down infected IoT devices, for example. Edge can also ingest threat intelligence feeds from any source and build on established blocklist policies.
  • Detect malicious behavior on the network like DNS tunneling, data exfiltration and domain generation algorithms. Edge employs smart analytics to look for patterns in DNS queries that indicate common DNS exploits. Any suspicious query data can be sent to popular SIEMS for further analysis and correlation. BlueCat recently introduced BlueCat DNS Edge for Splunk that offers additional capabilities for Splunk users, available for download on SplunkBase.

 

The latest version of Edge also includes new DNS-routing policies using multi-namespaces to introduce unique flexibility for administrators to configure their DNS resolution path, lighten the load on the WAN and web proxies, and eliminate duplication across namespaces. Additionally, new dashboard improvements make it easier for administrators to spot anomalies in DNS query data.

 

About BlueCat

BlueCat is the Adaptive DNS Company™. The largest global enterprises trust BlueCat to provide the foundation for digital transformation strategies such as cloud migration, virtualization and cybersecurity. Our Adaptive DNS platform improves control and compliance across entire networks, enabling organizations to centralize and automate DNS services for security and operational efficiency. For more information, please visit bluecatnetworks.com.

 

Contact Information

Jim Williams
BlueCat Public Relations
[email protected]
781.718.1435

Get in touch

We’re the DDI provider you’ve been looking for.
Drop us a line and let’s talk.

Related content

Isometric dashboard illustration showing a circular "33 Total Devices" donut chart, issue counts, and filter controls

BlueCat moves agentic AI from insight to action with new AI integrations

Extends its Intelligent NetOps platform to help organizations unlock measurable AI value through a unified data foundation

Read more
Headshot of a man in a suit and striped tie wearing rectangular glasses against a blurred office background

BlueCat appoints Jeff McCullough as Vice President, Worldwide Channel and Alliance

Experienced channel leader will drive partner-led growth and support partners in generating revenue and value within BlueCat’s global ecosystem

Read more
BlueCat logo above Horizon product name with stylized network horizon graphic and glowing center

BlueCat introduces BlueCat Horizon, a SaaS-first Intelligent NetOps platform for cross-domain network operations

The platform delivers a unified control plane for DNS, DHCP, IPAM, security, and observability, empowering rapid, automated action across networks

Read more
Report cover titled "The Network Observability Maturity Model" with EMA and BlueCat logos and purple design accents

Fewer than half of enterprises are fully successful with network observability tools

Fragmented tools and cloud blind spots are straining NetOps, but a new five-stage maturity model charts the path to excellence.

Read more