{"id":1433,"date":"2023-06-16T20:02:49","date_gmt":"2023-06-16T20:02:49","guid":{"rendered":"https:\/\/bluecatnetworks.com\/?p=273202"},"modified":"2023-06-16T20:02:49","modified_gmt":"2023-06-16T20:02:49","slug":"cisco-live-2023-introducing-zero-trust-dns","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/06\/16\/cisco-live-2023-introducing-zero-trust-dns\/","title":{"rendered":"Cisco Live 2023: Introducing Zero Trust DNS"},"content":{"rendered":"<p>At Cisco Live Las Vegas 2023, BlueCat\u2019s booth presentations were especially popular, as were personalized demos with BlueCat technical experts.<\/p>\n<div class=\"col-12 col-md-12 col-lg-8\"><img loading=\"lazy\" decoding=\"async\" class=\"js-loaded size-full wp-image-23745 img-fluid v-image-processed has-media-category media-cat-blog-pics-and-headers\" src=\"https:\/\/bluecatnetworks.com\/wp-content\/plugins\/v-site-base\/images\/fallback_images\/image-placeholder.svg\" alt=\"The BlueCat team at BlueCat's booth on the World of Solutions floor at Cisco Live 2023 in Las Vegas\" width=\"100%\" height=\"auto\" data-custom-sizes=\"1\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-5.jpg\" data-srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns.jpg 540w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-1.jpg 1200w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-2.jpg 340w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-3.jpg 640w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-4.jpg 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-5.jpg 2048w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-6.jpg 24w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-7.jpg 36w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-8.jpg 48w\" data-sizes=\"(min-width: 1200px) 1200px, (min-width: 992px) 992px, (min-width: 768px) 768px, (min-width: 576px) 576px, 100vw\"><span><em>The BlueCat team at BlueCat\u2019s booth on the World of Solutions floor at Cisco Live 2023 in Las Vegas.<\/em><\/span><\/div>\n<p>But we were really excited to introduce a new concept: Zero Trust DNS. At a basic level, <a href=\"https:\/\/bluecatnetworks.com\/resources\/how-to-secure-your-network-with-dns-security\/\">DNS security<\/a> is about leveraging your DNS to better secure your enterprise network.<\/p>\n<p>BlueCat solutions offer three crucial elements that comprise Zero Trust DNS:<\/p>\n<ul>\n<li>continuous verification,<\/li>\n<li>least-privilege access<\/li>\n<li>and context and response.<\/li>\n<\/ul>\n<p>In this post, we\u2019ll touch on why security is so important when it comes to DDI solutions. (<a href=\"https:\/\/bluecatnetworks.com\/glossary\/what-is-dns\/\">DNS<\/a>, <a href=\"https:\/\/bluecatnetworks.com\/glossary\/what-is-dhcp\/\">DHCP<\/a>, and <a href=\"https:\/\/bluecatnetworks.com\/glossary\/what-is-ipam\/\">IP address management<\/a>, often referred to collectively as DDI, provide the core services that enable network communications.) We\u2019ll share the highlights of our presentation introducing Zero Trust DNS as well as our integration with Cisco Umbrella and BlueCat Edge. And finally, we\u2019ll explore the take-home message from Cisco Live that the future is simplicity.<\/p>\n<p>By the way, now that <a href=\"https:\/\/bluecatnetworks.com\/blog\/bluecat-is-now-a-cisco-solutionsplus-partner\/\">BlueCat is now a Cisco SolutionsPlus partner,<\/a> it\u2019s even easier to adopt BlueCat solutions.<\/p>\n<h2>Security is critical for DDI solutions<\/h2>\n<p>Security tops the list of the most critical requirements sought in DDI solutions, according to a recent <a href=\"https:\/\/bluecatnetworks.com\/blog\/two-thirds-of-enterprises-employ-full-stack-ddi\/\">survey conducted by Enterprise Management Associates<\/a> (EMA) of 227 IT professionals from medium and large enterprises across North America and the United Kingdom.<\/p>\n<div class=\"col-12 col-md-12 col-lg-8\"><img decoding=\"async\" loading=\"lazy\" class=\"js-loaded size-full wp-image-23745 img-fluid v-image-processed has-media-category media-cat-blog-pics-and-headers\" src=\"https:\/\/bluecatnetworks.com\/wp-content\/plugins\/v-site-base\/images\/fallback_images\/image-placeholder.svg\" alt=\"A crowd gathered for a booth presentation at BlueCat's booth on the World of Solutions floor at Cisco Live 2023\" width=\"100%\" height=\"auto\" data-custom-sizes=\"1\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-14.jpg\" data-srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-9.jpg 540w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-10.jpg 1200w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-11.jpg 340w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-12.jpg 640w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-13.jpg 1152w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-14.jpg 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-15.jpg 2048w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-16.jpg 18w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-17.jpg 27w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-18.jpg 36w\" data-sizes=\"(min-width: 1200px) 1200px, (min-width: 992px) 992px, (min-width: 768px) 768px, (min-width: 576px) 576px, 100vw\"><span><em>A crowd gathers for a booth presentation at BlueCat\u2019s booth on the World of Solutions floor at Cisco Live 2023.<\/em><\/span><\/div>\n<p>DNS was built to correctly and efficiently respond to queries, not question their intent. As a result, DNS has real vulnerabilities and potential as a vector for cyberattacks.<\/p>\n<p>As the threat of <a href=\"https:\/\/bluecatnetworks.com\/blog\/four-major-dns-attack-types-and-how-to-mitigate-them\/\">DNS attacks<\/a> continues to grow, 59% of EMA survey respondents deemed security their top requirement when looking for a DDI solution. Sought-after features include both DNS security protection and monitoring, such as support for the <a href=\"https:\/\/bluecatnetworks.com\/blog\/breaking-down-dnssec-how-does-it-work\/\">DNSSEC<\/a> protocol or a <a href=\"https:\/\/bluecatnetworks.com\/blog\/how-to-choose-the-right-dns-firewall-for-your-network\/\">DNS firewall<\/a> to filter and block malicious activity.<\/p>\n<p>A number of factors are driving this demand for security in DDI solutions, including an increasing reliance on IP address forensics to prevent and remediate breaches. Other contributing factors include an emerging regulatory environment and demands for compliance and organizational alignment.<\/p>\n<p>DNS as part of your security solution offers numerous benefits, including the ability to:<\/p>\n<ul>\n<li>Take proactive and early kill-chain action;<\/li>\n<li>Prevent data exfiltration;<\/li>\n<li>Prevent command-and-control breaches;<\/li>\n<li>Segment your network;<\/li>\n<li>Get visibility and context for all DNS queries;<\/li>\n<li>Detect lateral threat movements;<\/li>\n<li>Remediate breaches faster; and<\/li>\n<li>Prevent <a href=\"https:\/\/bluecatnetworks.com\/blog\/ddos-attacks-use-dns-weapon\/\">distributed denial-of-service (DDoS) attacks<\/a>.<\/li>\n<\/ul>\n<p>Even <a href=\"https:\/\/bluecatnetworks.com\/blog\/our-analysis-gartners-dns-security-best-practices\/\">Gartner recognized DNS security<\/a> as crucial for improving the overall defense of your network.<\/p>\n<h2>Introducing Zero Trust DNS<\/h2>\n<div class=\"col-12 col-md-12 col-lg-8\"><img decoding=\"async\" loading=\"lazy\" class=\"js-loaded size-full wp-image-23745 img-fluid v-image-processed has-media-category media-cat-blog-pics-and-headers\" src=\"https:\/\/bluecatnetworks.com\/wp-content\/plugins\/v-site-base\/images\/fallback_images\/image-placeholder.svg\" alt=\"Martin McNealis, BlueCat\u2019s Chief Product Officer, introduces Zero Trust DNS to Cisco Live attendees at the World of Solutions\u2019 Content Corner at Cisco Live 2023\" width=\"100%\" height=\"auto\" data-custom-sizes=\"1\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-27.jpg\" data-srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-19.jpg 540w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-20.jpg 1200w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-21.jpg 340w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-22.jpg 640w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-23.jpg 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-24.jpg 24w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-25.jpg 36w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-26.jpg 48w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-27.jpg 1996w\" data-sizes=\"(min-width: 1200px) 1200px, (min-width: 992px) 992px, (min-width: 768px) 768px, (min-width: 576px) 576px, 100vw\"><span><em>Martin McNealis, BlueCat\u2019s Chief Product Officer, introduces Zero Trust DNS to Cisco Live attendees at the World of Solutions\u2019 Content Corner at Cisco Live 2023.<\/em><\/span><\/div>\n<p>Martin McNealis, BlueCat\u2019s Chief Product Officer, introduced Zero Trust DNS to Cisco Live attendees at the World of Solutions\u2019 Content Corner.<\/p>\n<p>In general, zero trust is a security framework that requires authentication, authorization, and continuous validation for all users before getting or keeping access to applications and data. Users can be on the local network, in the cloud, or in a hybrid environment.<\/p>\n<h3>How BlueCat solutions provide Zero Trust DNS<\/h3>\n<p>During his session, \u201cUnlocking the hidden value of your DDI data,\u201d McNealis broke down the specifics of how BlueCat\u2019s solutions foster Zero Trust DNS:<\/p>\n<ul>\n<li><b>Malicious domains:<\/b> Keep malicious domains at bay with domain control lists, alerts for newly observed domains, and real-time threat updates.<\/li>\n<li><b>Policy enforcement:<\/b> Enforce policies with intelligent forwarding or steering, policy tiers, and full query and response audits.<\/li>\n<li><b>DNS tunneling:<\/b> Ward off <a href=\"https:\/\/bluecatnetworks.com\/blog\/why-you-should-pay-attention-to-dns-tunneling\/\">DNS tunneling<\/a> with advanced pattern recognition, volumetric analysis, and data exfiltration detection.<\/li>\n<li><b>Most compromised endpoints:<\/b> Find your most compromised endpoints with cumulative risk scoring, traffic and tunneling analysis, and <a href=\"https:\/\/bluecatnetworks.com\/blog\/what-is-typosquatting-and-how-to-protect-against-it\/\">typosquatting<\/a> detection.<\/li>\n<li><b>Advanced DGA detection:<\/b> Detect <a href=\"https:\/\/bluecatnetworks.com\/blog\/among-cyber-attack-techniques-what-is-a-dga\/\">domain generation algorithm<\/a> (DGA) attacks with machine learning models while accelerating threat scanning and optimizing storage costs.<\/li>\n<li><b>Trust policy:<\/b> Ensure the trustworthiness of your network by qualifying domains and client device IP addresses, accelerating responses, and suppressing false positives.<\/li>\n<\/ul>\n<h3>What your DNS query and response data can tell you<\/h3>\n<p>Furthermore, BlueCat\u2019s solutions offer an extensive trove of both DNS query and <a href=\"https:\/\/bluecatnetworks.com\/blog\/the-value-of-dns-response-data\/\">response data<\/a>.<\/p>\n<p>With this data, you can identify attack sources and their source IP addresses, and you can append user identity information. You can discover unsecured entry points used during an attack. And you can engage in faster threat hunting during a security incident response.<\/p>\n<h3>What\u2019s next for Zero Trust DNS<\/h3>\n<p>McNealis also previewed what\u2019s to come for Zero Trust DNS from BlueCat. Future features will include identity provider integrations; device, user, and endpoint scoring; threat policy aggregation; API event channel integration; and actionable analytics.<\/p>\n<h2>Cisco Umbrella and BlueCat Edge<\/h2>\n<p><a href=\"https:\/\/bluecatnetworks.com\/cisco\/\">BlueCat and Cisco<\/a> can deliver a fully integrated, automation-driven, security-focused network. With these integrations, you can bring core DDI infrastructure into tools like Cisco Umbrella.<\/p>\n<p>Because of its critical position in the network, and because of the unique data that BlueCat manages, BlueCat Edge can improve the security profile of the modern enterprise.<\/p>\n<p>And with BlueCat Edge and Cisco Umbrella, you can get a new level of context and actionable data that security teams can use to rapidly identify and mitigate threats.<\/p>\n<p>BlueCat Edge uses client-facing service points to collect granular information about devices and user activity at the first hop in any network query. It sends the source IP of every DNS query, down to the individual endpoint IP address, to Cisco Umbrella. BlueCat applies security policies to and logs internal (east-west) queries. It shares that data with Cisco Umbrella\u2019s monitoring of external (north-south) queries. This creates a more comprehensive view of all network traffic in one user interface.<\/p>\n<p>The result is greater context for analyzing your DNS traffic, more granular security policies, and enhanced network security.<\/p>\n<p>Watch this clip of BlueCat in action on the floor talking about our Cisco Umbrella integration:<\/p>\n<p>And take note: BlueCat also integrates with Cisco DNA Center and Cisco ACI.<\/p>\n<h2>The Cisco Live message: Security needs simplicity<\/h2>\n<p>A key message at Cisco Live 2023 was that networks must eliminate complexity and sprawl to be effective, particularly when it comes to security.<\/p>\n<div class=\"col-12 col-md-12 col-lg-8\"><img decoding=\"async\" loading=\"lazy\" class=\"js-loaded size-full wp-image-23745 img-fluid v-image-processed has-media-category media-cat-blog-pics-and-headers\" src=\"https:\/\/bluecatnetworks.com\/wp-content\/plugins\/v-site-base\/images\/fallback_images\/image-placeholder.svg\" alt=\"A crowd gathered for a booth presentation at BlueCat's booth on the World of Solutions floor at Cisco Live 2023\" width=\"100%\" height=\"auto\" data-custom-sizes=\"1\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-33.jpg\" data-srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-28.jpg 540w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-29.jpg 1200w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-30.jpg 340w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-31.jpg 640w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-32.jpg 1536w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-33.jpg 2048w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-34.jpg 24w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-35.jpg 36w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/06\/cisco-live-2023-introducing-zero-trust-dns-36.jpg 48w\" data-sizes=\"(min-width: 1200px) 1200px, (min-width: 992px) 992px, (min-width: 768px) 768px, (min-width: 576px) 576px, 100vw\"><span><em>A crowd gathers for a booth presentation at BlueCat\u2019s booth on the World of Solutions floor at Cisco Live 2023.<\/em><\/span><\/div>\n<p>Network security has mostly evolved in a patchwork-like manner. The market is now saturated with about <a href=\"https:\/\/www.sdxcentral.com\/articles\/interview\/cisco-says-current-security-approaches-are-failing-touts-consolidated-platform\/2023\/05\/\">3,500 security vendors<\/a>, and a typical large enterprise may utilize 50 to 70 of them for their own networks, according to SDxCentral.<\/p>\n<p>Cisco is evolving toward a consolidated, end-to-end platform approach. Last year, Cisco unveiled Security Cloud, which consolidated its more than two dozen security services into a few product suites. And at Cisco Live, the company <a href=\"https:\/\/newsroom.cisco.com\/c\/r\/newsroom\/en\/us\/a\/y2023\/m06\/cisco-showcases-vision-to-simplify-networking-and-securely-connect-the-world.html\">announced Cisco Networking Cloud<\/a> to manage all Cisco networking products from one place.<\/p>\n<p>Similarly, with BlueCat\u2019s Zero Trust DNS, you can manage your DNS security from one consolidated platform that provides total visibility across your entire network.<\/p>\n<p>Learn more about <a href=\"https:\/\/bluecatnetworks.com\/adaptive-dns\/bluecat-edge\/\">BlueCat Edge<\/a> and how our solutions can bring you Zero Trust DNS.<\/p>\n<p> <a href=\"https:\/\/bluecatnetworks.com\/blog\/cisco-live-2023-introducing-zero-trust-dns\/\">BlueCat Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>At Cisco Live Las Vegas 2023, BlueCat\u2019s booth presentations were<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[94],"tags":[95],"class_list":["post-1433","post","type-post","status-publish","format-standard","hentry","category-blog","tag-blog"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Blue Cat","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/bluecat\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/blog\/\" rel=\"category tag\">Blog<\/a>","tag_info":"Blog","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1433","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=1433"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1433\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=1433"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=1433"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=1433"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}