{"id":1847,"date":"2023-10-09T10:02:07","date_gmt":"2023-10-09T10:02:07","guid":{"rendered":"https:\/\/efficientip.com\/?p=71422"},"modified":"2023-10-09T10:02:07","modified_gmt":"2023-10-09T10:02:07","slug":"dns-threat-intelligence-for-higher-education-networks","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/10\/09\/dns-threat-intelligence-for-higher-education-networks\/","title":{"rendered":"DNS Threat Intelligence for Higher Education Networks"},"content":{"rendered":"<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" fetchpriority=\"high\" title=\"DNS Threat Intelligence for Higher Education Networks | EfficientIP\" decoding=\"async\" fetchpriority=\"high\" width=\"640\" height=\"335\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dns-threat-intelligence-for-higher-education-networks.jpg?resize=640%2C335&#038;ssl=1\" alt=\"DNS Threat Intelligence for Higher Education Networks\" class=\"wp-image-71431\" srcset=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dns-threat-intelligence-for-higher-education-networks.jpg 1024w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dns-threat-intelligence-for-higher-education-networks-1.jpg 300w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dns-threat-intelligence-for-higher-education-networks-2.jpg 768w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dns-threat-intelligence-for-higher-education-networks-3.jpg 480w, https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2023\/10\/dns-threat-intelligence-for-higher-education-networks-4.jpg 1200w\" sizes=\"(max-width: 1024px) 100vw, 1024px\"><\/figure>\n<p>With IT staff struggling to protect legacy networks on tight budgets, it\u2019s no wonder schools and universities are top targets for cybercriminals. Sprawling campuses handling BYoD and multiple IoT devices, together with frequent ransomware attacks and compliance regulations add to the difficulty. The <a href=\"https:\/\/efficientip.com\/resources\/cyber-threat-intelligence-idc-2023-global-dns-threat-report\/\" title=\"IDC 2023 Global DNS Threat Report\">2023 IDC Threat Survey<\/a> found that 90% of institutions each suffer on average 8 DNS attacks per year, with every attack costing $1.15M in damages. The report goes on to provide recommendations on how <a href=\"https:\/\/efficientip.com\/blog\/how-ddi-helps-higher-education-surf-the-network-automation-wave\/\" title=\"How DDI Helps Higher Education Surf the Network Automation Wave\">Higher Ed<\/a> can evolve to proactive defense using DNS Threat Intelligence, in order to enhance ransomware detection and zero trust.<\/p>\n<h3 class=\"wp-block-heading\">Why is Higher Education a favorite target?<\/h3>\n<p>Universities handle a wealth of personal and research data, intellectual property and other valuable assets. This makes them enticing for state-sponsored actors, as well as cybercriminals looking to monetise stolen material through sale or ransom. Compliance frameworks also complexify security. Many regulations focus on data safety, while others enforce freedom of information.<\/p>\n<p>Institutions are having to handle distance-learning in the midst of the return to in-person learning. The online platforms required for this are often targeted as new entry points into academic networks. At the same time, staff and students connect multiple personal devices to university networks, many of which are outdated or incorrectly patched against known vulnerabilities. Lastly, recent vulnerabilities such as <a href=\"https:\/\/www.cisa.gov\/news-events\/news\/apache-log4j-vulnerability-guidance\" target=\"_blank\" rel=\"noopener\" title>Log4j<\/a> also opened up institutions to more attacks, affecting websites, apps, devices and digital systems across the campus.&nbsp;<\/p>\n<p>Sadly, <a href=\"https:\/\/efficientip.com\/industry\/higher-education\/\" title=\"Higher Education\">Higher Ed<\/a> institutions don\u2019t have the same resources as other industries, so have become an easier target.&nbsp; IT teams are left with few tools and professionals to adequately&nbsp;protect against the rise in frequency and sophistication of cyberattacks. Bad actors have therefore increased breaches such as phishing, malware, ransomware and data theft. Many of these benefit from using DNS as a threat target or vector.<\/p>\n<h3 class=\"wp-block-heading\">With DNS Attacks on the rise, it\u2019s time to take DNS Security seriously<\/h3>\n<p>90% of schools and universities were victims of DNS attacks according to the IDC Threat Report, with damage costs and recovery times being higher than the average across industries. Top attack types included phishing, ransomware, DDoS, and DNS Tunneling (CnC communication\/data exfiltration).&nbsp;<\/p>\n<p>Impacts of DNS attacks proved to be very serious, affecting productivity, brand image and finances. They included:<\/p>\n<ul>\n<li>Cloud service downtime (46%)<\/li>\n<li>In-house app downtime (39%)<\/li>\n<li>Data theft (28%)<\/li>\n<\/ul>\n<p>In addition, the defenses being used to counteract are inappropriate for ensuring continuity of services. 41% shut down the DNS service, 37% disabled the affected apps, and 26% shut down part of network infrastructure.<\/p>\n<h3 class=\"wp-block-heading\">IDC Report Highlights: DNS Threat Intelligence enables proactive defense<\/h3>\n<p>The IDC report shows that 84% of Higher Ed regard DNS Security as critical for ensuring the security of users, devices, applications, and services. It is viewed as important for the implementation of security concepts such as Threat Intelligence, Zero Trust and Shadow IT.&nbsp;<\/p>\n<p><strong>Below are some of the key highlights from the report:<\/strong><\/p>\n<h4 class=\"wp-block-heading\">DNS Threat Intelligence<\/h4>\n<ul>\n<li>Threat intelligence (TI) has emerged as a pivotal aspect of cybersecurity defense, with 65% of higher education considering it a vital component of their strategy to defend against cyberattacks<\/li>\n<li>There is a definite need for specialized DNS Threat Intelligence, incorporating DNS Feeds<\/li>\n<li>For TI, the market sees value of actionable DNS data for:\n<ul>\n<li>Malware detection \u2013 74%<\/li>\n<li>Phishing detection \u2013 77%<\/li>\n<li>Ransomware detection \u2013 73%<\/li>\n<li>Improved Access Control to apps and data \u2013 51%<\/li>\n<\/ul>\n<\/li>\n<li>But DNS data is being underutilized \u2013 43% of Higher Ed do not perform any analysis their DNS data, and only 19% use it today for TI<\/li>\n<\/ul>\n<h4 class=\"wp-block-heading\">Ransomware<\/h4>\n<ul>\n<li>Average <a href=\"https:\/\/www.insidehighered.com\/news\/2022\/07\/22\/ransomware-attacks-against-higher-ed-increase\" target=\"_blank\" rel=\"noopener\" title>remediation cost for Higher Ed was $1.42M<\/a> in 2021, with 85% of malware using DNS to develop their attack<\/li>\n<li>Analysis of DNS traffic<strong> <\/strong>helps identify unusual patterns of traffic to unveil zero-day malicious domains used for data exfiltration by ransomware<\/li>\n<\/ul>\n<ul>\n<li>Only 47% of Higher Ed use or consider using DNS security for ransomware and malware protection, far below the 54%<strong> <\/strong>average across industries<\/li>\n<li>DNS Filtering can block access to known malicious domains, preventing ransomware from communicating with its CnC servers, thus preventing the attack causing any damage<\/li>\n<li>DNS Filtering can also be used to block access to known phishing sites, helping prevent initiation of ransomware attacks<\/li>\n<\/ul>\n<h4 class=\"wp-block-heading\">Data Theft<\/h4>\n<ul>\n<li>Institutions are challenged with meeting compliance for data protection and data privacy regulations such as GDPR and <a href=\"https:\/\/www.enisa.europa.eu\/topics\/cybersecurity-policy\/nis-directive-new\" target=\"_blank\" rel=\"noopener\" title>NIS2<\/a><\/li>\n<li>DNS is a valuable tool for helping organizations achieve regulatory compliance by providing domain filtering, data privacy, logging and analysis, compliance reporting on DNS&nbsp; traffic, and overall boosted security measure<\/li>\n<li>DNS strengthens data protection by filling gaps left by traditional security systems<\/li>\n<li>53% of Higher Ed say DNS security can help prevent data exfiltration by detecting improper DNS flow and blocking related traffic. Average across all industries is 59%<\/li>\n<li>Private DNS over HTTPS (DoH) improves data privacy by encrypting DNS traffic and preventing unauthorized access to DNS data<\/li>\n<\/ul>\n<h4 class=\"wp-block-heading\">Securing Extended Networks<\/h4>\n<p>WIth Higher Education networks having to support connected devices, cloud services\/apps, and \u201cwork-from-anywhere\u201d, DNS is seen as critical in securing:<\/p>\n<ul>\n<li>On-prem workforce \u2013 83%<\/li>\n<li>Remote workforce \u2013 83%<\/li>\n<li>IoT \u2013 57%<\/li>\n<li>Cloud \u2013 84%<\/li>\n<li>Datacenters \u2013 65%<\/li>\n<\/ul>\n<h4 class=\"wp-block-heading\">Key Recommendations<\/h4>\n<ol>\n<li>Leverage DNS threat intelligence feeds to help you evolve to proactive defense<\/li>\n<li>Benefit from DNS observability to strengthen your security posture<\/li>\n<li>Incorporate DNS data into your security ecosystem to accelerate threat remediation<\/li>\n<\/ol>\n<p><a href=\"https:\/\/efficientip.com\/blog\/dns-threat-intelligence-for-higher-education-networks\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>With IT staff struggling to protect legacy networks on tight<\/p>\n","protected":false},"author":5,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[894,895,30,896,62,897,172,898,170,46,49,899,900],"tags":[901,902,38,903,69,904,176,905,171,54,57,906,907],"class_list":["post-1847","post","type-post","status-publish","format-standard","hentry","category-cyberthreat","category-data-theft","category-dns","category-dns-attack","category-dns-security","category-enterprise-network-security","category-internet-of-things","category-nod","category-privacy-laws","category-ransomware","category-threat-intelligence","category-threat-report","category-zero-trust","tag-cyberthreat","tag-data-theft","tag-dns","tag-dns-attack","tag-dns-security","tag-enterprise-network-security","tag-internet-of-things","tag-nod","tag-privacy-laws","tag-ransomware","tag-threat-intelligence","tag-threat-report","tag-zero-trust"],"featured_image_urls":{"full":"","thumbnail":"","medium":"","medium_large":"","large":"","1536x1536":"","2048x2048":"","chromenews-featured":"","chromenews-large":"","chromenews-medium":""},"author_info":{"display_name":"Efficient IP","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/efficient-ip\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/cyberthreat\/\" rel=\"category tag\">cyberthreat<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/data-theft\/\" rel=\"category tag\">Data theft<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/dns\/\" rel=\"category tag\">DNS<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/dns-attack\/\" rel=\"category tag\">DNS Attack<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/dns-security\/\" rel=\"category tag\">DNS Security<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/enterprise-network-security\/\" rel=\"category tag\">enterprise network security<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/internet-of-things\/\" rel=\"category tag\">Internet of Things<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/nod\/\" rel=\"category tag\">NOD<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/privacy-laws\/\" rel=\"category tag\">Privacy Laws<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/ransomware\/\" rel=\"category tag\">ransomware<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/threat-intelligence\/\" rel=\"category tag\">Threat Intelligence<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/threat-report\/\" rel=\"category tag\">Threat Report<\/a> <a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/zero-trust\/\" rel=\"category tag\">Zero Trust<\/a>","tag_info":"Zero Trust","comment_count":"0","jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1847","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=1847"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/1847\/revisions"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=1847"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=1847"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=1847"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}