Page 75 - CSI - Cisco Security Instroduction - BT
P. 75

Gather Intelligence & Enforce Security at the DNS Layer




                   Any Device                                                  Recursive DNS                                                     Authoritative DNS




                                                                                                                                                              root




                                                                                                                                                              com.



                                                                                                                                                              domain.com.






                                           Request Patterns                                                       Authoritative Logs



                                                Used to detect:                                                          Used to find:

                                    • Compromised systems                                                    • Newly staged infrastructures

                                    • Command & control callbacks                                            • Malicious domains, IPs,
                                    • Malware & phishing attempts                                               ASNs

                                    • Algorithm-generated domains                                            • DNS hijacking

                                    • Domain co-occurrences                                                  • Fast flux domains
                                    • Newly registered domains                                               • Related domains




          78
   70   71   72   73   74   75   76   77   78   79   80