Back to main siteBack Contact us
DNS Filtering

Cisco Umbrella

DNS Filtering

The cheapest security control is the one that answers first

Almost every connection a computer makes begins with a question: what address does this name resolve to? Umbrella answers that question, and declines to answer it for destinations known to be malicious. The attack fails before a connection is ever attempted.

Protection that only works on the corporate network is protection you have lost

Web filtering traditionally lived on the firewall at the office. That placement made sense when the office was where people worked and where their traffic left the organization. It makes considerably less sense now.

A laptop at home, in a hotel or on a client site does not pass through that firewall. Whatever filtering policy the organization has carefully configured simply does not apply, and the machines outside the building are precisely the ones in the least controlled environments.

Resolution happens wherever the device is. Moving the control to that layer means it travels with the laptop rather than waiting at an office the laptop may not visit for weeks.

A control that applies only inside the building protects the population least likely to need it.

What blocking at resolution actually prevents

The mechanism is unglamorous and unusually effective, because so many attacks depend on a name being resolved at some point in their sequence.

LINK CLICKED or macro runs NAME LOOKUP REFUSED PAYLOAD FETCHED CREDENTIALS SENT COMMAND CHANNEL
None of the three outcomes on the right can begin if the name never resolves.
Phishing that survives the mail filter
A convincing message reaches an inbox and the link is clicked. The credential harvesting page never loads, because its domain does not resolve.
Malware retrieving its payload
Many initial files are small downloaders whose only job is to fetch the real malware. Blocking that fetch leaves an inert file on disk.
Command and control
Compromised machines call home. When that call cannot be placed, the attacker has a foothold they cannot instruct, and the beacon attempts themselves become a detection signal.
Newly registered domains
Attack infrastructure is frequently days old. Treating very recently registered domains with suspicion blocks a substantial share of campaigns before anyone has categorised them.

Why this is usually the first control to deploy

Most security improvements require an agent on every machine, a change window, a pilot group and a rollback plan. Changing where an organization's name resolution points is a configuration change measured in minutes for an entire site.

It also produces visibility almost immediately. The log of what was requested and blocked is frequently the first time an organization sees which machines are trying to reach infrastructure they should not, which is a useful finding independent of the blocking itself.

Minutes, not months Deployment for a whole network is a configuration change. For roaming laptops it is a lightweight client, which is still among the simplest agents to distribute.

What it covers, and what it plainly does not

ScenarioBlocked at resolution
Link to a known malicious domainYes
Malware fetching a payload by nameYes
Beacon to a known command serverYes
Connection made to a raw addressNo
Malicious file already on the machineNo
Attack using a trusted cloud serviceFrequently not

Those last three rows matter. This is a broad, cheap, early control, not a complete one. It belongs alongside endpoint protection and mail filtering rather than in place of either, and any proposal presenting it as sufficient on its own should be treated sceptically.

Where it earns its place

For organizations with remote or travelling staff, this is among the highest value controls available for the money, precisely because it follows the device. For those with many small sites and no appetite for hardware at each one, it provides consistent filtering without anything to install locally.

It is less compelling for a single site with a capable firewall already inspecting outbound traffic, where much of the benefit is duplicated. Even then, the roaming client for laptops that leave the building is usually worth having on its own.

See what your estate is currently requesting →

In short

Find out what your machines are asking for

A short period of monitoring before any blocking typically reveals requests nobody expected, and that log is a useful picture of the estate in its own right.

Review Your DNS Traffic

Get in touch with Your Company

Questions about this solution? Reach us directly.