Cisco Umbrella
The cheapest security control is the one that answers first
Almost every connection a computer makes begins with a question: what address does this name resolve to? Umbrella answers that question, and declines to answer it for destinations known to be malicious. The attack fails before a connection is ever attempted.
Protection that only works on the corporate network is protection you have lost
Web filtering traditionally lived on the firewall at the office. That placement made sense when the office was where people worked and where their traffic left the organization. It makes considerably less sense now.
A laptop at home, in a hotel or on a client site does not pass through that firewall. Whatever filtering policy the organization has carefully configured simply does not apply, and the machines outside the building are precisely the ones in the least controlled environments.
Resolution happens wherever the device is. Moving the control to that layer means it travels with the laptop rather than waiting at an office the laptop may not visit for weeks.
What blocking at resolution actually prevents
The mechanism is unglamorous and unusually effective, because so many attacks depend on a name being resolved at some point in their sequence.
- Phishing that survives the mail filter
- A convincing message reaches an inbox and the link is clicked. The credential harvesting page never loads, because its domain does not resolve.
- Malware retrieving its payload
- Many initial files are small downloaders whose only job is to fetch the real malware. Blocking that fetch leaves an inert file on disk.
- Command and control
- Compromised machines call home. When that call cannot be placed, the attacker has a foothold they cannot instruct, and the beacon attempts themselves become a detection signal.
- Newly registered domains
- Attack infrastructure is frequently days old. Treating very recently registered domains with suspicion blocks a substantial share of campaigns before anyone has categorised them.
Why this is usually the first control to deploy
Most security improvements require an agent on every machine, a change window, a pilot group and a rollback plan. Changing where an organization's name resolution points is a configuration change measured in minutes for an entire site.
It also produces visibility almost immediately. The log of what was requested and blocked is frequently the first time an organization sees which machines are trying to reach infrastructure they should not, which is a useful finding independent of the blocking itself.
What it covers, and what it plainly does not
| Scenario | Blocked at resolution |
|---|---|
| Link to a known malicious domain | Yes |
| Malware fetching a payload by name | Yes |
| Beacon to a known command server | Yes |
| Connection made to a raw address | No |
| Malicious file already on the machine | No |
| Attack using a trusted cloud service | Frequently not |
Those last three rows matter. This is a broad, cheap, early control, not a complete one. It belongs alongside endpoint protection and mail filtering rather than in place of either, and any proposal presenting it as sufficient on its own should be treated sceptically.
Where it earns its place
For organizations with remote or travelling staff, this is among the highest value controls available for the money, precisely because it follows the device. For those with many small sites and no appetite for hardware at each one, it provides consistent filtering without anything to install locally.
It is less compelling for a single site with a capable firewall already inspecting outbound traffic, where much of the benefit is duplicated. Even then, the roaming client for laptops that leave the building is usually worth having on its own.
Find out what your machines are asking for
A short period of monitoring before any blocking typically reveals requests nobody expected, and that log is a useful picture of the estate in its own right.
Review Your DNS TrafficGet in touch with Your Company
Questions about this solution? Reach us directly.