DNS Security
Domain Name Service (DNS) is a critical and foundational Internet Protocol,
as described in the
core RFCs for
the protocol. Malicious actors have utilized command and control (C2)
(C2) communication channels over the DNS and, in some cases, have even used the
protocol to exfiltrate data. DNS exfiltration can happen when a bad actor
compromises an application instance in your network and then uses DNS lookup to send
data out of the network to a domain they control. Malicious actors can also
infiltrate malicious data or payloads to the network workloads over DNS. Over the
years, Palo Alto Networks Unit 42 research has described
different types of DNS abuse discovered.
Cloud NGFW for Azure allows you to protect your VNet and vWAN traffic from
advanced DNS-based threats by monitoring and controlling the domains that your
network resources query. With Cloud NGFW for Azure, you can deny access to the
domains that Palo Alto Networks considers bad or suspicious and allow all other
queries to pass-through.
For this purpose, Cloud NGFW leverages the Palo Alto Networks’ DNS Security service,
which
proactively detects malicious domains by
generating DNS signatures using advanced predictive analysis and machine learning,
with data from multiple sources (such as WildFire® traffic analysis, passive DNS,
active web crawling & malicious web content analysis, URL sandbox analysis,
Honeynet, DGA reverse engineering, telemetry data, whois, the Unit 42 research
organization, and
Cyber Threat Alliance). The DNS security service then
distributes these DNS signatures
to your Cloud NGFW resources to
proactively defend against malware using DNS for command and control (C2)
and data theft.
| Category | Log Severity | Action |
| Ad Tracking Domains | Informational | Allow |
| Command and control (C2) Domains | High | Block |
| Dynamic DNS (DDNS) Domains | Informational | Allow |
| Grayware Domains | Low | Block |
| Malware Domains | Medium | Block |
| Newly Registered Domains | Informational | Allow |
| Parked Domains | Informational | Allow |
| Phishing Domains | Low | Block |
| Proxy Avoidance and Anonymizers | Low | Block |