A DNS Firewall For Every Network

Sep 06, 2022
Daniel Cid(@dcid)

We spend a lot of time talking about CleanBrowsing in the context of DNS filtering, but in this article we're going to spend some time focusing on the security benefits you get with CleanBrowsing.

By default, security is built into the CleanBrowsing service. It is foundational to every Free and Paid service. Organizations have the ability to consume our Security RPZ feed for a cost, but every Free filter has it "on" by default, and paying customers have the ability to enable or disable the filter from the dashboard.

Our DNS Firewall works to block access to phishing, spam, malware and other malicious domains. Our database of malicious domains is updated hourly and considered to be one of the best in the industry.

Let's shed a little light into how it works, and provide a few real-world examples.

A DNS Primer

DNS is the internet's lookup table. It builds a bridge between the domain name (e.g., perezbox.com) and the IP address (e.g., 184.24.56.17). The IP address being where you can find the server that hosts the domain. In addition to its job as a lookup table, it can also serve as an effective security control.

DNS is lightweight, doesn't require an installation, highly effective, conforms to the TTPs employed by attackers, and, more importantly, affordable.

The CleanBrowsing DNS Firewall

DNS is foundational to how the internet works. It is what makes it so effective for content filtering, but also why it's so important to leverage it for security.

In addition to working to prevent attacks, the DNS Firewall also has another very cool feature in that it also helps thwart attacks even if they make it on the network. Here are a few different tactics employed by bad actors that help illustrate how DNS Firewalls help keep you safe:

  • Benign Websites: An attacker compromises a benign site (domain), it's used to distribute malware, or perform other nefarious activity (e.g., Phishing, SEO Spam, etc.).
  • Malicious Websites: An attacker creates a malicious site (domain), its sole purpose is to distribute malware, or perform other nefarious activity (e.g., Phishing, SEO Spam, Dropper, etc.).
  • Command & Control (C&C): Command and Controls (C&C) is what an attacker uses to facilitate their orchestration. Payloads will phone home to C&Cs for instructions on what to do next.
Real-World Examples

A great example of how this works is to look at our recent research, in which we were able to uncover an active Spam / Malware network. In that research we spent a week monitoring hackers as they worked through our honeypot. In the process, they sprinkled our server with various malware payloads all designed to abuse our web server and corresponding website. In this specific instance it was about hijacking a benign website and using it to distribute both SPAM and Malware to users.

Our research allowed us to block the entire network via our Security filter, keeping all our users safe from domains intended on doing online visitor harm. We also used that intelligence to reach out to organizations like Linode, CloudFlare and the various registrars to help get these bad actors off the web.

Another great example comes from 2019. In 2019, there were a number of WordPress hacks that exploited a vulnerability in a well known plugin. This exploit affected thousands of sites, including the popular Mailgun service.

Attackers used their access to embed JS code on the sites that would initiate calls to a number of different domains: hellofromhony[.]org, jqueryextd[.]at, adwordstraffic[.]link. These domains would then initiate different actions (including stealing credit card information) depending on the request.

DNS Firewalls Help Create Safe Browsing Experiences

While we spend a lot of time talking about content filtering, security is a very important layer of that filtering. Via DNS we are not only able to stop attacks that look to introduce malicious payloads into your network, but we can use the same technology to look at outbound communications to block ongoing attacks.

It's important to note that this is not a replacement for existing security controls like traditional Firewalls, IPS, HIDS, etc. It should be looked at as a complementary control, especially when paired with encrypted DNS for additional privacy and security.

Protect Your Network Today

Start using CleanBrowsing's powerful DNS filtering to keep your users safe and your internet clean.

Filtering Guides

Practical tips and tutorials to help you get the most out of DNS filtering and safe browsing.

DNSArchive

Investigate domains with passive DNS, IP reputation, and web metadata.

Explore
Trunc SIEM

Forward your DNS logs to a secure, cloud-hosted SIEM in minutes.

Learn more
NOC Web Infrastructure

Secure and accelerate your websites with authoritative DNS, a global CDN, and intelligent WAF protection.

Visit NOC
Contact us!

Have a question? Reach out at support@cleanbrowsing.org