Home / Blogs

Reducing the Risks of BYOD with DNS-Based Security Intelligence; Part 1: Understanding the Risks

Don't miss a thing – sign up for CircleID Weekly Wrap newsletter delivered to your inbox once a week.
Pat Barnes

Ah, BYOD. How I love thee.

BYOD, or "Bring Your Own Device", gives me choices. I can use a device at work I actually like and am most effective with. (How did I ever get by without my iPad?)

But BYOD comes with challenges. Personal devices can be infected with malware. Once they're connected to an enterprise's network, they can be controlled by a bot master to hijack enterprise resources and wreak havoc as part of a botnet. The biggest risk is data exfiltration which can have serious consequences: loss of valuable intellectual property, unauthorized disclosure of personal and confidential information, and more.

Having mentioned bot masters and botnets, here's a primer on what these terms are. Many cyber criminals employ bot networks, commonly known as "botnets", as the instrument of choice to implement their malicious activities. Bots are simply software that runs autonomously over the Internet. Devices can be infected with malware that operates as a "bot", autonomously exploiting the network to conduct malicious activities. A botnet is a collection of bots in the control of a cyber criminal (the "bot master"). Botnets are used by cyber criminals for a variety of malicious purposes. For example, they might rent their botnet to perform distributed denial of service (DDoS) attacks against websites or they're tasked with penetrating enterprise defenses and looking for valuable data. Bot masters control botnets by providing them with instructions that dictate the malicious activities the bot undertakes. Bots receive instructions by communicating with a server controlled by the bot master, known as command and control (C&C).

What can an enterprise do? Should BYOD be banned? Not without revolt, likely. In part two I'll discuss a DNS-based approach you can use to reduce the risks of allowing BYOD on your network.

By Pat Barnes, Product Manager of Security Solutions at Nominum

Related topics: Cybersecurity, DNS

 
   

Comments

Way too short - you might put a bit more than just the teaser paragraphs in, next time. Suresh Ramasubramanian  –  Jan 22, 2013 8:14 PM PDT

That said, yes, DNS jails, device firewall policies etc (and metrics from those) are absolutely necessary for byod deployment.

To post comments, please login or create an account.

Related Blogs

Related News

Explore Topics

Dig Deeper

Afilias

DNS Security

Sponsored by Afilias
Afilias Mobile & Web Services

Mobile Internet

Sponsored by Afilias Mobile & Web Services
Verisign

Cybersecurity

Sponsored by Verisign

Promoted Posts

Now Is the Time for .eco

.eco launches globally at 16:00 UTC on April 25, 2017, when domains will be available on a first-come, first-serve basis. .eco is for businesses, non-profits and people committed to positive change for the planet. See list of registrars offering .eco more»

Boston Ivy Gets Competitive With Its TLDs, Offers Registrars New Wholesale Pricing

With a mission to make its top-level domains available to the broadest market possible, Boston Ivy has permanently reduced its registration, renewal and transfer prices for .Broker, .Forex, .Markets and .Trading. more»

Industry Updates – Sponsored Posts

Attacks Decrease by 23 Precent in 1st Quarter While Peak Attack Sizes Increase: DDoS Trends Report

Leading Internet Associations Strengthen Cooperation

Global Domain Name Registrations Reach 329.3 Million, 2.3 Million Growth in Last Quarter of 2016

Verisign Releases Q4 2016 DDoS Trends Report: 167% Increase in Average Peak Attack from 2015 to 2016

Neustar to be Acquired by Private Investment Group Led by Golden Gate Capital

Verisign Q3 2016 DDoS Trends Report: User Datagram Protocol (UDP) Flood Attacks Continue to Dominate

2016 U.S. Election: An Internet Forecast

Government Guidance for Email Authentication Has Arrived in USA and UK

ValiMail Raises $12M for Its Email Authentication Service

Don't Gamble With Your DNS

Defending Against Layer 7 DDoS Attacks

Understanding the Risks of the Dark Web

New TLD? Make Sure It's Secure

Verisign Releases Q2 2016 DDoS Trends Report - Layer 7 DDoS Attacks a Growing Trend

How Savvy DDoS Attackers Are Using DNSSEC Against Us

Radix Adds Dyn as a DNS Service Provider

Facilitating a Trusted Web Space for Financial Service Professionals

MarkMonitor Partners with CYREN to Deepen Visibility into Global Phishing Attacks

Verisign Named to the Online Trust Alliance's 2016 Honor Roll

Dyn Partners with the Internet Systems Consortium to Host Global F-Root Nameservers