MENU

Rohde & Schwarz’ cybersecurity tools strengthen firewall protection

Rohde & Schwarz’ cybersecurity tools strengthen firewall protection

New Products |
By eeNews Europe



The OEM deep packet inspection software R&S PACE 2 now improves the reliability and credibility of network protection solutions. When embedded in a firewall, malicious attacks that bypass common security policies via DNS tunnelling can be identified and prevented.

 

DNS is a core component of the Internet and of paramount importance to the operation of the World Wide Web. It provides the mapping service between a domain name and the corresponding IP, translating human-friendly domain names into IP addresses.

 

As DNS is a trusted protocol it is often overlooked for security as no one considers using the protocol for data transmission. The use of DNS, especially with port 53, for data theft is called DNS tunnelling. In tunnelling, cybercriminals use the DNS protocol as an established pathway to direct the exchange of information for malicious purposes. Several tools have been developed to bypass traditional IPS or firewall inspection and network security measures to reach the Internet.

 

 

With the enhanced DNS tunnelling detection functionality of the DPI engine R&S PACE 2, Rohde & Schwarz Cybersecurity now provides a highly scalable OEM software solution for network protection products. When embedded in a firewall, IT security vendors are able to inspect the entire DNS query for deeper markers of either good or bad behaviour. This way, malicious attacks that bypass common security policies via DNS tunnelling can be identified and prevented.

 

According to the DNS Threat Survey 2017 by Efficient IP, 94% claim DNS security is critical for their business. This is not surprising as in the past year, 76% of organizations around the world have been subjected to a DNS attack and a third suffered data theft. In addition, DNS tunnelling was one of the leading causes, alongside malware, DDoS and cache poisoning attacks.

 

Besides the ability to detect DNS tunnelling, R&S PACE 2 also provides reliable detection of tunnelling in the HTTP protocol.

 

The R&S PACE 2 DPI software library provides powerful and reliable detection and classification of thousands of applications and protocols by combining deep packet inspection and behavioural traffic analysis – regardless of whether the protocols use advanced obfuscation, port-hopping techniques or encryption. DPI is, R&S concludes, needed everywhere in the network where intelligent decisions need to be made based on the nature of IP traffic, whether it is wanted or unwanted traffic, good or malicious.

 

Rohde & Schwarz; www.rohde-schwarz.com

 

 

If you enjoyed this article, you will like the following ones: don't miss them by subscribing to :    eeNews on Google News

Share:

Linked Articles
10s