Presentation is loading. Please wait.

Presentation is loading. Please wait.

Securing Your DNS Infrastructure in 5 Minutes

Similar presentations


Presentation on theme: "Securing Your DNS Infrastructure in 5 Minutes"— Presentation transcript:

1 Securing Your DNS Infrastructure in 5 Minutes
Allan Liska Securing Your DNS Infrastructure in 5 Minutes

2 About Me 15+ Years Experience in Security
Solutions Architect at Recorded Future Writes about: Security, Intelligence, DNS, Ransomware and NTP. Contact me:

3 Despite Its Importance, DNS Security is often Overlooked
This presentation is a 15-point checklist for improving your DNS security

4 1. What domains does your organization have, who registered them & when do they expire?

5 2. Where Are They Registered?

6 3. Centralize control of domains & create a domain registration policy

7 4. Enable Registrar 2-Factor Authentication

8 5. Lock Domains to Prevent Updates/Transfers

9 6. Enable DNSSEC for your Domains

10 7. Host Primary and Secondary DNS with Different Registrars

11 8. Pen-Test Your Registrars (NOT THEIR NETWORK!)

12 Musical Interlude

13 9. Use Split-View Recursive DNS

14 10. Patch your recursive DNS server

15 11. Block all outgoing traffic on TCP/UDP port 53 at the firewall
Except, of course, traffic from your recursive DNS server…

16 12. Enable RPZs/Blacklists

17 13. Log DNS Traffic

18 14. MONITOR THE LOGS MONITOR THE LOGS MONITOR THE LOGS

19 15. Document all of the steps

20


Download ppt "Securing Your DNS Infrastructure in 5 Minutes"

Similar presentations


Ads by Google