NSA Recommends Using Only Designated DNS Resolvers

  /     /     /  
Publicated : 23/11/2024   Category : security


NSA Recommends Using Only Designated DNS Resolvers


Agency provides guidelines on securely deploying DNS over HTTPS, aka DoH.



The National Security Agency (NSA) has issued an advisory recommending that enterprises employ only their designated DNS resolver for DNS traffic and avoid third-party resolvers, which could place their data at risk.
NSA said encrypted Domain Name System (DNS) technology, aka DNS over HTTPS (DoH), can be abused by attackers if its not properly deployed in an enterprise. Using only the organizations designated enterprise DNS server for both encrypted or unencrypted DNS traffic is the safest route. All other DNS resolvers should be disabled and blocked, the agency said.
DHS, which converts domain names into IP addresses on the Internet, increasingly has become a popular attack vector for attackers. The NSA published new guidelines for rolling out DoH securely,
Adopting Encrypted DNS in Enterprise Environments
.
It outlines the importance of configuring enterprise networks appropriately to add benefits to, and not hinder, their DNS security controls. These enterprise DNS controls can prevent numerous threat techniques used by cyber threat actors for initial access, command and control, and exfiltration, the NSA said.
Read more
here


Last News

▸ ArcSight prepares for future at user conference post HP acquisition. ◂
Discovered: 07/01/2025
Category: security

▸ Samsung Epic 4G: First To Use Media Hub ◂
Discovered: 07/01/2025
Category: security

▸ Many third-party software fails security tests ◂
Discovered: 07/01/2025
Category: security


Cyber Security Categories
Google Dorks Database
Exploits Vulnerability
Exploit Shellcodes

CVE List
Tools/Apps
News/Aarticles

Phishing Database
Deepfake Detection
Trends/Statistics & Live Infos



Tags:
NSA Recommends Using Only Designated DNS Resolvers