TCI RED Web Protection

The domain name system (DNS) is one of the most critical elements in the network, and nearly all network applications rely on DNS to establish connectivity between hosts. Due to its criticality, DNS is often deliberately left open and unfiltered on corporate firewalls, effectively being a fire hose for information entering and exiting your network. As a consequence of this historical trend by security vendors to ignore DNS it is quickly becoming a favorite of hackers, botnet owners, malware authors, and other malicious actors on the Internet.

Unlike existing Web security applications and appliances, TCI RED Web Protection provides complete inspection, filtering, protection and reporting on the DNS traffic entering and exiting your network, enabling complete inbound and outbound network protection for IT administrators.

TCI RED Web Protection proactively stops threats designed to infect your network’s computers – reducing employee productivity, compromising sensitive (proprietary) information, and increasing costs. Malware (inbound) and botnet (outbound) infections can seize network resources to commit denial of service attacks, steal confidential data from within your network, and waste precious bandwidth and computer resources.

Consider a compromised machine on your network, infected via a USB stick or email attachment. Nearly all malware today will “phone home” often over non-Web traffic to a malicious botnet host using DNS to communicate with its master. Malware uses DNS because hardcoding an IP address is too easy to thwart by security vendors. By using DNS, malware authors hope that they can constantly hop from domain name to domain name, or frequently update the IP address a domain points to in order to evade take-down efforts by the security community. By using TCI RED Web Protection, it doesn’t matter if the domain is active or not: it can be blocked from resolving on your network immediately. This effectively cuts malware off at the knees. Not to mention, TCI RED Web Protection can now alert the IT administrator to the compromise so further remediation efforts can take place.

TCI RED Web Protection secures the DNS layer to block these attacks before they have a chance to infect your network. Like a firewall for DNS, TCI RED Web Protection is application agnostic and can control any traffic that relies on DNS — not just Web traffic — without increasing latency.

In fact, TCI RED Web Protection often speeds up domain resolution for users. One of the most appealing aspects of TCI RED Web Protection is that because it is a service, there is no expensive appliance to buy or software that needs to be installed on every computer or device in your network. This means TCI RED Web Protection can protect all the devices on your network, regardless of operating system or platform.

And, best of all, TCI RED Web Protection is easy to implement: a quick change on your router, gateway or DHCP server is all that’s required to secure your network. No intrusive proxy-based traffic redirection is required on devices or anywhere in the network. The protection is comprehensive — any managed employee or unmanaged guest device accessing your network, when your network is secured by TCI RED Web Protection, is protected.

It’s worth recognizing that TCI RED Web Protection can complement existing security solutions. Unlike hardware appliances that often require a rip-and-replace mentality, TCI RED Web Protection believes in a defense-in-depth strategy and encourages a heterogeneous network security strategy.

As a security solution that proactively filters malicious DNS traffic and only allows legitimate DNS traffic into and out of your network, every major threat on the Internet is blocked from reaching the network. It is entirely a new layer of protection for your organization. Working on the DNS layer, TCI RED Web Protection operates as a lightweight, no-latency protection point that blocks malicious traffic.