I’m thrilled to announce our collaboration with Google Cloud with the launch of DNS Armor. Our partnership with Google Cloud represents a strategic milestone in our commitment to innovation and mission to enhance cloud security.
Our partnership announcement includes two components—Infoblox Universal DDI™ for Cloud WAN and DNS Armor, powered by Infoblox. In this blog, I’ll touch upon how we are enhancing security for Google Cloud workloads. You can read about how we are addressing networking challenges for distributed sites with Universal DDI for Cloud WAN in our blog
“Transforming Enterprise Networking: Infoblox Partners with Google Cloud” by Padmini Kao, Executive Vice President, Engineering at Infoblox.
The Enterprise Security Challenge
Moving workloads to the cloud comes with its own set of challenges. Traditional security measures often fall short, detecting malware only after it has already caused damage. This reactive approach just isn’t enough anymore. On top of that, advanced attacks, like DNS tunneling, zero-day DNS and domain generation algorithms (DGAs) require real-time inspection of DNS traffic to catch them early. Managing security across multiple environments can be a complex task, and compliance is always a growing concern. These challenges highlight the need for more proactive and integrated security solutions to keep cloud workloads safe.
What Is DNS Armor?
DNS Armor, powered by Infoblox, is a next-generation Protective DNS solution from Google Cloud. By leveraging Infoblox’s deep expertise in DNS-focused threat intelligence and Google Cloud’s scalable infrastructure, DNS Armor provides advanced threat detection of malicious activity for Google Cloud workloads. This innovative service empowers Google Cloud administrators to monitor DNS queries and access real-time DNS threat logs, enabling early threat detection and a proactive security posture.
Why DNS Armor Is Essential
In today’s rapidly evolving threat landscape, securing cloud workloads is more challenging than ever. Advanced threats are constantly evolving—from attacks that exploit vulnerabilities on cloud workloads and phishing scams on virtual desktops, to compromised identity credentials, malware/ransomware delivered through command-and-control servers, data exfiltration attempts, or prompt injection attacks on AI apps.
Every attack starts with a DNS query—when a cloud workload tries to connect to a potentially malicious domain. By monitoring these DNS queries, organizations can detect early signs of compromise. If an application unknowingly reaches out to a bad actor-controlled site, it’s a clear signal something is amiss.
DNS Armor takes advantage of the visibility Infoblox provides to 70 billion DNS events daily to help find DNS-based attacks with an astoundingly low false positive rate of just 0.0002%. This visibility significantly reduces the risk of malware, data breaches and cyberattacks for Google Cloud customers.
DNS Armor is an essential component of any organization’s preemptive cybersecurity strategy.
Figure 1: DNS Armor architecture
Key Features and Benefits of DNS Armor
- Preemptive Cyber Defense: Leverages Infoblox’s industry-leading Protective DNS capabilities and DNS-powered threat intelligence to detect threats, such as malware, high-risk domains, zero-day DNS, DGAs and data exfiltration, in real time.
- Native Integration: Eliminates the need for additional tools by fully embedding within the Google Cloud console, simplifying activation, configuration and management.
- Operational Efficiency: Strengthens security without adding complexity, ensuring robust threat detection for your cloud workloads with minimal operational impact.
- Cloud-Native Scalability: Scales with your workloads, delivering high performance and reliability even during peak demands.
DNS Armor will be available from Google Cloud later this year, and can be enabled natively in Google Cloud directly, allowing customers to detect threats for their VPCs.
Join Us at Google Cloud Next
We invite you to join us at Next 25, where we will announce DNS Armor. Come by our booth 3436 to learn more about this next-generation Protective DNS solution and discover how it can elevate your cloud security posture.
Stay tuned for more updates as we continue to collaborate with Google Cloud to deliver leading cloud-native DNS security solutions.