Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

BloxOne Threat Defense integrates threat intelligence feeds, security policies, and advanced analytics to strengthen your network security, protecting you from escalating cyber threats that can adversely affect your business.

To begin protecting your network infrastructure using BloxOne Threat Defense, you define a network scope to which you apply security configuration via the Cloud Services Portal. The network scope can include your company's public networks, roaming end users, and on-premises networks (including the NIOS Grid). You can then configure custom lists, add filters, and apply security policies to the network scope. Based on your subscription level, BloxOne Threat Defense automatically applies threat intelligence feeds to your defined networks. In addition to providing secure DNS resolution in the cloud, BloxOne Threat Defense combines advanced analytics based on machine learning, highly accurate and aggregated threat intelligence, and automation to detect and prevent a broad range of threats, including DGA families, data exfiltration, look-alike domain use, fast flux, and others. These analytic tools include reports, active indicators, threat lab, Dossier research, and TIDE (Threat Intelligence Data Exchange), all working together to provide insight into your network security and visibility into infected and compromised devices.

The following illustration describes the high-level workflow of the BloxOne Threat Defense deployment:

Image RemovedImage Added

Complete the following steps to deploy BloxOne Threat Defense:

  1. Define the scope of networks you would like to protect from malicious attack via the Cloud Service Portal:
  2. Set up initial security configuration on the defined network scope by doing the following:
  3. Configure security rules and policies, or point your networks to a redirect page:
  4. Using advanced analytics, BloxOne Threat Defense provides reports that you use to analyze DNS traffic, so you can monitor how the security configuration protects your networks.
    BloxOne provides a list of available reports. To view available reports, see Viewing Reports.

    You can also view get high-level statistics by viewing the Dashboards, For more information, see Viewing the Dashboards.

    Independent of reporting, you can always use Dossier research, active indicators, and threat lab to investigate suspicious domains and decide what action you might want to take.

...

Excerpt
hiddentrue

Drawio
mVer2
simple0
zoom1
inComment0
custContentId244351421
pageId9083972
diagramDisplayNameB1TDHighLevelSteps
lbox1
contentVer1112
revision1112
baseUrlhttps://infoblox-docs.atlassian.net/wiki
diagramNameUntitled Diagram-1684880996123.drawio
pCenter1
width1002
links
tbstyle
height376411.5