The Ten Year Protective DNS Journey with Infoblox
DNS is no longer just infrastructure — it is the frontline of preemptive security. This session highlights Infoblox’s decade-long journey in shaping DNS security, with Protective DNS at the center of defending users against evolving threats. Attendees will see why DNS is uniquely positioned to stop attacks before they spread and how DDI integration delivers powerful visibility, automation, and protection. Speaker Mukesh Gupta detailed Infoblox’s evolution from an enterprise appliance company known for DDI (DNS, DHCP, and IPAM) to a security-focused organization. He explained that as enterprises adopted multiple cloud platforms, they ended up with siloed DNS systems (e.g., on-prem, AWS Route 53, Azure DNS), leading to complexity and outages. Infoblox addressed this by creating “Universal DDI,” a platform that provides a single management layer for all of a customer’s disparate DNS services, whether they are on-premises or in the cloud, and offers a true SaaS-based option for DDI services.
Gupta emphasized that DNS is the first point of detection for nearly all types of cyberattacks—from phishing and malware to data exfiltration—because a DNS query always precedes the malicious action. Blocking threats at this initial DNS layer is highly effective, protecting all devices on the network without deploying new agents and significantly reducing the load on other security tools like firewalls and XDRs. Infoblox’s unique approach, developed by a former NSA expert, focuses on tracking the cybercriminal “cartels” rather than individual attacks. Instead of chasing millions of malicious domains (the “drug dealers”), Infoblox identifies and monitors the infrastructure of organizations like “Prolific Puma” (a malicious URL shortening service) or “VainWiper” (a malicious traffic distribution system) that service thousands of attackers. This “cartel”-focused strategy provides a significant strategic advantage.
The primary benefits of this unique approach are a massive lead time and incredible accuracy. Infoblox can identify malicious domains an average of 68 days before they are used in a campaign, often right after the cartel registers them, allowing for preemptive blocking without waiting for a “patient zero.” This methodology also results in an extremely low false positive rate (0.0002%). Gupta argued that integrating this protection directly into the DDI platform is more operationally efficient, as it prevents finger-pointing between network and security teams when a domain is blocked. Infoblox is now extending this protection to cloud workloads, either by having customers point their cloud DNS to Infoblox’s service or through native integrations, such as the new Google Cloud DNS Armor service, which is powered by Infoblox’s threat intelligence technology.
Presented by Mukesh Gupta, Executive Vice President & Chief Products Officer. Recorded live at Security Field Day 14 in Silicon Valley on September 24, 2025. Watch the entire presentation at https://techfieldday.com/appearance/infoblox-presents-at-security-field-day-14/ or visit https://techfieldday.com/event/xfd14/ or https://Infoblox.com for more information.
Transcript
Thank you so much for giving us the opportunity to talk about our unique approach to using DNS, uh, to fight cyber crime. That's what we will focus on today. We've talked about DNS enough in the past, but today we are gonna talk about cybersecurity.
Uh, my name is eSSH Gupta. I am Chief Product Officer here at Infoblox. Uh, joined the company about two years ago now.
Before that, spent four and a half years at Palo Alto Networks, building the software firewalls for that. Spent six years at a company called Lumia, um, built microsegmentation solution. I was the first product manager at Lumia, so we got the opportunity to build that pretty much from scratch.
And before that, Juniper ax firewalls net, um, firewalls, checkpoint Nokia firewalls, lots of firewall experience in the past. Um, I would start with, I don't know how much you know about info blocks, so I'll start with overview and evolution of info blocks. Um, but I'll try to keep that, you know, as short as I can.
Uh, then I would talk about why use DNS to fight cyber crime, uh, why DNS is a really, uh, effective way of fighting cyber crime. Um, now I'll talk about our unique approach. You know, there's something unique that we have figured out, uh, how to use DNS to fight cyber crime.
So I'll try to explain that to you. Uh, one thing that comes up all the time when I talk to customers is, should I turn this on, on Infoblox, or should I turn this on, on Palo Alto or Zscaler? So I'll share my thoughts on what I hear from customers, why you should turn it on on Infoblox.
And then lastly, I'll talk about how you can use protective DNS to protect the cloud workloads as well, not just your users. Okay, so these are the things I'll talk about here is a little bit of history. So the company's about 25 years old.
Uh, we started by building a DNS appliance. Uh, like Tom was saying, um, it's always DNS people who are using Microsoft or open source things like bind to run enterprise DNS. And that wasn't working very well.
Infoblox caught that opportunity, built this enterprise grade DNS, uh, appliance, and became famous for it. So that's where we started. Uh, five years later, uh, company realized that DHCP is the other thing that has similar attributes.
So we expanded into DHCP and with DHCP comes IP address management. And we invented this, this term called DDI. Most people don't know what that is.
It's D-N-S-D-H-C-P and IPAM. So that's what DDI stands for. And, and that's the category we created.
Um, the company went public in 2012, so we are publicly listed company. In 2016 is where our security journey started. We come acquired a company called IID, and that's where Infoblox went into security.
Uh, so that's where that tenure of journey comes from. We were acquired by Vista in 2016. So we, we are now privately owned by two PE firms.
Vista started it in 2016, then we sold half of info blocks to Warburg Pincus. So we are half, half owned by Vista and Warburg. Uh, right now, uh, we launch our cloud-based threat defense service, which we will dig into today a lot.
Uh, in 2019, we launch our SaaS based DDI from going away from appliances and offering a SaaS service. That happened in 2019 as well. Uh, big event in 2023.
Uh, Scott Harrell, who came from Cisco, took over, uh, as the new CEO, uh, brought me in as the new CPO. And now we are trying to transform the company together. The two important things we did, uh, in last two years, one is we started publishing research on these DNS space.
Uh, you know, cartels that we detect that I I'll talk about. Uh, so first one was Decoy Dog. That, and, and now we have published a whole bunch more.
And the other thing that we did last year is we launched something we call Universal DDI, and I'll touch on that as well. So that's kind of where we are as a company. Um, 13,000 plus customers, 92 of the Fortune hundreds are Infoblox customers, 75%.
The Fortune 500 are Infoblox customers. So we are very successful at the large enterprise, you know, and pretty much all verticals. Uh, as you can see location wise, we are headquartered right here.
Our office is literally three minutes away from this hotel. Uh, so that's where headquarters is. Uh, we have big engineering sites in Washington, Tacoma, uh, which is near Seattle.
Uh, one in Bangalore and one in Burnaby, Canada. So those are main, uh, engineering, uh, sites. And then we have sales offices, of course, now we went in the work.
So product wise, the evolution is we started with something we call nios, uh, network Identity Operating System. That was our original DDI solution. It was hardware appliance first.
Then we also released virtual appliances. Uh, there are two parts to it. One is the management layer that we call grid management.
So you can manage a whole bunch of D-N-S-D-H-C-P servers, and those are the protocol servers. So it's super simple that there is the grid management and the whole bunch of protocol servers that customers deploy. Um, over time what happened was customers started going to cloud.
So all clouds come with built-in DNS. Uh, AWS has Route 53. Azure has Azure.
D-N-S-G-C-P has G-C-P-D-N-S. So cloud teams love to just use the native solution. Uh, so most customers end up with five different DNS systems.
And as Tom was saying, something breaks because DNS connects everything, it's always DNS, and they end up with a whole bunch of outages because you're dealing with five different system. So that became a big problem in 2019. We launched our FA first, uh, SaaS service that offered D-N-S-D-H-C-P and ipam.
Um, the management part was SaaS. The protocol servers were still virtual appliances or hardware appliances. Uh, so that's where we were in 2023.
Uh, the company made two big mistakes by doing that SaaS service. First, we call it SaaS, but it wasn't true SaaS. You still had to deploy appliances, so that was a problem.
The second problem the company created is the IO solution. And the blocks one solution. There were two separate solutions, and they didn't work together.
Uh, so our customers were already suffering from five different DDI solutions. We added two more to make their lives worse. So in 2023, we realized that the critical problem that they're all dealing with is these four five siloed different DNS systems.
Uh, so we pivoted our platform strategy in 2023 and came up with this brand new thing called Universal DDI. And so I'll explain what that is. Uh, universal DDI is new product suite We launched last year.
Uh, you'd see that new tag. Those are the protocol delivery. We had the physical servers and the virtual servers.
We added a true SaaS option to it. So just like in sass e you just connect to a SASS e service and everything is delivered as a cloud service. That NS X as a service delivers D-N-S-D-H-C-P and NTP as a cloud service.
So you don't have to deploy any appliances, you just connect to the service. And we do D-N-S-D-H-C-P and and IPM completely as a service. So that's something new we added.
So customers that were looking for a pure SaaS service, they can now that have that option. Um, also, we, we embraced the, the fact that our customers are using third party DNS systems, like Route 53, Azure, DNS, and G-C-P-D-N-S. Uh, so we created this management layer on top that's called Universal DNS Management.
What that means is you can use Route 53 and AWS, you can use G-C-P-D-N-S and GCP, but Infoblox allows you to manage all of it in one place. Uh, so Universal DNS then allows customers to manage all of them in one place, and that solves a whole bunch of problems for them. Uh, also includes universal ipam.
So we can now scan their cloud environments, find all the subnets that the cloud teams deployed that the network team had no idea about, which happens quite a lot. We can find dangling DNS records, uh, and solve some other security problems as well. So that's universal.
DDI. The asset insight piece that you see is the ability to detect and collect all the assets that our customers have on the network. And this is a big problem.
We solved this problem on the on-prem side by scanning their network and bringing that into ipam. Uh, last year we also added the ability to scan the cloud environments and bring that into IPM as well. So, so that's Universal Asset Insights.
And then lastly, we took our SaaS management portal and we extended that to our N os as well. So now if you have NIOS in some places and you have sas, TDI, you can manage it all from one place. So that's the universal.
Um, most customers have, uh, public cloud on-prem stuff. We allow them to universally manage DNSD, HCP and ipam. That's what Universal DDI is.
Okay, I'm gonna focus on security today, but I just wanted to give you, uh, a little bit of evolution. Any questions so far? Everything making sense?
Good. So let's talk about security. This is the motherhood and apple pie.
What's going on with the threat landscape? Uh, I'll give you my view. I like to think about the threat landscape in three dimensions.
The number of attacks, uh, that, that we are seeing every day, because the more attacks we see, the probability that you get hit is higher. The second is the sophistication of the attacks. The more sophisticated they get, the higher it gets for our customers to fight against them.
And Genai is clearly making, you know, strides there. Uh, we are starting to see, uh, you know, good companies using three, four developers to get to a hundred million a r using genai. We're also starting to see a small group of attackers trying to bring a country down using genai.
So sophistication is going up. And the third dimension is the impact. Um, what happens when you get hit?
Um, we were seeing before, you know, CEOs and CIOs getting fired. Now we are seeing human lives getting lost, uh, because of these cyber attacks, right? So, so that's the world we are living in.
Uh, bunch of numbers on the slide that you could read, but this is, uh, a turning point. This is the first piece of malware, publicly disclosed malware that's using Gen AI to completely evolve itself runtime using Gen AI to come up with the commands they use. So all the signature based detection tools that the industry has built are gonna fail against this piece of malware because it's just continuously updating itself.
Uh, and you are always going to catch up against it. So this is the first one. I am pretty sure we will start seeing more and more of these things, but I just wanted to bring that to your attention.
Now, one thing that people don't realize, most of the times our customers don't realize this as well. Um, they think of DNS as something attackers use to exfiltrate data to connect to command and control centers. 'cause DNS is allowed everywhere.
So they just use those pathways to do bad stuff. But what they don't realize is DNS is actually the first point of detection or prevention for all types of cyber attacks, not just the ones that are using DNS. Think about these four scenarios.
If you get a phishing email or a ING text, or you have this new thing called ing, which is a QR code with a malicious URL, uh, in it, you click on any of those things, the first thing that happens is a DNS query, uh, to that bad URL, right? The second way cus uh, attackers, uh, come into your infrastructure is they exploit some vulnerability that you have. And you are always trying to catch up with fixing these vulnerabilities.
But what happens after they exploit that vulnerability, they connect to a command and control center and they download malware, ransomware, or something bad on that machine. Nothing bad has happened after just the exploit. It happens after they connect to that command and control center.
And guess what, the first thing that happens is a DNS query to that command and control center. The third thing is, if they somehow got in and they're trying to exfiltrate data data, and it's not just DNS, they could be uploading it to, you know, a, a DN a a a server sitting somewhere on the internet. They could be uploading it to an S3 bucket in AWS.
But the first thing that will happen again, is the first DNS query before they start exfiltrating data. So not just D-N-S-D-N-S based, of course, we, we will detect it with DNS, but non DNS based uploads can also be detected and blocked, uh, by DNS. And the last one is in ai.
If someone is doing prompt injection attacks or something similar, even there, there would be a DNS query to something batch. So my point here is no matter what kind of attack you seek, there always a query DNS query, do something malicious before anything bad happens. So I would like you to imagine that if you had a shield around, uh, your organization that allowed the good DNS queries out, but blocked all the bad DNS queries, you would be be able to protect yourself, uh, against all types of attacks, right?
Um, because DNS is the first thing that happens, if you block it, your command and control center connections will be blocked. Your data exfiltration attempts would be blocked, your phishing emails would be blocked. So everything can be blocked at that DNS layer.
Uh, two good things about DNS if you did this first, everything in your infrastructure is already connecting to DNS. So you don't have to deploy any new tools. You don't have to deploy anything on the network.
You just have to flip a switch on your DNS server and everything is already talking to DNS server. And suddenly you are protecting, uh, your users, your mobile endpoints, your IOT devices, your cloud workloads, your data center servers, because everything is talking to DNS, right? So that's really easy way to turn this on and, and deploy it.
The second is because DNS is the first thing that happens. Um, if you blocked that, all the other security tools would stay quiet. Your XDR tools, your firewalls will not see all this bad traffic.
Uh, your SIEM tools, your Splunk is not gonna see, you know, thousands of logs coming from all, all the security tools because you cut the problem at the source. So everything quiets down. Um, when we talk to our customers who've deployed this, turned this on, uh, they tell us, some of them tell us that they saw, uh, 50% reduction on their traffic, on their load, on their firewalls, uh, when they, you know, started blocking these bad DNS queries.
And in some cases, their firewall teams literally panicked, uh, thinking something bad had happened, uh, why their Palo Alto firewalls were suddenly seeing 40%, 50% less traffic. It was because all the malicious traffic does not go on your network once you block that DNS query. So how do you do this?
Because, um, DNS is everywhere. Uh, you, you can start blocking these bad DNS queries, but if you block good DNS queries, then things are gonna break. People are gonna complain.
So you really have to be careful, uh, so you block the bad ones, but you not block the good ones. And that's the trick. So that's the unique approach, uh, that we have come up with.
So we can block all the bad DNS queries, but not create false positives. And it originated from, uh, Dr. Renee Burton, who we hired from NSA, uh, she was at D-O-D-N-S-A, uh, for 22 years, uh, before she joined Infoblox as head of our threat intel team.
And one of the things she did there was, uh, use DNS to, to catch cyber criminals using DNS. So she actually invented this approach, uh, at NSA and brought that approach to, to, uh, and I'm gonna explain that approach using an analogy so it makes sense to you. Um, think of a city that is infected with a drug problem.
There are two ways you could clean up that city. Your first approach would be to go after the drug dealers. And if you go after the drug dealers, there will be a lot of drug dealers in a big city, and they'll be at, you know, schools and colleges and street corners, and you'll have to hunt them down.
And as you eliminate them, the new ones keep popping up. So you end up playing this game of vamo if you go after the, the, the drug dealers, right? Um, the second approach is to go after the drug cartel that's supplying the drugs to the city.
Now, that is much harder, but generally there's either one or at max two cartels. If you knock them down, then you don't have to worry about the drug dealers. They just disappear, right?
So much more effective way of cleaning the city. So now let me map this to our unique approach. I'll give you one example of such a cartel in cyber world.
Everybody I'm assuming is, uh, familiar with Bitly. Bitly is a URL shortening service that all of us use when we need to shorten our URLs. Now guess what?
Attackers also need, uh, A URL shortening service. So all those USPS messages that you get on your phone, uh, or FedEx delivery messages, they all have these shortened URLs. Where do they come from?
They don't come from Bitly because Bitly doesn't allow, uh, attackers to use their service. There is a company like Bitly in the cyber world, uh, we have named them prolific Puma. And you'll hear these, you know, names that our threat intel team comes up with.
That company does not attack anybody. They are in the business of serving URL shortening services to all the attackers. So there are millions of attackers.
They all use prolific Puma for shortening the URLs. That company has purchased 75,000 domains just in last two years. What they do is, as these attackers are using URL shortening service, and that domain gets blocked by, you know, the security tools, they just move on to the next one, to the next one, to the next one, and they just keep going.
It's really easy to buy domains. So nobody is gonna run out of domains. So that's what they're doing.
If you go after the attackers and those shortened URLs and you block them in Palo Alto or Wire Total and all these tools, then they just move on to the next one. But we are tracking prolific Puma. We are tracking their DNS infrastructure.
We are tracking all the domains that they register to the registrars. Uh, and that's how we are catching all these bad things. We're not going after the shortened URLs that are used in phishing campaigns.
We are tracking prolific Puma. So that's the example of a cartel. Here is another cartel.
Uh, we call them, uh, vein Viper, and we have a whole series of wipers. Uh, and Dave is gonna talk to you about what these do. But think of Google AdSense.
Google AdSense is a service that when you and I are going on news article, website, or even Tech Field Day website, you see ads, you see ads everywhere. Those ads are served by Google AdSense. Google AdSense is a big distributed service that is connecting the publishers like Tech Field Day or blogs, news websites to the advertisers so they can serve the right ads to the right people.
And this is why when you're trying to buy a shoe somewhere, you start seeing shoes everywhere, right? That's what Google AdSense does. Now, attackers also need something similar.
Uh, Google AdSense would not serve the attackers. So there is a company called Wayne Viper. They have built this traffic distribution system, and they connect the malicious advertisers that are trying to, uh, you know, sell fake, uh, scam schemes, investment schemes, or fake gift cards.
They connect them with the malicious or compromised publishers. So if a compromised website is there, instead of the attackers trying to put their code there, uh, they just give it to Wayne Weer. And Wayne Weer is trying to maximize, uh, the, the benefit for them, and that's the business they are in.
So Wayne Weer is not gonna attack anybody. They're just running this company making billions of dollars by running this operations. So again, we track Viper instead of tracking all the compromised websites.
So that's the the different approach we have taken. Um, we are tracking about 204,000 search cartels. So it's a lot of companies and all these companies are used by probably millions of attackers.
Since you're focusing on the drug dealers or the millions of attackers, we are focusing on the cartels, which are these 204,000, uh, cartels. Okay? Um, a hundred plus are big enough that we have named them.
Uh, so as you know, you would see in the product, our customers are able to see the names of these cartels. They're able to see what they do and all their infrastructure. So that's, that's the unique approach, uh, that powers threat defense that, that we would talk about.
Again, I'll pause any questions. Does this make sense? Yes.
Okay. So these are some of those cartels with the funny names we forgot to bring. We have soft toys with these characters as well that people really love.
So we can get those to you if you want it. Uh, but if you go to our threat Intel website, you would see, um, I don't know, maybe 13, 14. So far the big cartels that we have discovered in using these cartels, we have uncovered some serious, like crime criminal gangs that we have reported to FBI and, uh, and Anthrop o Uh, so we get involved in that.
Uh, we uncover all sorts of stuff that, you know, Dave would talk to you about. Uh, but that's the approach. What this approach allows us to do is, first it gives us a lead time.
We are able to see these bad domains almost 68 days before anybody else sees them. Why? Because we are not going after those domains.
When a phishing campaign is launched, we, we detected when they purchase that domain because we are tracking Van Viper and, and we know if they, um, purchase a domain, we know they're gonna do something bad with it. So we start blocking it then instead of waiting till they launch a campaign. So it gives us 68 d days lead time, it gives all of our customers 68 days.
Uh, so we are already blocking it. So even when the first query goes out to this bad domain, we block that because we knew about it. So we don't need to wait for patient zero.
We don't need to ba wait for the first, uh, signature because we already know that these domains are bad, right? So that's the first advantage we get. The second one is the probability that prolific Puma registers a domain and they're gonna do something good with it, or run a non-profit website, it's pretty much zero, right?
They're in the business of doing bad things. 0002%. That's three zeros in front of 10, right?
And it's because of that unique approach, we are going after the cartels and we are blocking domains there. Okay? So those are the two big benefits that we get out of that unique approach.
Quick question on this. Yeah. I know you can't share your secret sauce.
I don't want you to share your secret sauce, but you are not the only DNS secure player security player in the market, right? Why can't other providers do what you're doing? Why do you have that 68 day Yeah.
Advantage over other people who are trying to do the same type of protections that you do? Funny enough, I get asked that question all the time. So, um, my answer to this is, um, some of it is the expertise that we have built.
Some of it is the infrastructure and systems that we have built that are tracking all those cartels. Um, some of it is our threat intel team, um, members. But could someone copy this and do it?
Anybody can do anything. If you put enough money and time and focus on it, then yes. But so far, you know, we are advancing this approach.
We came up with it, you know, uh, a long time ago, and we have built over time. I don't think other players even understand it. So, uh, why all they see is, and our customers, you know, compare us with other tools and they see we block all sorts of stuff that's bad, but the other tools are not catching it, but they don't know why.
Like I, because I'm revealing here, not the full tech, but the approach, you're able to understand it's different. Uh, but I don't think anybody understands this different approach. Um, once they understand it, if they copied it, could they do it?
Probably, uh, we would still probably be ahead because of the lead time that we have, but could someone copy it? Absolutely. You think someone could probably Approach Edge some of that time down, but you still think you'd be ahead just because right?
You have a head Start. Because we already pack 200, 4,000 cartels. Someone starts doing it now, it'll, it'll take them some time and our number is going up.
Uh, you know, a few months ago it was 180, now it's 204. So it's just growing because new one, new companies are being launched in the cyber world doing all these bad things. So yeah, it's a catch up game.
Okay, any other questions? Good. That means everything is making sense.
Okay. So, um, I promised you to, to talk about this. So, um, a lot of customers that are trying threat defense ask us, should I turn this?
Like you said, um, should I do this on my firewall? My firewall also has DNS protection or my SASS e platform has DNS protection. Uh, and my, my answer, you know, when I was trying to figure this out, what should I say to these customers?
I asked a whole bunch of the customers that had purchased Threat Defense, and I said, why did you decide to, to do this on Infoblox? And their answer was this, that when a domain gets blocked, it could be because of two problems. Either it could be a security problem that, you know, domain is bad, so the security tool blocked it, or it could be a real DNS problem.
The DNS server is down or something is wrong with the DNS service and that's why it got blocked. So if they did it on SS e or firewall, then every time, and like Tom was saying, it's always DNS, you have two teams on that call trying to figure out is it a security problem? Should we go troubleshoot on, you know, the firewall or it's a DNS problem, we should troubleshoot on info blocks versus if you turn this on on info blocks, it's one team and they can take care of it, right?
So it's, this is the number one reason it comes up. You know, when I ask customers why you decided to do it on DDI platform, uh, they don't want two teams finger pointing at each other every time. You know, a domain, A DNS problem happens in this case, they can hold one team accountable, they own DNS and they own protective DNS.
Uh, so if it's a security problem or a real DNS problem, it's one team, uh, and it's operationally a lot more effective. So that's the reason. Uh, I just wanted to share, the last thing I wanted to share is, uh, how do we protect cloud workloads using the same Approach?
Can you go back one? Yes. So I, I like your compare and contrast between SSE uh, providers.
What about the people who say, well, you know, I already have an XDR tool that has DNS protections. Um, same thing. So when a client opens a ticket saying, I'm trying to go to this website and I can't, you'll have to have the XDR team on the call and you'll have to have the, the DNS Infoblox team because it could be blocked by DNS or, or, or broken DNS or XCR, right?
Again, you'll have to, I guess that's assuming that Infoblox is in the mix, right? So Argument, well, let's say it's not Infoblox, it's uh, some other DNS, it's Microsoft DNS, it's, uh, one of our competitors. Okay, you still have the same problem.
Let's say it's Route 53. Yeah, you still have the same problem. You have to look into Route 53 and you have to look into XDR and then figure out where the problem is.
And every time when someone reports, they can go to a u rl. It's just operationally very inefficient. I like the operational efficiency side of things.
Yeah. Is there any other components that you might bring to bear? Yeah, because yeah, everyone's always trying to figure out where to solve this, right?
Do I solve the endpoint? Do I solve the network? Right.
Solve DS provider, right? Is there any other argument that you guys would bring to bear to say, here's why we solve it at the DNS? Well, so that's the, the unique approach.
What you would see is, even though all the other providers claim to do DNS, when we run tests or our customers run tests, um, what we block because of that unique approach is like here, what you would see in other tools is here, right? I think we have a slide showing you that without the, so The science and the, the, the threat, right? So it's the efficacy, which is gonna be much higher, the probability that we will block it, catch it, and save you from, uh, you know, an attack is way higher Yeah.
Than all the other tools. And then, then second is this operational efficiency. Those are the two things that come Up.
Thank you. Mm-hmm. So, so we realized that, you know, all customers moving to cloud and all the cloud workloads have the same problems.
Um, our focus initially was, uh, threat defense will protect users like your endpoint clients, uh, branches, campuses, data centers, um, by being the DNS service in the middle. So we allow all good DNS queries, but we block all the bad ones. But if you look at the cloud workloads, uh, when they make DNS queries, it's going to route 53 or it's going to Azure DNS, or it's going to G-C-P-D-N-S and they have no protection.
AWS last year launched this, uh, advanced DNS firewall. So they have a little bit of protection. Um, it's weak at best, but Azure has no protection.
GCP has no protection. OCI has no protection. So literally, if a workload gets compromised and it's connecting to command and control centers and exfiltrating all the data, uh, at DNS layer, they won't detect anything.
It's just complete quiet, right? So we figured we should help our customers do that same protection, uh, for the cloud workloads. Uh, and we took our, uh, universal D-D-I-D-N-S as a service and we said, if you can point all your workload cloud workloads and their DNS settings to our service, then we will not only serve DNS, we'll also apply threat defense security there, and you'll be safe.
And instead of having to deal with four different DNS, uh, and DNS security solutions, you would just have one. Um, some customers love this. So they go, okay, we are gonna take all of our cloud environment and, and move, uh, their DNS to Infoblox so we can use this protection.
But we also have customers where the cloud teams go. No way in hell. Uh, I am moving away from G-C-P-D-N-S.
Why? I ask. And one of the customers said, DNS is the only service that has a hundred percent SLA in GCP.
I didn't know that a hundred percent SLA, um, that's the only service. So there is no way I'm switching away from Google DNS. So I said, okay.
So we said, then the only way we solve your problem is that we need to bring this protection to G-C-P-D-N-S. So we went and talked to GCP and we said, Hey, we wanna bring this, you know, protection to G-C-P-D-N-S natively so then customers can, uh, you know, get this protection without having to go away from Google DNS. And that's what we did with Google.
So last week, this service is in public public preview. It's a Google service. It's called Google Cloud, DNS Armor.
And it's powered by the same info blocks technology, uh, that's powers threat defense. So behind the scenes, uh, we have integrated our service, but customers don't see anything. All they see is powered by info blocks, you know, in the documentation.
Uh, so it's a hundred percent native GCP service. Uh, it's really easy to use. They can literally turn one button that says, protect my DNS traffic.
And it turns on. And then at that point, all the DNS queries are going to our service. And, uh, we would run it through the same cartel and size, same approach, and we report all the threads into Google Security Center.
Uh, so it's a hundred percent native. Uh, and I think Coupa is gonna double click on this a as well, a little bit, but that's the first one. Uh, we are working with other cloud providers on something similar.
Um, that's not public information, so I wouldn't talk about it. But our goal is to solve this in both ways. If customers are willing to switch their DNS, they can.
If they wanna keep G-C-P-D-N-S, we wanna bring the protection to them. And that's what we did. Okay.