{"id":4445,"date":"2013-09-27T11:47:02","date_gmt":"2013-09-27T18:47:02","guid":{"rendered":"https:\/\/blogs.infoblox.com\/?p=4445"},"modified":"2020-05-06T10:31:38","modified_gmt":"2020-05-06T17:31:38","slug":"partners-in-mitigating-crime","status":"publish","type":"post","link":"https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/","title":{"rendered":"Partners in (Mitigating) Crime"},"content":{"rendered":"<p>Last week the tech IPO scene was hot, with the FireEye and Rocket Fuel IPO fueling the fire (pun intended).<\/p>\n<p>It was a spectacular show and hardly anyone was surprised. The only differences of opinion were around what led to the spectacular success. Beyond the obvious leadership, timing, and being at right place at right time, the one that caught my attention involved the partner strategy.<\/p>\n<p>At a dinner with one of a prominent security VARs, someone pointed out that partnerships were critical from the stickiness perspective that led to the growth and market capture for FireEye over the last two years. In our earnings call for FY2013, Infoblox announced a similar partnership with FireEye (an extension of our DNS Firewall use case, which we discussed in an earlier blog). This was a classic example of customer-driven partnership and product development.<\/p>\n<p>The need for this kind of partnership is illustrated by the diagram below, which shows how, at every stage of the APT propagation, there is a DNS query to a malicious destination.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-4446\" src=\"https:\/\/blogs.infoblox.com\/wp-content\/uploads\/malware-life-cycle.png\" alt=\"Every step of malware life cycle relies on DNS\" width=\"904\" height=\"482\" srcset=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/malware-life-cycle.png 904w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/malware-life-cycle-300x160.png 300w, https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/malware-life-cycle-768x409.png 768w\" sizes=\"auto, (max-width: 904px) 100vw, 904px\" \/><\/p>\n<p>There may be several different stages and steps, but at the core there is a dropper download, calling home to get instructions or to exfiltrate data to an Internet destination. In every query, the way the malware client finds its destination is by looking for the domain name. It can obviously have an IP address in there to reach out directly, but most bad domains use techniques like fast fluxing at the backend that allow the domain names to be hosted and brought down at very high speed. Using IP addresses makes that hard to do and in addition takes away the flexibility to use infected grandma\u2019s PC that uses DHCP.<\/p>\n<p>We provide malware data feed service to our customers by identifying malware hosting destinations on the Internet. This works well for the known threats and botnets that are out there. However, APTs are different and unique in terms of how they operate. An APT is a targeted and tailored attack on a specific organization. As a result, the activity around it looks like a perfectly normal connection that is being made to a server on the Internet. Normal malware detection systems and research don\u2019t get triggered because the activity appears fairly benign.<\/p>\n<p>This is where FireEye\u2019s Virtual emulation technology and APT detection capabilities play a critical role. As FireEye identifies these organization-specific threats, a notification is sent to the DNS Firewall with the details on the domain. Any effort to reach to that destination is blocked from that point onward, containing the APT and preventing other clients from getting infected.<\/p>\n<p>The Infoblox IPAM solution with DHCP fingerprinting capability takes this to the next level by helping IT teams to quickly identify the infected source so that necessary remediation can be provided.<\/p>\n<p>So we\u2019re looking forward to releasing this integration between Infoblox and FireEye, and congratulations to our partner in (mitigating) crime, FireEye, for the great Wall Street score!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Last week the tech IPO scene was hot, with the FireEye and Rocket Fuel IPO fueling the fire (pun intended). It was a spectacular show and hardly anyone was surprised. The only differences of opinion were around what led to the spectacular success. Beyond the obvious leadership, timing, and being at right place at right [&hellip;]<\/p>\n","protected":false},"author":254,"featured_media":4416,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"_genesis_hide_title":false,"_genesis_hide_breadcrumbs":false,"_genesis_hide_singular_image":false,"_genesis_hide_footer_widgets":false,"_genesis_custom_body_class":"","_genesis_custom_post_class":"","_genesis_layout":"","footnotes":""},"categories":[2],"tags":[30,14,194,16,32,15],"class_list":{"0":"post-4445","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-security","8":"tag-dns","9":"tag-events","10":"tag-fireeye","11":"tag-infoblox","12":"tag-malware","13":"tag-security","14":"entry"},"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.3 (Yoast SEO v27.3) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Partners in (Mitigating) Crime<\/title>\n<meta name=\"description\" content=\"Last week the tech IPO scene was hot, with the FireEye and Rocket Fuel IPO fueling the fire (pun intended). It was a spectacular show and hardly\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Partners in (Mitigating) Crime\" \/>\n<meta property=\"og:description\" content=\"Last week the tech IPO scene was hot, with the FireEye and Rocket Fuel IPO fueling the fire (pun intended). It was a spectacular show and hardly\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/\" \/>\n<meta property=\"og:site_name\" content=\"Infoblox Blog\" \/>\n<meta property=\"article:published_time\" content=\"2013-09-27T18:47:02+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-05-06T17:31:38+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/visible-threat-featured-image.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"613\" \/>\n\t<meta property=\"og:image:height\" content=\"434\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Renuka Nadkarni\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Renuka Nadkarni\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/partners-in-mitigating-crime\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/partners-in-mitigating-crime\\\/\"},\"author\":{\"name\":\"Renuka Nadkarni\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/111901fc66473b7a5d5d6cf2ae869ef9\"},\"headline\":\"Partners in (Mitigating) Crime\",\"datePublished\":\"2013-09-27T18:47:02+00:00\",\"dateModified\":\"2020-05-06T17:31:38+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/partners-in-mitigating-crime\\\/\"},\"wordCount\":500,\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/partners-in-mitigating-crime\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/visible-threat-featured-image.jpg\",\"keywords\":[\"DNS\",\"Events\",\"FireEye\",\"Infoblox\",\"Malware\",\"Security\"],\"articleSection\":[\"Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/partners-in-mitigating-crime\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/partners-in-mitigating-crime\\\/\",\"name\":\"Partners in (Mitigating) Crime\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/partners-in-mitigating-crime\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/partners-in-mitigating-crime\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/visible-threat-featured-image.jpg\",\"datePublished\":\"2013-09-27T18:47:02+00:00\",\"dateModified\":\"2020-05-06T17:31:38+00:00\",\"description\":\"Last week the tech IPO scene was hot, with the FireEye and Rocket Fuel IPO fueling the fire (pun intended). It was a spectacular show and hardly\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/partners-in-mitigating-crime\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/partners-in-mitigating-crime\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/partners-in-mitigating-crime\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/visible-threat-featured-image.jpg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/visible-threat-featured-image.jpg\",\"width\":613,\"height\":434},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/security\\\/partners-in-mitigating-crime\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Security\",\"item\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/category\\\/security\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Partners in (Mitigating) Crime\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"name\":\"infoblox.com\\\/blog\\\/\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#organization\",\"name\":\"Infoblox\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"contentUrl\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/wp-content\\\/uploads\\\/infoblox-logo-2.svg\",\"width\":137,\"height\":30,\"caption\":\"Infoblox\"},\"image\":{\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/#\\\/schema\\\/person\\\/111901fc66473b7a5d5d6cf2ae869ef9\",\"name\":\"Renuka Nadkarni\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0661e443c4c379f0c36c9451f82921d754eda7aa497a8cbc3002b9c3a298bcce?s=96&d=blank&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0661e443c4c379f0c36c9451f82921d754eda7aa497a8cbc3002b9c3a298bcce?s=96&d=blank&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/0661e443c4c379f0c36c9451f82921d754eda7aa497a8cbc3002b9c3a298bcce?s=96&d=blank&r=g\",\"caption\":\"Renuka Nadkarni\"},\"url\":\"https:\\\/\\\/www.infoblox.com\\\/blog\\\/author\\\/renuka-nadkarni\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Partners in (Mitigating) Crime","description":"Last week the tech IPO scene was hot, with the FireEye and Rocket Fuel IPO fueling the fire (pun intended). It was a spectacular show and hardly","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/","og_locale":"en_US","og_type":"article","og_title":"Partners in (Mitigating) Crime","og_description":"Last week the tech IPO scene was hot, with the FireEye and Rocket Fuel IPO fueling the fire (pun intended). It was a spectacular show and hardly","og_url":"https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/","og_site_name":"Infoblox Blog","article_published_time":"2013-09-27T18:47:02+00:00","article_modified_time":"2020-05-06T17:31:38+00:00","og_image":[{"width":613,"height":434,"url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/visible-threat-featured-image.jpg","type":"image\/jpeg"}],"author":"Renuka Nadkarni","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Renuka Nadkarni","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/#article","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/"},"author":{"name":"Renuka Nadkarni","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/111901fc66473b7a5d5d6cf2ae869ef9"},"headline":"Partners in (Mitigating) Crime","datePublished":"2013-09-27T18:47:02+00:00","dateModified":"2020-05-06T17:31:38+00:00","mainEntityOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/"},"wordCount":500,"publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/visible-threat-featured-image.jpg","keywords":["DNS","Events","FireEye","Infoblox","Malware","Security"],"articleSection":["Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/","url":"https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/","name":"Partners in (Mitigating) Crime","isPartOf":{"@id":"https:\/\/www.infoblox.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/#primaryimage"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/#primaryimage"},"thumbnailUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/visible-threat-featured-image.jpg","datePublished":"2013-09-27T18:47:02+00:00","dateModified":"2020-05-06T17:31:38+00:00","description":"Last week the tech IPO scene was hot, with the FireEye and Rocket Fuel IPO fueling the fire (pun intended). It was a spectacular show and hardly","breadcrumb":{"@id":"https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/#primaryimage","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/visible-threat-featured-image.jpg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/visible-threat-featured-image.jpg","width":613,"height":434},{"@type":"BreadcrumbList","@id":"https:\/\/www.infoblox.com\/blog\/security\/partners-in-mitigating-crime\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.infoblox.com\/blog\/"},{"@type":"ListItem","position":2,"name":"Security","item":"https:\/\/www.infoblox.com\/blog\/category\/security\/"},{"@type":"ListItem","position":3,"name":"Partners in (Mitigating) Crime"}]},{"@type":"WebSite","@id":"https:\/\/www.infoblox.com\/blog\/#website","url":"https:\/\/www.infoblox.com\/blog\/","name":"infoblox.com\/blog\/","description":"","publisher":{"@id":"https:\/\/www.infoblox.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.infoblox.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.infoblox.com\/blog\/#organization","name":"Infoblox","url":"https:\/\/www.infoblox.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","contentUrl":"https:\/\/www.infoblox.com\/blog\/wp-content\/uploads\/infoblox-logo-2.svg","width":137,"height":30,"caption":"Infoblox"},"image":{"@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.infoblox.com\/blog\/#\/schema\/person\/111901fc66473b7a5d5d6cf2ae869ef9","name":"Renuka Nadkarni","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/0661e443c4c379f0c36c9451f82921d754eda7aa497a8cbc3002b9c3a298bcce?s=96&d=blank&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/0661e443c4c379f0c36c9451f82921d754eda7aa497a8cbc3002b9c3a298bcce?s=96&d=blank&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/0661e443c4c379f0c36c9451f82921d754eda7aa497a8cbc3002b9c3a298bcce?s=96&d=blank&r=g","caption":"Renuka Nadkarni"},"url":"https:\/\/www.infoblox.com\/blog\/author\/renuka-nadkarni\/"}]}},"_links":{"self":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/4445","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/users\/254"}],"replies":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/comments?post=4445"}],"version-history":[{"count":2,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/4445\/revisions"}],"predecessor-version":[{"id":4449,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/posts\/4445\/revisions\/4449"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media\/4416"}],"wp:attachment":[{"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/media?parent=4445"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/categories?post=4445"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.infoblox.com\/blog\/wp-json\/wp\/v2\/tags?post=4445"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}