Understanding malware blocks and device identification
If you're using DNSFilter and encounter a blocked malware threat, you might want to know where the malware was blocked or which devices initiated the blocked DNS requests. Here’s a guide on how to manage such scenarios.
How DNSFilter handles malware
We proactively block malware and malicious domains before they can impact your network. When a threat is detected and blocked, it’s intercepted at the DNS level, meaning the malicious content never reaches your machines. In most cases, there’s no need for further action or malware removal from your devices, as the block prevents the threat from executing.
Identifying devices behind blocked DNS requests
If you’re looking to identify which devices initiated the blocked DNS request, DNSFilter allows you to dig deeper into your network activity. Here's what you can do:
- Check your DNS Query Log: In the DNSFilter dashboard, you can review logs under Tools to identify which device or IP address made the request that triggered the block.
- Use Roaming Clients for granular tracking: If you want even more visibility, setting up a Roaming Client can provide detailed insights into which specific devices or users are making requests within your network.
It's worth noting that not all blocked requests come from human actions. Devices often send out DNS requests for system updates, cloud services, or telemetry data, which can sometimes result in a block if a device inadvertently reaches a risky domain.
How do you monitor blocked DNS requests in your environment? Any tips or tools you use to identify devices or manage automated DNS queries?
-
Consider the following situation:
- A user attempts to use a website
- DNSFilter flags the website for malware
- The user notifies the website's maintainers of the malware condition
- The malware is removed and the website is repaired
How long after the website has been cleaned and repaired will it take for DNSFilter to re-classify the website so it no longer is listed as malware?
0 -
Great question, Alex Ackerman ! DNSFilter doesn't automatically age out a Malware classification on a timer. Reclassification happens through a review process rather than on its own after a site is cleaned.
To get the domain re-checked, you can submit it through the Domain Report Tool in the dashboard: Domain Report → enter the domain → Report under the current category → select the correct category → add any supporting details → Submit. If the review is approved, we'll update the classification.
If you need access to the site right away while the review is in progress, you can add the domain to the Allow List in your filtering policy (Filtering Policies → Allow List) to unblock it in the meantime.
0
Please sign in to leave a comment.
Comments
2 comments