You are on page 1of 5

SOLUTION NOTE

Infoblox Ecosystem Exchange


Reducing Threat Response Time and Costs with Enhanced
Productivity and Automation

SUMMARY
Infoblox Ecosystem Exchange is a highly connected set of integrations that enable
organizations to eliminate silos, optimize security orchestration, automation and
response (SOAR) solutions and improve the ROI of their entire cybersecurity
ecosystem, including third-party, multi-vendor assets. It reduces the time it takes to
respond to threats as well as the cost through enhanced automation and real-time,
two-way data sharing enabled by extensive APIs.

Infoblox as Part of the Cybersecurity Ecosystem

Threat Data Feeds for Use in Ecosystem Roaming Clients/


Remote Access

External Email Filter


Threat Feeds
Infoblox Threat Intel Cloud BloxOne™ Threat Defense
(TIDE) Infrastructure Business Cloud IPS

Network Automation
DNS Related and Visibility Firewall
Perimeter Threat Grid
Security, F/W, Intelligence Member DNS Threat
IDS/IPS etc. query/response Security Intelligence
data Events Platform (TIP)

Grid Member
Grid Member +
DNS/DHCP with Infoblox Grid SIEM
DFP
BloxOne™ Threat Defense
Vulnerability
Network Scanner
Insight Network and Security Events
with Context; DNS data;
Figure 1: The Infoblox user Information
Grid Member
products and technologies DNS/DHCP with NAC
that enable fluid integration BloxOne™ Threat Defense +
Device
across third-party Discovery Data Connector
cybersecurity ecosystem Endpoint
Network Infrastructure Security
components.
(Switches, Routers, Firewalls, etc.)
APT/Malware
Detection
Internal Clients
Infoblox’s extensive integrations enable the broader cybersecurity ecosystem to work in unison to detect and remediate threats
(Figure 1). They combine aggregated, curated threat intelligence, more than 30 API-level vendor integrations and pervasive
automation, enabling network and security teams to:

• Gain centralized visibility into devices • Reduce costs associated with manual • Improve the effectiveness of threat
and DNS- based threat vectors across on- intervention and human error intelligence across the ecosystem
premises, virtual and cloud deployments,
• Reduce the number of alerts teams must • Lower cost of SIEM solutions by sending
including VMWare, AWS, Azure, Cisco
review only suspicious DNS data to these
ACI and OpenStack
platforms
• Make threat analysts up to three times
• Orchestrate common security policy
more productive • Get better ROI from existing network
across the infrastructure
security investment
• Optimize SOAR solutions by automatically
• Decrease time to remediation by up to
sharing contextual threat information
two-thirds

Ecosystem Technology Integration Overview Benefits

Advanced Threat Detection • BloxOne™ Threat Defense automatically • Enables flexible policy enforcement
(FireEye NX Series) shares information with advanced threat
• Rapidly identifies infected devices
detection solutions on incidents involving
advanced persistent threat (APT) activity • Builds defense and remediation into IT
and malicious domains systems and processes
• Infoblox then automatically blocks, logs
events or takes appropriate action on
these threats

Threat Intelligence Sharing • Infoblox Threat Intelligence Data Exchange • Reduces the number of alerts that require
(ThreatConnect, Cisco Threat (TIDE) sends information on malicious host review
Intelligence Director, Check names, IP addresses and URLs to the threat
• Improves situational awareness for
Point Threat Cloud, Windows intelligence platform (TIP)
network and security organizations
Server 2016)
• TIP enables blocking and monitoring of
• Enhances overall security posture
more threats

Security Information and • Infoblox sends information on IP addresses, • Provides consolidated visibility into
Event Management (SIEM) infected devices and suspicious DNS device activity regardless of where log
(LogRhythm, Splunk, McAfee requests and responses to SIEM data was generated
ESM, IBM, QRadar, Micro
• SIEM can use this information to perform • Supplies context for more accurate
Focus ArcSight)
analysis and take action prioritization of security events

• Improves operational efficiency of


network ops and IT teams

Vulnerability Management • Infoblox sends information on IP addresses, • Provides near-real-time visibility into
(Qualys, Rapid7, Tenable network devices and malicious events to new devices as they join the network
Security Center) vulnerability management
• Automates and accelerates responses to
• Vulnerability management uses that network changes and malicious events
information to automatically trigger
• Improves ROI on security investments
scans, enabling easier compliance and
already made
accelerated remediation
Network Access Control • Infoblox provides information on IP • Expands visibility into network
(NAC) addresses, network devices and DNS infrastructure, users and devices
(Cisco, ISE, Aruba ClearPass, security events
• Provides vital context for threat prioritization
ForeScout)
• NAC solutions can use that information to get
• Enables consistent policy enforcement
context to better prioritize threats and take
more immediate action (such as removing a
device from the network) to shorten time to
containment

Next Generation End-point • Infoblox detects DNS-based malware • Quickly identifies and prevents DNS-based
Security communications and informs next generation endpoint communications to malicious
(Carbon Black, McAfee ePO) endpoint security technologies domains

• These products can identify the malicious • Automatically responds to endpoint


processes, quarantine the endpoint or take threats, reducing dwell time
other actions
• Enables mass deployment of Infoblox
• For added protection, endpoint security endpoint agent for DNS security and
solutions can incorporate Infoblox client streamlines workflows
agents

Next Generation Firewall • NGFW receives malicious host names, IP • Reduces the number of alerts to review
(NGFW) addresses and URLs from Infoblox TIDE
• Improves situational awareness for
(Palo Alto Networks)
• NGFW enables customer to block or monitor network and security organizations
threats
• Strengthens overall security posture

Web Gateway • BloxOne Threat Defense blocks DNS-based • Unifies domain blocking and http security
(McAfee) data exfiltration, as well as DNS requests for broader protection
to malicious domains before forwarding the
• Speeds detection of malicious traffic
traffic to McAfee Web Gateway
originating from infected endpoints,
• The web gateway then scans traffic for regardless of its location
further inspection with URL filtering, SSL
• Complements web gateway with DNS-
and more
based threat intelligence

Security Orchestration, • SOAR solution receives information on IP • Integrates disparate security tools and
Automation and Response address, network devices and malicious provides vendor-neutral threat intelligence
(Phantom Cyber) events from Infoblox for all devices

• SOAR uses that information to block/un- • Automates and produces faster response
block/check domain, check information with full set of threat intelligence APIs
about IP/host/network/domain in IPAM
• Enhances and improves incident response
• Infoblox automatically enriches IPAM with with better threat intelligence
data from security tools and events
• Improves security processes by integrating
with other systems via SOAR

ITSM/ITOM/Security • Infoblox sends information on new devices, • Provides at-a-glance dashboard views into
Operations networks and IP addresses to ITSM/ITOM/ devices and endpoints joining and leaving
(ServiceNow) Security Operations the network

• Network and security admins can view • Enables proactive identification of network
devices and events discovered by Infoblox issues to accelerate responses to network
in a single place changes and security events
Automating Workflows through Cloud Infoblox network automation and cloud eocystem integrations
enable organizations to:
Ecosystem Integration
• Unify domain blocking and http security for broader
Networks ops teams may have hundreds of network tools in protection
their environment. Often, these tools work in silos, making it
very difficult to see the full range of diverse network assets in a • Speed detection of malicious traffic originating from
single place. Today’s organizations also use varied deployments infected endpoints, regardless of its location
and architectures, from physical to virtual to cloud. Infoblox
• Complement web gateway with DNS-based threat intel
ecosystem integration enables networkers to gain a consolidated
view of assets and architectures, while automating common
workflows to speed response times and improve agility.

Ecosystem Technology Integration Overview Benefits

Cloud Management • Infoblox automation enables quick spin ups • Enables faster provisioning of new users
Platforms of VMWare instances joining the network
(Cisco, VMWare)
• Cloud management platforms can • Provides unified visibility across diverse
incorporate DDI automation into their assets and infrastructure
workflows
• Facilitates and automates policy
• Infoblox automation ties into service enforcement
management solution from Cisco and
VMWare

Service Provider Services • Infoblox NIOS integrates with Nokia Cloud • Simplifies network operations by automating
(Nokia) Band to accelerate Network Functions infrastructure and Infoblox DDI appliance
Virtualization (NFV) development and lifecycle management processes
implementation
• Accelerates deployment with a pre-integrated
• The Cloud Band NFV system orchestrates solution that combines Infoblox DDI software
the deployment of Infoblox Virtual with Nokia’s NFV infrastructure solution
Appliances in the network

Public Cloud • Infoblox and public cloud exchange • Provides consolidated views into IP and DNS
(AWS, Azure, VMWare) information with each other to provide information for virtual machines (VMs) located
unified visibility and management across on-premises or in the cloud
all platforms
• Enables centralized management of DNS
• Infoblox and public cloud integration servers on-premises and in the cloud
enables automation of IPAM and DNS
• Ensures efficient utilization of cloud resources
provisioning
across multiple clouds (Azure, AWS, VMWare,
OpenStack)

Private Cloud • Infoblox integration enables automatic • Ensures consistency and visibility in hybrid
(OpenStack) provisioning of the next available IP address deployments (on-premises, virtual and/or
and DNS record when creating VMs and cloud)
automatically releases IPs and DNS records
• Reduces manual processes
when destroying VMs
• Speeds time to deployment
• Private cloud spins up VM on Hypervisor
(e.g., KVM) and VM makes DHCP request
after it starts up
Next Generation Data • Infoblox provides IPAM and DDI provisioning • Automates manual tasks
Centers workflows
• Enables faster response to network changes
(Cisco, Nutanix)
• Integration between DDI and next generation
• Provides better ROI for existing network
data center products provides consolidated
investments
environment and provisioning flexibility
• Offers flexibility and helps consolidate
operations

Note: The integrations require one or more relevant Infoblox


products to be able to pass necessary information to the tools
mentioned above. Infoblox integrations support a variety of
options including REST APIs, STIX/TAXII, JSON, XML and
CSV formats, syslog and third-party propriety methods, to
ensure interoperability.

To learn more, please visit Technology Alliance Partner page.

Infoblox is leading the way to next-level DDI with its Secure Cloud-Managed Network Services. Infoblox brings next-level security,
reliability and automation to on-premises, cloud and hybrid networks, setting customers on a path to a single pane of glass for
network management. Infoblox is a recognized leader with 50 percent market share comprised of 8,000 customers, including 350
of the Fortune 500.

Corporate Headquarters | 3111 Coronado Dr. | Santa Clara, CA | 95054


+1.408.986.4000 | 1.866.463.6256 (toll-free, U.S. and Canada) | info@infoblox.com | www.infoblox.com

© 2019 Infoblox, Inc. All rights reserved. Infoblox logo, and other marks appearing herein are property of Infoblox, Inc. All other marks are the property of
their respective owner(s).

You might also like