惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Martin Fowler
Martin Fowler
Engineering at Meta
Engineering at Meta
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
阮一峰的网络日志
阮一峰的网络日志
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
量子位
Jina AI
Jina AI
Microsoft Azure Blog
Microsoft Azure Blog
博客园_首页
L
LangChain Blog
A
About on SuperTechFans
人人都是产品经理
人人都是产品经理
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
美团技术团队
博客园 - 三生石上(FineUI控件)
N
Netflix TechBlog - Medium
D
DataBreaches.Net
P
Proofpoint News Feed
小众软件
小众软件
Vercel News
Vercel News
T
The Blog of Author Tim Ferriss
WordPress大学
WordPress大学
雷峰网
雷峰网
G
Google Developers Blog

AI demand is so high, AWS customers are trying to buy out its entire capacity | Network World

Cisco: Latest news and insights 2026 network outage report and internet health check Selector targets the network visibility gap in multi-cloud infrastructure AI reshapes cybersecurity workforce priorities as IT teams brace for new risks Top network and data center events of 2026 How AI is transforming network incident response (and where it still falls short) Google opens TPUs to enterprises beyond its own cloud via Blackstone JV AI, cybersecurity skills top IT pay premiums Startup Bolt Graphics promises 5x performance over Nvidia’s best GPU Wireless security is a battle of AI vs. AI NetOps teams look to AI to automate Day 2 operations Digital twins reshape network and data center management Network outages, power failures strain data center resiliency Five takeaways from Cisco's blowout quarter and what it means to customers Cisco to cut nearly 4,000 jobs despite strong growth in AI, enterprise networking Startup SPAN teams with Nvidia to put data center nodes in your backyard Hard drive shortage affecting enterprise storage needs Wi-Fi 8 is closer than you think. Here’s what you need to know Cisco open-sources agentic AI security spec HPE revamps private cloud stack for enterprises rethinking VMware Versa takes aim at fragmented enterprise security with CSPM, orchestration update, and AI agent controls Red Hat opens Ansible to AI agents, within limits Red Hat offers endless Linux support — for a fee Red Hat: Sovereignty is more than just compliance Tech job postings hit three-year high as AI demand fuels hiring rebound HPE memory server targets compute-heavy and agentic AI workloads PCI group begins work on new spec to support bandwidth-hungry apps like AI, HPC Q&A: Quantum physicist Sonia Fernández-Vidal on why classical computing isn't going anywhere OpenAI-led consortium seeks to address AI processing bottlenecks AWS hit by US-East-1 outage after data center thermal event
DNS security is often inadequate, and network engineers s...
2026-04-14 · via AI demand is so high, AWS customers are trying to buy out its entire capacity | Network World

Despite widespread adoption of defensive measures, most IT professionals believe their DNS infrastructure is not secure enough.

Enterprise Management Associates (EMA) recently published DDI Directions 2026, a market research report that explores enterprise strategies for DNS, DHCP, and IP address management (DDI). In that report, only 28% of DDI experts said they believe that their DNS infrastructure is completely secure.

The risk of insecure DNS

This pessimism about DNS security represents a major risk to enterprises. DNS is critical layer of infrastructure that translates human-readable domain names into IP addresses, making it a control plan for every networked application and service that an enterprise runs both internally and externally. DNS is both an attack vector and a means of obfuscation. For example, a denial-of-service attack on DNS can bring down digital services. Malicious actors often disguise command and control communications and data exfiltration as DNS query traffic. And criminals often try to redirect users to malicious sites via DNS abuse.

EMA’s research found that IT organizations are primarily concerned about the following DNS threats:

  • Malicious redirections of users
  • Distributed denial of service (DDoS) attacks
  • DNS exfiltration and abuse

Moreover, DNS threats are becoming more sophisticated. Some 86% of enterprises have seen evidence of AI-enhanced DNS attacks. Threat actors use AI to rapidly iterate their attacks and make them more targeted, which pushes security measures to their limit.

Go deeper with DNS security

Most network security and cybersecurity vendors can protect DNS infrastructure and prevent DNS abuse with targeted policies. For example, URL filtering can block known malicious sites. Some of these security vendors have started selling DNS security solutions that go deeper.

On the other hand, DDI vendors and managed DNS providers offer more specialized DNS security solutions based on threat research, AI-driven behavioral analysis, and their overall DNS expertise.

EMA asked DDI decision-makers which type of vendor they trusted most to secure DNS. Nearly 55% said they trusted their general network security and cybersecurity vendors, while only 33% trusted DNS solution specialists. Our research suggests trust in general security vendors is misplaced. Survey respondents who trusted DNS solution providers were more likely to believe their DNS infrastructure was completely secure, while those who trusted general security providers were less secure. EMA recommends that enterprises go with the DNS experts to secure this infrastructure.

DNS security is a hybrid cloud issue

Many enterprises have siloed approaches to on-premises and cloud infrastructure. The network team builds and manages the on-premises network, including DNS infrastructure. The cloud team owns its own domain and manages its own DNS services. This can create DNS security silos, where policies, defensive measures, and security monitoring are inconsistent.

EMA research found that only 49% of DDI teams have enough influence over how DNS is implemented and managed in the public cloud. Survey respondents who reported having enough influence were more likely to believe their DNS is fully secure. With sufficient influence, DDI teams have more assurance that cloud teams are taking the right steps to secure DNS.

What does good DNS security look like?

EMA found that enterprises with secure DNS infrastructure tended to have:

  • Confidence in their DDI data: They were aware of all DDI assets on their networks, including DNS. And they had strong discovery and reporting in place to make sure they could track changes to DNS.
  • Their IP address management (IPAM) tools were integrated with more DNS infrastructure. This integration allows them to manage and track changes to DNS centrally in the IPAM tool, reducing opportunities for bad changes to open security vulnerabilities.
  • DDI operations were highly automated, which drives efficiency but also reduces errors.
  • DDI technology was integrated with network security controls, security monitoring tools, and identity and access management systems. This ensures the DDI stack and DNS infrastructure is plugged into the overall security ecosystem.

Finally, most enterprises reported that they were using specialized DNS security solutions such as DNS firewalls or DDoS protection to defend their networks. Most companies were also encrypting DNS traffic to prevent malicious actors from snooping and extracting intelligence from DNS queries.

What should you do next? Empower network engineering

EMA advises IT leaders to put DDI experts in charge of DNS security. Many organizations let cybersecurity take the lead. In fact, some DDI teams defer to cybersecurity on this issue under the assumption that cybersecurity has the expertise needed to protect DNS. In many cases, they do not.

Our research shows DNS tends to be more secure when the network engineering team responsible for DDI has ownership of DNS security. They understand its vulnerabilities, and they know how bad actors might abuse it. But it goes beyond protection. DNS security is about more than selecting the right security controls and monitoring tools. IT organizations need to improve overall design and management of DNS infrastructure. This means better discovery, monitoring, design, and ongoing management of DNS infrastructure.

Our research found that 40% of enterprises have experienced a security breach over the last two years attributable to mismanagement of DDI technology. In other words, it wasn’t the security measures that failed. It was the design and day-to-day management of DNS and other DDI assets that led to trouble. Network engineers are well positioned to take an integrated approach to DNS security, from design and management of DNS infrastructure to the security systems implemented to protect that infrastructure.

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.