惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
雷峰网
雷峰网
The Cloudflare Blog
WordPress大学
WordPress大学
博客园 - 聂微东
人人都是产品经理
人人都是产品经理
IT之家
IT之家
V
V2EX
博客园 - 司徒正美
小众软件
小众软件
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
酷 壳 – CoolShell
酷 壳 – CoolShell
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
Hugging Face - Blog
Hugging Face - Blog
T
Tailwind CSS Blog
Last Week in AI
Last Week in AI
Jina AI
Jina AI
博客园 - 叶小钗
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
阮一峰的网络日志
阮一峰的网络日志
爱范儿
爱范儿

Infoblox Blog

You Don’t Need a Locksmith: Preparing for the Root Zone Key Signing Key (KSK) Rollover in October 2026 AI Agent Security: DNS-AID and Protective DNS | Infoblox Illegal Gambling Sites Reveal Three Types of Cybercrime Infoblox vNIOS on AWS China | Unified DDI Across Global and China Cloud Environments DNS-AID: Securing AI Agents and the Future of Agentic Commerce Modernizing Federal Networks Without Compromise | Infoblox DNS at IETF 126 To Open Weight or Not to Open Weight - That Should NOT be the question Infoblox Supports the Next Generation of Cybersecurity Talent at Cyber Battle Australia The Second Life of Expired Domains Illegal Streaming Fronts a $7M Dropcatch Domain Operation Expired Malicious Domains Bring New Threats to Life How Many AI Agents Are Running in Your Organization? Infoblox IQ for DDI Is Now Generally Available | AI for Network Operations Kentik Joins Infoblox: Network Observability & AI Cybercrime Trends and Threat Intelligence | Infoblox AI’s First Move Is a Name Lookup External Attack Surface Management: See What Attackers See | Infoblox FedRAMP DDI Management with Infoblox Government Cloud Inside a Global Procurement-Themed AiTM Phishing Campaign The Missing Link in the Anti-Scam Chain: Why DNS Belongs in the Room. (DNS, GASA, Global Anti-Scam Alliance, DNS Threat Intelligence) Oracle Cloud Discovery for Universal Asset Insights | Infoblox Why Asset Discovery Integrations Start with Network Intelligence Infoblox Kentik Acquisition: AI-Driven Network and Security Intelligence Proxyware actor behind fake 7-Zip is bigger than you think! Using Protective DNS to Dismantle Global Scam Networks | Infosecurity Europe 2026 Residential Proxies: Why DNS Is the Stronger Play NIST Maps DNS Security to the Cybersecurity Framework 2.0 Trusted Infrastructure Data for AI and AgenticOps | Infoblox Meet Your Security Analyst’s New AI Teammate | Infoblox IQ
AI Governance with DNS Security | Infoblox
Drew Patten · 2026-08-15 · via Infoblox Blog

How Infoblox uses its own DNS security platform to govern access to generative AI services across the enterprise

What Problem Are We Solving?

The rapid growth of AI, generative AI and chatbot platforms has created new security and governance challenges. While these tools can improve productivity, unmanaged access introduces risks including data leakage, intellectual property exposure and regulatory compliance concerns. Organizations need a consistent and scalable way to control AI usage without relying solely on endpoint-based controls.

Why DNS Is the Right Control Point

Infoblox Threat Defense™ provides visibility and policy enforcement at the DNS layer, allowing security teams to identify, monitor and block access to AI services before connections are established. Because DNS is involved in nearly every internet transaction, it serves as an effective and centralized enforcement point across the enterprise.

How We Implement It

  • Blanket Security Policy: Threat Defense inspects all DNS queries originating from managed endpoints, on-premises DNS infrastructure and forwarding proxies.
  • Application Filters: Built-in generative AI and AI chatbot application filters identify and control AI-related services.
  • Custom Domain Lists: Custom lists provide additional coverage for AI services not included in default application categories.
  • Threat Defense Endpoint: The endpoint agent is deployed across managed systems to ensure consistent visibility and enforcement.
  • DNS Forwarding Proxy (DFP): DFP is deployed on NIOS and NIOS-X platforms to ensure enterprise-wide inspection of DNS traffic.

Policy Enforcement in Practice

To demonstrate the approach, Infoblox created a dedicated AI application filter and used it to block selected generative AI services, including DeepSeek. The filter is attached to a blanket security policy configured with a default redirect action and applied to the organization’s primary endpoint group.



Figure 1. Infoblox Threat Defense application filter

The same policy is enforced consistently across DNS Forwarding Proxy deployments, NIOS-X as a Service environments, external networks and Threat Defense-managed endpoint users, creating a unified governance model for AI access.

Key Takeaway

Infoblox actively uses Threat Defense to govern AI access at DNS scale within its own environment. This internal deployment demonstrates how organizations can use DNS-based security controls to enable AI governance, reduce risk and maintain visibility across rapidly evolving AI ecosystems.

Senior Manager, IT, Infoblox

Drew Patten is a senior manager in IT with a focus on network services, cybersecurity and infrastructure modernization. With deep experience in DNS, DHCP, IP address management and enterprise network architectures, he helps drive the adoption of scalable technologies that enhance visibility, governance and operational efficiency. Drew is passionate about leveraging DNS as a foundational security control and exploring innovative approaches to governance, threat protection and emerging technologies such as artificial intelligence.

View All Posts