DDI Central now facilitates Anomaly detection for both Linux and Windows environments, where network admins gain visual summary over the reports of DNS and DHCP service anomalies.
For DNS, it can detect high volume queries, unusual and long domains, non existing domains, high-entropy domains, excessive sub domains, suspicious TLDs, outbound queries, periodic queries.
For DHCP, it can detect DHCP starvation attacks, rogue DHCP servers, invalid packets, repeated requests, IP address conflicts, unusual option codes, excessive lease renewals, and high rate of DHCP declines.
DDI Central anomaly detection can also be facilitated via the integration of Zoho's AI engine, Zia, for an effective, accurate, and advance threat identification within the network. This integration will leverage advanced machine learning models to detect and prevent DNS-based threats such as domain generation algorithms (DGAs), suspicious query patterns, and DNS tunneling, threats that often bypass traditional firewalls.
Zia-based Anomaly detection would support:
Real-time anomaly detection based on query behavior and usage patterns.- Adaptive reputation scoring of domains by analyzing data across global intelligence feeds.
- Predictive alerts that identify potentially malicious DNS activity before it leads to a breach.