Reports

In the BI.ZONE Secure web interface, you can create reports on the Solution's performance for a selected period. The reports will be sent to your email.

Each report includes a variety of information about how the Solution protects your organization's DNS traffic, grouped into the following sections:

  • General DNS traffic statistics. This section provides summary information about your organization's DNS traffic for the selected period:

    • average number of DNS queries per second, broken down by triggered checks

    • volume of traffic transmitted through detected DNS tunnels

    • number of detected DNS tunnels

  • Changes in DNS traffic over time. This section contains two graphs:

    • total number of DNS queries per second for the selected period

    • number of DNS queries per second for each of the filtering policies

  • Domains. This section shows the most popular fully qualified domain names (FQDN) by the number of DNS queries for the selected period. If the number of DNS queries to a particular domain is significantly higher than to others, this could indicate that the domain does not exist or that its server is unavailable. In such cases, we recommend locating the sources of DNS queries to these domains within your organization's network and verifying their legitimacy.

  • Source IP addresses of DNS queries. This section shows the most popular source IP addresses of DNS queries by number of queries for the selected period. These are the IP addresses within your organization that sent the most DNS queries to various domains.

  • Domains on BlackList. This section shows the most popular domains from BlackList by the number of DNS queries for the selected period. Typically, domains are added to the blacklist if they are unsafe or undesirable according to your organization's cybersecurity policy.

  • TI categories. This section shows the distribution of DNS queries by category in the threat intelligence (TI) database for the selected period. If a DNS query matches a TI database category and the TI policy is set to Block, the query will be blocked.

  • TI domains. This section shows the most popular FQDNs whose DNS queries match categories in the TI database, by number of DNS queries for the selected period.

  • Outbound traffic through DNS tunnels. This section provides information about outbound traffic through DNS tunnels detected for the selected period. The detection of DNS tunnels may indicate illegitimate activity on your network.

You can create: