DNS Isn’t Infrastructure — It’s Security
On a recent episode of The Defender’s Log, host David Redekop sat down with Yaëlle Harel, Senior Product Marketing Manager at EfficientIP, to discuss why DNS remains one of the most vital—yet frequently overlooked—attack surfaces in enterprise cybersecurity.
Shifting from Infrastructure to Security Control Plane
For years, DNS was viewed strictly as a networking utility. Today, security leaders increasingly recognize it as a core security control plane. Unlike endpoint tools or traditional firewalls, DNS sits ahead of connection establishment. Because virtually every network interaction flows through DNS, it serves as a critical first line of defense to stop attacks before payloads execute.
Uniquely Positioned Against Modern Threats
While tools like EDR are essential, they cannot cover every asset, such as unmanaged devices or agent-to-agent AI communications. DNS traffic provides unique visibility into network behavior. For example, analyzing DNS queries can expose domain generation algorithms (DGAs) and command-and-control attempts well before malicious domains are registered or connections are established.
Overcoming Alert Fatigue with AI
Adding defense layers often increases alert volume, but the future of DNS defense lies in AI-driven correlation. By analyzing vast amounts of traffic data and identifying true anomalies, integrated systems can streamline telemetry and significantly reduce false positives.
Empowering the Next Generation
Harel concluded with advice for the broader tech community: “Come to this industry, which is fascinating—we need to see more women in cybersecurity.”
TL;DR
- DNS as a Security Control Plane: DNS is no longer just a networking utility—it sits before connections are established, making it a critical first line of defense to block attacks early.
- Fills Gaps Left by EDR/XDR: Endpoint protection cannot be installed on every asset (like IoT, unmanaged devices, or AI agent communications), but virtually all network traffic must pass through DNS.
- Early Threat Visibility: DNS traffic analysis can detect suspicious activity—such as domain generation algorithms (DGAs) and command-and-control attempts—well before malicious domains are even registered or successfully reached.
- AI & Alert Fatigue: While adding security controls often increases alert volume, AI-driven correlation across systems will be key to reducing false positives and streamlining SOC workflows.
- Encryption Needs Control: While DNS encryption (DoH/DoT) protects user privacy, enterprises must monitor and govern it to prevent malware from bypassing internal security policies.
- Diversity in Cyber: Yaëlle Harel closed with an encouraging call to action, urging more women to enter and help shape the rapidly growing cybersecurity field.
Links
View it on YouTube: https://www.youtube.com/watch?v=JE2f7Yh3U3o
Listen to the episode on your favourite podcast platform:
Apple
Spotify
https://open.spotify.com/episode/14odZHw0og9QhosxQXmNbA
Amazon Music
ADAMnetworks
The Defender’s Log full transcript - Episode 031
DNS Isn’t Infrastructure — It’s Security
Announcer: Deep in the digital shadows where threats hide behind any random byte, a fearless crew of cybersecurity warriors guards the line between chaos and order. Their epic battles, rarely spoken of until today. Welcome to the Defender’s Log, where we crack open the secrets of top security chiefs, CISOs, and architects who faced the abyss and won.
Introduction and Welcome
David Redekop: Here’s your host, David Redekop. Welcome back to another episode of “The Defender’s Log,” where we do deep dives into front lines of cybersecurity with people that are always building and defending. And I’m your host, and today I am joined by Yaëlle Harel. And Yaëlle brings over 15 years of experience in cybersecurity, in threat intelligence, in compliance, and is currently leading product marketing efforts at EfficientIP, and we have some friends over there as well.
She spent her career bridging the gap between deep technical engineering and high-level security strategy, and with a huge focus on one of the most vital, yet constantly overlooked attack surfaces in the enterprise, which is, of course, DNS. Yaëlle, welcome to the show.
Yaëlle Harel: Thank you. Very happy to be here.
David Redekop: We are at that time of year where the weather could be one way or the other. It could be really bad, could be really good, and I find that very often it relates to DNS. If we’re gonna have a bad news in the DNS Security Day, the weather seems to be not so good. So first question is, what’s the weather like?
Yaëlle Harel: Oh. So actually, we have very weird weather right here in Paris now. One day it’s 32 Celsius degrees, which is very hot. The other day it’s cold, so yeah, the weather is crazy. I don’t know if I can correlate it to DNS, but I can correlate it to DNS because we have been doing some very interesting research into the ClickFix world, and I’m going to be very interested in any insight you have into that world as well because it’s very turbulent right now.
Career Origins in Cybersecurity
David Redekop: Could be a good day, could be a bad day. But before we get into that, Yaëlle, you’ve spent over 15 years in cybersecurity, in a field that looks so completely different today than when you first entered it. So what originally drew you to cybersecurity and compliance to begin with?
Yaëlle Harel: Actually, I think since I’ve mentioned the 15-plus years, a few years passed since then, and when I first joined the cybersecurity industry, I think it was, it’s now going back about 20 years ago. The first company I worked for was Check Point. And back then, cybersecurity was basically firewall. This is what the company knew, firewall and antiviruses on the endpoint side. and the world has changed.
It was at the early 2000s, and everything became connected. We started talking about cloud. Everybody, everyone was scared about cloud, like today, everyone’s scared about AI. and I had a feeling that this industry is going, it was already established, but that it is going to explode. and this is why I went to cybersecurity, and I think I was right looking back to do so.
David Redekop: Absolutely. Yeah. Now, was there any one particular incident that really sticks out in your mind to say, “This is what made me convinced of that”?
Yaëlle Harel: Not necessarily. I think back then, I’ve been working in Israel, I’m coming from Israel, and Check Point for me was like, a big success story of a small startup that started with a few people. And for me it was like going to work for Check Point was the best thing, and this is how I got to cybersecurity.
DNS: Infrastructure vs. Security Control Plane
David Redekop: Oh, okay. Very good. So in your role as senior product marketing manager, your role sits squarely in the intersection of advanced security engineering as well as executive strategy, and is there any particular disconnect that you see between technical defenders, like ourselves, that view the problem versus how leadership sees it?
Yaëlle Harel: Yeah, completely. I think that technical defenders understand the problem. They need to choose between many different solutions and technologies. and the leaders, they see, they understand, of course, the risk of cybersecurity, but they see it in a very high-level way. and for them, there’s a pool of solutions there.
and one of the efforts we are doing is to educate them about the roles of the different elements in the security portfolio toolkit that they have. And it’s particularly difficult with DNS because DNS is seen as an infrastructure element, not necessarily as a security element. So that’s an interesting challenge for us.
David Redekop: I would love to see over time what that opinion shape looks like. You just pointed out that by many folks, it is seen as infrastructure versus a strong component of security, or as I think it was Dr. Paul Vixie many years ago that coined the term control plane, where that understanding or the mind shift has taken place. Is it at least going in the right direction in your experience?
Yaëlle Harel:
Yeah, definitely. I think that’s definitely, I see that when participating in events, in cybersecurity events, which are not networking events, which is a different audience. DNS, itself, the main audience is or was using DNS was networking teams, and I see awareness also in cybersecurity teams.
They approach us. They ask questions. They understand that DNS is like the door of the organization. We can describe it like that. So with the security people, like security team managers, CISOs, it is much better than what I’ve seen even a few years ago when I joined the company.
David Redekop: It really is the unsung hero of security but it sounds to me like we still have a ways to go for everyone in the security and in the networking space to be on the same page about it being a very valuable, very important, you know, first step of the first line of defense.and, it seems like it’s still one of those things that it seems to get ignored until it breaks.
Or it gets ignored until someone says, “We can do something with it.” That is really kinda cool.
Yaëlle Harel: Yeah, so I think it’s interesting because the fact that it’s being ignored, it breaks. As long as it works, people don’t see the DNS. They know it’s there, maybe. Not everybody knows it’s there, but the networking and the security teams definitely know that. But they don’t think about it as a point in which you can put a control and security, and I agree that we have a lot more to do around that, but it’s better than what I’ve seen before.
David Redekop: Now, we often have traditional defenders saying, “I already have EDR and XDR everywhere. why do I need DNS-level protection?” What’s your first go-to answer to that?
Yaëlle Harel: So my first answer to that is that DNS, first of all, DNS doesn’t replace any of the security tools you have, which is not always a very comfortable answer for the customers because for them, I’m saying, “Oh, you need to buy something in addition.” but on the other hand, no, because DNS, they always have DNS, and DNS sits before, the endpoint.
It sits before the connection is being established, you can first and all block the attack earlier, and second, you can put an endpoint on every device today. You can put an endpoint on your laptop, on a user’s device, but you can’t put it anywhere, so it will not cover everything.
And especially when we’re talking about the AI area, which I think we can’t avoid in this discussion, you have agents talking to other agents, communicating. We’re not talking about users and devices anymore, so you definitely need another layer of protection, and almost every interaction that you have in your network goes through the DNS, so this is a great point to secure.
The Unique Visibility of DNS Traffic
David Redekop: That brings me to the many incidents over your lifetime and mine that we have witnessed where a huge, global event like an Olympics outage or a cloud outage has happened. And when threat actors target core infrastructure during high-stakes moments like that, what unique visibility does DNS traffic analysis provide that other telemetry actually misses?
Yaëlle Harel: So the thing about the DNS traffic is that we can see behavior. For example, if we look at DNS traffic coming from multiple enterprises or from telcos, you can see trends that are not seen at a network level because you can even see the attempts of connections.
I will give a recent example from research that wasn’t yet published, about how DGAs are predicting malware, because malware is using DGAs, and we can see the domains, they are out there in the traffic, well before the malware starts operating. and this is something you can see only with the DNS because you can see the infected devices, the malware trying to connect to its command and control with some domains that are not yet even registered or listed anywhere.
and only the DNS can see that because these are requests that are not successful. The connection will not be established. You will not see it on the endpoint side eventually.
AI in the Security Operations Center
David Redekop: Yeah, I find it really fascinating that we are now at the point where a lot of those algorithms are already visible even before we see the first query, never mind the registration. So what ends up happening is preemptive defense detects that, “Ooh, this is a domain name that will be registered, and then we just start seeing it sometimes being requested before it exists, and then it gets registered, right?”
And so the adversaries have to work on their timing a little bit and become a little bit more advanced because we’re at the point now where we are using AI, hopefully in as effective a way as the adversaries are. So let’s talk about AI in the security operations center for a moment, because we’re seeing it being used to launch sophisticated phishing and attacks, and we look to preemptively detect them or, as a last resort, catch them in real time, or maybe as an even for the last resort, wait for evidence to be there.
right? And so we’re using defense in depth there. But where is AI currently providing the highest ROI for defenders, or is that all hype?
Yaëlle Harel: So it’s definitely not hype when it comes to security. I think it’s a race between defenders and attackers. attackers, they have the advantage of the fact that they don’t need to follow any regulations. They don’t need to think about privacy. They don’t need to think about the security of deploying AI. So they’re just using AI to develop their attacks. We see AI, not being used only to write the code, but to actually to run and take decisions in real time during the attack.
and the defenders need to adjust to that in many aspects. We first need to detect attacks which are faster, more sophisticated, and we’re using AI. When I say we, I’m talking about the cybersecurity industry as a whole, is using AI, machine learning to analyze hugest amount of data. In the DNS case, it’s what we see in the traffic to detect anomalies, to detect activity that might have been generated by AI or might be actual agents speaking to each other during an attack.
this is the main challenge and opportunity, on the other hand, because this is something, we need to provide to our customers. And the second aspect of AI, I think, is the adoption of AI within the organizations, which brings another challenge to companies today because in one hand you want employees to use AI in order to accelerate, in order to be more productive, to deliver faster.
but you also want to make sure that they use AI properly, and you want to govern AI and DNS can be also used for that. So these are two aspects of the completely different aspects of AI that are part of the security ecosystem.
Alert Fatigue and DNS Defense
David Redekop: No, absolutely. we are definitely aligned there, for sure. And what about alert fatigue and practical defense? Because I’m just reminded of a conversation I recently had with Dhruv, my friend Dhruv, from DiscrimiNat and he says that what they found was if you apply the right layers at the right levels, you actually end up dramatically reducing alerts where it’s most meaningful. And in your experience, what does proper DNS defense do in terms of preventing alert fatigue?
Yaëlle Harel: So I will answer that completely honestly. When you add a protection layer, you add alerts, and you add alert fatigue. And the right approach to deal with that is to have good correlation between the different alerts, to have good integration between the different system in the ecosystem.
And I think today this is something, it’s mature in, if you look at it with eyes of before AI in what we could do, but I think AI will dramatically change that. And once we’ll have MCP servers offered by the different security solutions, that we’ll be able to communicate to each other and collate alerts, and to eventually provide one single alert saying that something has happened, is happening in your organization, go and check it for the CISO, that will change this problem completely.
And this is actually, we talked before about how my career started. I think this is one of the first tasks I had. I was, back then project manager of IPS, and I did a customer survey. Back then, customer survey were meant to go on a plane and travel and meet customers face-to-face. And I came back with a big insight.
The main problem of IPS is false positives and alert fatigue, and it was, I think, almost 20 years ago. We’re still facing the same problem, and I think that AI can dramatically and will dramatically change that.
The Unsteady State of Security
David Redekop: I’m looking forward to that, because we have actually inadvertently created something in the industry with default deny all, because default deny all, by its very nature, means that there needs to be an element of discoverability of what are essential services that should be allowed.
So instead of having an alert that something got blocked that shouldn’t have been, it’s the other way around. Here’s something that we, yeah, that we allowed. So it’s an interesting dynamic. And every single time I am zoomed in to a specific point in time that we’re at in terms of DNS and security and using it as a control plane, I think, “Okay, maybe things will slow down now.
Maybe we’ve now arrived at a point of stability.“ But then, if I reflect back on time, every single time I had that sentiment, I was wrong. Because what was about to happen was yet another upset. So where do you think we are today in terms of that steady state or not?
Yaëlle Harel: Unfortunately, I think we’re not close to the steady state at all. I think AI opens the door, unfortunately, to everyone, to both technology in the good side of technology and in the other side to anyone that wants to do something malicious, just for as a hobby or to gain actual profit.
It makes it easier, which means that nothing is stable for us because we need to keep up and provide solutions and protection for that.
David Redekop: There’s no question that we are going to never be bored again, Yaëlle. We’re going to continue to need to be on our toes and be super alert about what’s coming around the corner.
Perspectives on DNS Encryption
David Redekop: We talk on this podcast a lot about DNS and DNS encryption. What’s your broad big picture perspective on where we’re at, the importance of it, the role of DNSSEC versus DoH and DoT and how they are tangentially related? but give us a big picture of where you stand in terms of DNS encryption.
Yaëlle Harel: So for us as a DNS security vendor solution, DNS encryption has its benefits for the end user, for privacy, but it does reduce visibility. and I think that when we speak about enterprise traffic, we do need to have this visibility because DNS encryption can help users or not user, malicious software that is installed in your organization to bypass security policies and measures.
So I think it should be allowed. We can’t avoid that, but it should be controlled and monitored, and we need to be aware of what’s being used and to control that it’s being used for the right reasons. So that’s my main insights around that.
David Redekop: Yeah, we would be in complete agreement. It’s been a bit of a challenge as endpoints and software has decided, “You know what? We want the privacy, and we don’t care about the impact that it has on the enterprise,” and then those risks are brought in. But fortunately, so far, we’ve been able to mitigate that, and as long as we continue to have those control elements in place, it seems like we’re going to be able to keep on using it as a control plane.
Our worldview on that, Yaëlle, is that an endpoint should never be able to reach beyond its perimeter for DNS ever. And to enforce that really ends up being a networking and a security function together, so that there has to be agreement there from executive level down that is an important aspect.
Otherwise, you’re always gonna have that open hole. And then there’s also record types, right? there’s the TXT record types. There’s the null record types that end up, we see, getting abused. And an interesting research that we did, I wanna say about a year ago, where we’ve wanted to really investigate how important it is to even have TXT record availability to your typical end user endpoints, your mobile devices, your laptops, Windows, and so forth.
And it turns out that there are almost zero use cases where that’s necessary. And so it turns out that we can just, in most policies, not allow TXT record lookups unless it’s being used by an environment that actually needs that. So we’re finding interesting ways to deal with the threats that are there, but staying alert and always there is fascinating.
Discovering a Passion for DNS
David Redekop: What do you find is the most interesting aspect of the work that you do, Yaëlle?
Yaëlle Harel: Wow. I think that I’m in the right place in the right time. I think we’re in very interesting moment of the tech industry in general and the cybersecurity in particular. And as you said before, my role right now is in the intersection between the customer needs, the market, what’s going on, and the technology.
So for me, that’s a very exciting times to be a security product marketing manager. and I’m passionate about AI, about cyber, and the two connect very well.
David Redekop: So you wake up and you’re excited for the day because you’re dealing with real-life stuff. None of it is theoretical. Everything’s real, right? And you can apply it. That’s wonderful.
I may have shared this story with you before, Yaëlle, but I remember the first time that I took a tower that I needed to put on the internet in a data center, and I took it to a friend of ours in London, Ontario, of all places, that had just been brought online with the first internet service provider.
And, the guy I brought the tower to, I said, “Well,we have a domain, and we would like that to be hosted on this box.” And he says, “Okay. what’s your zone file?” And I remember just looking at him briefly, and he was one of those Unix beard guys, right? Like it went all the way down past his waist, the long beard.
And I said, “What is a zone file?” And he just started to slowly stroke his beard thinking, “Okay , who am I dealing with?” What was your first moment where you had a curiosity about DNS and security that illustrated that there is, it’s a very deep field?
Yaëlle Harel: I will be very honest about my answer about that. It didn’t start with a “Wow” moment. I moved to France after having a long career in Israel. And when I was looking for a new opportunity here in France, I got into EfficientIP. And, unlike my previous career decision, I joined EfficientIP mainly because I really liked the people I met during the session.
I didn’t have much background before that with DNS security, and my passion to DNS security came after I joined and I realized, “Wow, this is really interesting.“I’ve been so many years in the cybersecurity industry without giving a second thought about DNS, besides we had some DNS protections in the IPS, but it was very one small feature out of a lot of things I did.
And when I realized the power of such a service that every organization has this is when I had my “Aha!” moment. It was actually after I joined the company.
David Redekop: Ah, very good. Well, that speaks well to the company culture there. And, if you have other people like our mutual friend Andreas Taudte, then it’s not surprising. And you should be at places like DNS-OARC where other DNS people hang out, hang around.
A large part of the audience in places like that tends to be on the authoritative, on that side of things, on the DNS world. But I think the more we bring in participation from people that are passionate about DNS on the consumption and on the control plane, on the defense side, the more it’s going to be equally balanced to also represent defenders in that space that utilize it as a defense tool.
So anyway, you just know that you are welcome in those circles and we’d love to have you there.
Yaëlle Harel: That would be great. Really good, gentle hearts in places like that. People that are genuinely curious about what the interface is like with people in different roles. And you also get the old guys that have been around for three, four, five decades that are getting crusty and just don’t wanna give anybody the time of day anymore for any new ideas because they’ve already heard them all.
And there’s wisdom in stuff that is not gonna change. And then you have young people for whom the whole future is bright, right? And so you end up with a mix of them all. I find it’s pretty interesting.
Yaëlle Harel: It takes me back to the beginning of our conversation when you connected the weather to DNS. One thing I can say, I do agree that I can, I don’t know how to explain it, but I do find a connection between the character of people and DNS. People working on DNS, all people I’ve met are really nice and kind people. I don’t know if it’s random or not, but this is an observation I did see.
David Redekop: That is very interesting. I have never thought about that. But if I were to very quickly get response to that, I would be saying that when it comes to DNS and relating that to characters, it makes sense to me because DNS is extremely deterministic, and character determination of someone that you are potentially going to connect with is about how deterministic is our trust with each other.
Can we rely on one another? So it kinda makes sense that there would be a lot in common with those characters, yeah.
Yaëlle Harel: The only contradiction is with your great statement of “Don’t talk to strangers,” which contradicts with the fact that we like to talk to each other and exchange.
David Redekop: Yeah, but you know what? We very quickly become non-strangers, right? And what’s interesting about environments like that, they are not massive tens and hundreds of thousands of people conferences. They tend to be conferences of a few hundred or maybe in any one given session, maybe 20, 30, 40.
So these conferences are, generally though, very heartwarming because it’s quick to get to know someone. And people don’t have a mysterious background, right? We all love our privacy and our security and our own OSINT, but generally speaking, all of us have left some kind of a digital mark online with what we’re about and what we represent, and it’s just a wonderful place to get like-minded people together.
Yaëlle Harel: So maybe I’ll join Andreas to the next one.
David Redekop: Wonderful. Well, then this podcast is already a success if that’s the case. Yaëlle, you and I have only spoken once before this podcast, and I just felt like, okay, here’s someone else that we can connect with and bring into the circle with no regrets.
Final Advice and Outro
David Redekop: So, I have one last question for you, Yaëlle. Is there any particular wisdom or advice that you would like to leave with our listeners today?
Yaëlle Harel: So if I may, my advice will not be around DNS. It will be around cybersecurity and technology, and I will speak to the young ladies out there. We don’t see you enough, and come to this industry, which is fascinating, and I like to see more women around this industry. So this will be my key message from this session.
David Redekop: Thank you, Yaëlle. I will take that advice and introduce you to Aditi at Microsoft because I think she would agree, and I think you two would get along. Thank you. Thanks so much for spending your time with me today, and look forward to connecting with you again real soon.
Yaëlle Harel: Thank you, David.
Announcer: The Defender’s Log requires more than a conversation. It takes action, research, and collective wisdom. If today’s episode resonated with you, we’d love to hear your insights. Join the conversation and help us shape the future together. We’ll be back with more stories, strategies, and real-world solutions that are making a difference for everyone.
In the meantime, be sure to subscribe, rate, write a review, and share it with someone you think would benefit from it, too. Thanks for listening, and we’ll see you on the next episode.
