DNS is the gateway to your business
DNS disruption equates to lost business and damage to your brand.
Imperva DNS Protection ensures network connectivity and website availability to keep your business operational and resilient against the threat of a DNS-targeted attack.
DNS attacks interrupt the performance of your websites and impact on your customers’ experience.
Imperva DNS Protection filters out bad traffic and only responds to legitimate requests to guarantee operational uptime and ensure business continuity.
- DNS traffic statistics and trends
- DNS attacks analytics
- Instant attack notifications (mail, mobile)
- Primary & Secondary Hidden DNS Master configurations support
- DNSSEC – additional layer of security via authentication
- Possibility to switch between managed/proxied DNS as needed
- Automated onboarding and automation via API
- Zone Import & Export
Precise DDoS mitigation
DDoS protection for domain name servers uses a combination of reputation and rate-based heuristics to inspect incoming queries and filter out malicious packets without impacting legitimate visitors.
DNS Protection works in sync with our DDoS protection for websites and DDoS protection for networks services. Together they shield Imperva customers against all types of DDoS attacks.
Imperva DNS protection serves DNS queries from the closest point of presence to your end users for the fastest response time and optimal performance
- Millions of applications and IPs protected
- 1.03 Trillion requests analyzed
- 3,500,000 bad requests blocked/minute
- 99.999% uptime SLA
- 3-sec DDoS mitigation SLA
How it works
Our service is deployed in front of your DNS server, becoming the first destination for all DNS queries. Acting as a secure proxy, Imperva prevents illegal DNS queries from reaching your server while masking it from direct-to-IP network layer attacks.
From the Imperva dashboard you can whitelist specific queries and for additional peace of mind, you can also set a threshold to rate-limit the queries your server receives.
Finally, with DDoS protection for domain name servers in place you will still be able to manage your DNS zone files outside of the Imperva network.