Dualog® Protect – reducing the risk of malware doing harm to your ships
Written by Muhamad Sallehuddin | 29 December 2021
Stay up to date!
* By subscribing to the latest news from our blog, you consent to us storing your email address, and sending you monthly emails. You can, at any time, retract this consent.
In 2022 and beyond, you can no longer rely only on basic endpoint security tools, such as firewalls or antivirus software, to protect your ships from increasingly sophisticated cyber threats. You need DNS protection.
As you’re reading this, there’s probably a malicious email on its way to an inbox on one of your vessels.
Do you have a shipboard protection mechanism installed that blocks threats designed to circumvent firewalls or stand-alone antivirus solutions?
If not, you’re leaving your fleet vulnerable to cyber attacks that get sneakier – and more devastating – by the day.
Advanced phishing attempts – and what stops them
Suppose the captain on one of your ships receives an email from a maritime organisation he has communicated with not too long ago. The subject line includes ‘RE:’ and ‘Invoice #’ – with a valid-looking invoice number and the name of your shipping company.
Unsuspectingly, his mind wandering, the captain clicks the link leading to a compromised site, which automatically initiates download of a zip file containing malicious content.
Without knowing it, he has just activated a sophisticated malware attack.
How do you secure your ships against malware with malicious links?
Recipients of this attack would see the sender as someone they have previously worked with, replying to an email chain they might recognise as safe. The result is deceptively real and very hard to identify as malicious.
That is why you need to implement a protection mechanism that operates at the DNS level – blocking malware, trojan and phishing attempts before they can do any harm at all to your onboard systems and networks.
In simple terms, DNS protection means providing an additional layer of protection between a crew member and the Internet, by blacklisting dangerous sites and filtering out unwanted content.
As more and more malware uses DNS as its first step to executing an attack, stopping the first step may prevent the rest of the attack from happening entirely.
This is exactly what Dualog® Protect does.
How Dualog® Protect works
Dualog® Protect has a DNS server installed onboard your ships, which sends all DNS queries to the Dualog Cloud. In the cloud, every DNS request is analysed to validate whether the user is allowed to access that site or not. A query will be blocked if the site is of a malicious nature, like a Command-and-Control, malware, or similar queries.
Sites can also be blocked based on content types. For example, you can decide to block all video streaming sites, social media platforms, or a dozen other categories to fit your company policy.
All of this configuration is done in the Dualog Portal. In a matter of seconds, you can reconfigure tens or even hundreds of ships to have a new policy in their onboard networks. You also store information on DNS queries, where you can have a full overview of the situation across all your ships, a key requirement towards IMO compliance.
Here’s a short video that illustrates how Dualog® Protect works:
Yesterday’s IT protection tools are child’s play for modern-day cybercriminals. With Dualog® Protect in place to provide that crucial extra layer of security fortification to your IT operations, you drastically reduce the risk of malware doing harm to your ships.
Muhamad Sallehuddin (Din) is Dualog’s Pre-Sales Technical Manager for Asia. Since joining Dualog in 2006, Din has used his extensive experience in maritime satellite communications to facilitate large-scale, fleet-wide deployments of Dualog solutions across a wide range of shipping companies. His primary role is technical consultancy and training to IT departments and seafarers. When not experimenting with new technology, Din enjoys travelling to new places and - being an avid culinarian - experimenting in the kitchen.