- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
As adversaries deploy increasingly automated, machine-speed evasion tactics, traditional security models are hitting a critical bottleneck. Historically, network perimeters have relied on Layer 7 payload analysis, domain reputations, and URL filters to block threats. While highly effective at inspecting traditional traffic, these L7 controls have a blindspot when malware bypasses name resolution and web based URL and connects to the attacker infrastructure directly using IP address.
According to Unit 42 telemetry, 23% of all modern malware command-and-control (C2) connections bypass DNS completely, establishing outbound socket connections directly to hardcoded IP addresses. At the same time, adversaries are weaponizing automated scanning across vast residential proxy networks, hopping rapidly between IP addresses in fractions of a second to evade rate limits and static blocklists. A recent Wall Street Journal investigation laid out the immense scale of this tactic, exposing a cyber campaign that used a network with over 750,000 consumer routers and smart devices.
This blog post explores how Palo Alto Networks is closing this evasion vector by extending Precision AI directly to the network layer with Advanced IP Defense—denying access at the network layer by blocking attacker internet infrastructure outright.
To protect perimeters, many organizations have historically relied on commercial third-party threat feeds or open-source intelligence (OSINT) blocklists, operationalized as External Dynamic Lists (EDLs) on their edge firewalls. While conceptually straightforward, this architecture introduces massive operational friction:
To close these critical security and operational gaps, Palo Alto Networks is introducing Advanced IP Defense, a new Cloud-Delivered Security Service (CDSS) that extends Precision AI directly to the network layer. Rather than relying on reactive, payload-based signature matching or static blocklists, Advanced IP Defense continuously monitors, scores, and categorizes the entire publicly routable IP address space of over 8 million active threat hosts in real time.
Operating inline at the security zone boundary, Advanced IP Defense evaluates traffic—prior to Layer 7 session establishment and without requiring resource-heavy SSL/TLS decryption. By acting as an authoritative front-door guard, it proactively blocks malicious scanning, exploit delivery, and command-and-control (C2) callback attempts at the network edge before they can ever reach your assets or execute payloads.
Operating inline and cloud-delivered, Advanced IP Defense addresses these structural weaknesses at the network layer, requiring zero SSL/TLS decryption to evaluate and enforce security verdicts. It achieves this through three core technical capabilities:
Advanced IP Defense abandons slow-moving, static lists in favor of an active, cloud-delivered scoring database. Translating global telemetry from over 75,000 enterprise customers and 1,600 research sources, the engine dynamically monitors and maps the entire publicly routable IP address space across 40+ security attributes (including malware_c2, tor_exit, open_proxy, and bulletproof_hosting).
Zero-Trust IP is a major paradigm shift that moves beyond static reputation lookups to evaluate a client’s behavioral intent. Under a Zero-Trust IP policy, the firewall dynamically tracks local client DNS traffic. If an endpoint attempts to connect outbound to a public cloud IP address, the firewall verifies if that connection was preceded by a valid, benign DNS resolution.
If a legitimate user opens an application, a DNS request is made, cached, and the connection is allowed. However, if an evasive malware script attempts to phone home direct-to-IP to a hardcoded host in AWS or GCP, Zero-Trust IP identifies the complete lack of a preceding DNS query. It instantly identifies the connection as direct-to-IP, and allows the admin to choose an action — (allow or drop), even if that shared cloud IP is explicitly allowed for business traffic.
Rather than treating IP addresses as binary "allow or deny" blocklists, Advanced IP Defense continuously profiles and categorizes every publicly routable IPv4 address across over 40 rich, dynamic security attributes. These attributes are organized into seven primary, content-delivered categories:
Because blocking at the IP layer carries high false-positive risks, Palo Alto Networks engineered a patented pipeline called the Indicator of Benignity. Standard threat feeds only look for signs of compromise. The Indicator of Benignity engine actively searches for positive indicators of clean, legitimate usage to counterprove and immediately suppress malicious classifications. This rigorous filtering maintains an exceptionally high standard of precision, keeping false positives to an absolute minimum so network teams can sleep at night.
Operating inline and cloud-delivered, Advanced IP Defense addresses these structural weaknesses at the network layer, requiring zero SSL/TLS decryption to evaluate and enforce security verdicts. It achieves this through three core technical capabilities:
Outbound Protection: Stopping Direct-to-IP Malware & Exfiltration
Inbound Protection: Hardening Public Gateways
To ensure a smooth, disruption-free deployment of Advanced IP Defense, Palo Alto Networks recommends the following administrative guardrails:
Advanced IP Defense extends Precision AI to the network layer, hardening your perimeter against threats that bypass standard protocol and web-level inspection engines:
Shifting prevention to the edge replaces 20-day feed lags with real-time intelligence, removes static blocklist overhead, and slashes SOC alert noise across the 67% of enterprise networks exposed to preventable network-layer threats.
Ready to close your network-layer evasion gaps?
Evaluate Your Exposure with a Security Lifecycle Review (SLR): Palo Alto Networks has integrated Advanced IP Defense reporting directly into the Security Lifecycle Review (SLR) tool. Work with your account team to run an SLR on your edge firewalls to receive a customized report highlighting the stealthy direct-to-IP bypasses, malicious scanners, and anonymizers currently traversing your network uninspected.
Activate a 30-Day Free Trial: Qualified customers can immediately activate a 30-day free trial. Run the profile in "Alert" (monitor-only) mode first to validate detection accuracy and view full threat visibility in your SCM dashboards without any risk of traffic interruption.
Prepare for PAN-OS 12.2 Ceres: To leverage full real-time inline cloud lookups, zone-based profiles, and Zero-Trust IP behavioral enforcement, coordinate with your network security team to plan your upgrade to PAN-OS 12.2 (Ceres).
Contact your Palo Alto Networks account representative today to schedule a live, technical demonstration of Advanced IP Defense.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
| Subject | Likes |
|---|---|
| 7 Likes | |
| 3 Likes | |
| 3 Likes | |
| 2 Likes | |
| 2 Likes |

