3.10 Ensure 'Enable predict network actions' is set to 'Enabled: Do not predict actions on any network connection'

Information

Google Chrome comes with the network prediction feature which provides DNS prefetching, TCP and SSL preconnection, and prerendering of web pages.

Predict network actions on any network connection (0) or (1)

Do not predict network actions on any network connection (2)

The recommended state for this setting is: Enabled with a value of Do not predict network actions on any network connection (2)

Rationale:

Opening connections to resources that may not be used could allow unneeded connections increasing attack surface and in some cases could lead to opening connections to resources which the user did not intend to utilize.

Impact:

Users will not be presented with web page predictions.

Solution

To establish the recommended configuration via Group Policy, set the following UI path to Enabled: Do not predict network actions on any network connection:

Computer Configuration\Administrative Templates\Google\Google Chrome\Enable network prediction

Default Value:

Unset (Same as Enabled with a value of Predict network actions on any network connection)

See Also

https://workbench.cisecurity.org/benchmarks/8691

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b.

Plugin: Windows

Control ID: b12ae72144c1e219556366865df08defc9ba527bf9dbb1b746b0d303032a2279