3 Access Apps Networks Mgmt Mobility Edge Copyright © 2013 Juniper Networks, Inc. Data center Cloud Products
SECURITY AT JUNIPER
Security innovation
& leadership
Customer segments
Service Providers, Enterprise
Business segments
Routing, Switching, Security
Invest more than 20% of revenue on R&D
Leader in high-end firewalls and remote access SSL VPN
Pioneer in Intrusion Deception technology
DDoS advanced technology
First to deliver purpose-built virtual firewall
SC Magazine 2014 best cloud, UTM and NAC solution
Tech Target’s 2013 reader’s choice gold awards for virtual
security, IDP
, and NAC
5
Copyright © 2013 Juniper Networks, Inc. www.juniper.net
7
Copyright © 2013 Juniper Networks, Inc. www.juniper.net
9
Copyright © 2013 Juniper Networks, Inc. www.juniper.net
THE GAPS THAT DDOS SECURE ADDRESSES
New attacks: before the signature exists
Low-and-slow application attacks
1
11
Copyright © 2013 Juniper Networks, Inc. www.juniper.net
• DNS/URL Response Time
• URL Rate, Pending counts
• HTTP Server Error Codes
KEY CONCEPT: RESOURCE HEALTH
Resource health:
real-time view of status for every discrete “thing”
on protected interface, based on stateful analysis of source and
resource responsiveness
Internet Traffic
Internet Traffic
Resources
Internet Traffic
DDoS Secure
L7
• Backlog Queue (per resource, per port)
• TCP stats: SYN, SYN-ACK, CLS, RST, etc
L3-4
Ex
a
m
p
le
s
13
Copyright © 2013 Juniper Networks, Inc. www.juniper.net
JUNOS DDoS SECURE PACKET FLOW SEQUENCE
Drop Packet
IP Behavior Table
Resource
CHARM Threshold
Drop Packet
Packet
Enters
Syntax
Screener
OK
So Far
CHARM
Generator
With
CHARM
Value
CHARM
Screener
Packet
Exits
Validates data packet
Validates against defined filters
Validates packet against RFCs
Validates packet sequencing
TCP Connection state
1
Calculates CHARM value
for data packet
References IP behaviour table
Function of time and historical behaviour
Better behaved = better CHARM
2
Behaviour is
recorded
Supports up to
32M profiles
Profiles aged on least
used basis
3
Calculates
CHARM
Threshold
Responsiveness
of Resource
4
Allow or Drop
CHARM Threshold
CHARM value
5
15
Copyright © 2013 Juniper Networks, Inc. www.juniper.net
LOW AND SLOW ATTACKS
What to say about DDoS Secure and Topology
DDoS Secure is an in-line device, usually deployed at the data center edge (behind
internet facing router, in front of firewall)
DDoS Secure performs real-time stateful analysis and heuristics of packets, both
inbound and outbound, as they pass
Source IP addresses are given a real-time “risk score” called CHARM
Resource health (web server, firewall, etc) is monitored and have a CHARM
threshold
Once resource starts to struggle, threshold is raised, and packets with a lower
CHARM score are rate limited
One website is in “logging” mode so we can see the results of the attack. The other
website is in “defending” mode so we can see how the attack is mitigated.
16
Copyright © 2013 Juniper Networks, Inc. www.juniper.net
VOLUME ATTACK
What to say:
Once again, DDoS Secure is sitting inline behind the router.
Attacker is sending traffic to the web server (but it could also be the
customer’s firewall or load balancer) and is attempting to
overwhelm the customers network pipe
But DDoS Secure will detect the attack, and will signal the
upstream router to redirect the traffic so that the network is not
saturated
17
Copyright © 2013 Juniper Networks, Inc. www.juniper.net
JUNOS DDoS SECURE SUMMARY
Dynamic
Heuristic Technology
99.999% effective
after 6-12 hours
Outstanding 24/7
support
Virtualized
options available
Multi Tenanted and
fully IPv6 compliant
1Gb to 10Gb
HA appliances
Layer 2
Transport Bridge
No Public
IP address
80% Effective
10 mins after
installation