• No results found

JUNOS DDoS SECURE. Advanced DDoS Mitigation Technology

N/A
N/A
Protected

Academic year: 2021

Share "JUNOS DDoS SECURE. Advanced DDoS Mitigation Technology"

Copied!
18
0
0

Loading.... (view fulltext now)

Full text

(1)

JUNOS DDoS SECURE

(2)

Biography

Nguyen Tien Duc

[email protected], +84 903344505

Consulting Engineer- Viet Nam

CISSP # 346725

CISA # 623462

(3)

3 Access Apps Networks Mgmt Mobility Edge Copyright © 2013 Juniper Networks, Inc. Data center Cloud Products

SECURITY AT JUNIPER

Security innovation

& leadership

Customer segments

Service Providers, Enterprise

Business segments

Routing, Switching, Security

Invest more than 20% of revenue on R&D

Leader in high-end firewalls and remote access SSL VPN

Pioneer in Intrusion Deception technology

DDoS advanced technology

First to deliver purpose-built virtual firewall

SC Magazine 2014 best cloud, UTM and NAC solution

Tech Target’s 2013 reader’s choice gold awards for virtual

security, IDP

, and NAC

(4)

DDOS ATTACK VECTORS

VOLUMETRIC

• Easy to detect.

• Attacks are getting bigger in

size

• Frequency of attacks

increasing at a moderate

rate.

ANYTHING THAT MAKES

THE RESOURCES BUSY

• Flash mobs.

• Legitimate requests for a big

event available at one time.

SLOW AND LOW

• Growing faster than

volumetric – 25% of attacks

in 2013 (source: Gartner)

• More sophisticated

& difficult to detect

• Target back-end weaknesses

• Small volume of requests

can take out a large web

site.

(5)

5

Copyright © 2013 Juniper Networks, Inc. www.juniper.net

(6)

LOW ION ORBIT CANNON (LOIC)

Flood any site

Easy to download

Simple to run

(7)

7

Copyright © 2013 Juniper Networks, Inc. www.juniper.net

(8)

EVOLVING ATTACK COMPLEXITY

Signature-Based

Scrubbers

Thresholds &

Netflow Analysis

Emerging

Battleground

S

te

a

lt

h

Newness

Known

Unknown

V

o

lu

m

e

tr

ic

Low

-an

d

-sl

o

w

Challenge

: manual

management of IP

thresholds in

dynamic networks

Challenge

: Creating

signatures for new

attacks

(9)

9

Copyright © 2013 Juniper Networks, Inc. www.juniper.net

THE GAPS THAT DDOS SECURE ADDRESSES

New attacks: before the signature exists

Low-and-slow application attacks

1

(10)

KEY CONCEPT: CHARM

Simple example: real human

traffic typically bursty and

irregular; machine/bot traffic is

regular

Algorithms updated regularly with

characteristics of new attacks

CHARM:

Real-time risk score for each source IP

0

100

Initial

50

Human-like

Machine-like

(11)

11

Copyright © 2013 Juniper Networks, Inc. www.juniper.net

• DNS/URL Response Time

• URL Rate, Pending counts

• HTTP Server Error Codes

KEY CONCEPT: RESOURCE HEALTH

Resource health:

real-time view of status for every discrete “thing”

on protected interface, based on stateful analysis of source and

resource responsiveness

Internet Traffic

Internet Traffic

Resources

Internet Traffic

DDoS Secure

L7

• Backlog Queue (per resource, per port)

• TCP stats: SYN, SYN-ACK, CLS, RST, etc

L3-4

Ex

a

m

p

le

s

(12)

JUNOS DDoS SECURE RESOURCE MANAGEMENT

In this example, Resource

2’s response time starts to

degrade and the CHARM

pass threshold is increased

to start the process of rate

limiting the bad traffic.

At this point the good traffic

will continue to pass

unhindered whilst the

attackers will start to believe

their attack has been

successful

as their request fails.

Resource 1

Resource 2

Resource 3

Resource ‘N’

The attack traffic to Resource

2 reduces as the attackers

switch the attack to

Resource 3.

Once again, Junos DDoS

Secure responds

dynamically by increasing

the pass threshold for

Resource 3 Limiting bad

traffic.

(13)

13

Copyright © 2013 Juniper Networks, Inc. www.juniper.net

JUNOS DDoS SECURE PACKET FLOW SEQUENCE

Drop Packet

IP Behavior Table

Resource

CHARM Threshold

Drop Packet

Packet

Enters

Syntax

Screener

OK

So Far

CHARM

Generator

With

CHARM

Value

CHARM

Screener

Packet

Exits

Validates data packet

Validates against defined filters

Validates packet against RFCs

Validates packet sequencing

TCP Connection state

1

Calculates CHARM value

for data packet

References IP behaviour table

Function of time and historical behaviour

Better behaved = better CHARM

2

Behaviour is

recorded

Supports up to

32M profiles

Profiles aged on least

used basis

3

Calculates

CHARM

Threshold

Responsiveness

of Resource

4

Allow or Drop

CHARM Threshold

CHARM value

5

(14)

HEURISTIC MITIGATION IN ACTION

Junos DDoS Secure

Heurisitc Analysis

DDoS Attack Traffic

Management PC

Normal Internet Traffic

DDoS Attack Traffic

Normal Internet Traffic

Resources

Normal Internet traffic flows through the Junos DDoS Secure Appliance, while the software analyses

the type, origin, flow, data rate, sequencing, style and protocol being utilized by all inbound and

outbound traffic. The analysis is heuristic in nature and adjusts over time but is applied in real time,

with minimal (store and forward) latency.

(15)

15

Copyright © 2013 Juniper Networks, Inc. www.juniper.net

LOW AND SLOW ATTACKS

What to say about DDoS Secure and Topology

DDoS Secure is an in-line device, usually deployed at the data center edge (behind

internet facing router, in front of firewall)

DDoS Secure performs real-time stateful analysis and heuristics of packets, both

inbound and outbound, as they pass

Source IP addresses are given a real-time “risk score” called CHARM

Resource health (web server, firewall, etc) is monitored and have a CHARM

threshold

Once resource starts to struggle, threshold is raised, and packets with a lower

CHARM score are rate limited

One website is in “logging” mode so we can see the results of the attack. The other

website is in “defending” mode so we can see how the attack is mitigated.

(16)

16

Copyright © 2013 Juniper Networks, Inc. www.juniper.net

VOLUME ATTACK

What to say:

Once again, DDoS Secure is sitting inline behind the router.

Attacker is sending traffic to the web server (but it could also be the

customer’s firewall or load balancer) and is attempting to

overwhelm the customers network pipe

But DDoS Secure will detect the attack, and will signal the

upstream router to redirect the traffic so that the network is not

saturated

(17)

17

Copyright © 2013 Juniper Networks, Inc. www.juniper.net

JUNOS DDoS SECURE SUMMARY

Dynamic

Heuristic Technology

99.999% effective

after 6-12 hours

Outstanding 24/7

support

Virtualized

options available

Multi Tenanted and

fully IPv6 compliant

1Gb to 10Gb

HA appliances

Layer 2

Transport Bridge

No Public

IP address

80% Effective

10 mins after

installation

(18)

References

Related documents

AEs: Adverse events; CI: Confidence interval; CONSORT: Consolidated Standards of Reporting Trials; CRASH-2: Clinical randomisation of an anti-fibrinolytic in

As we shall see, there are three 3-tiling configurations: two imprimitive variations of the 2-tiling (see Figure 2.3.3 and Figure 2.3.4), and a primitive configuration that we will

All stationary perfect equilibria of the intertemporal game approach (as slight stochastic perturbations as in Nash (1953) tend to zero) the same division of surplus as the static

Key words: Ahtna Athabascans, Community Subsistence Harvest, subsistence hunting, GMU 13 moose, Alaska Board o f Game, Copper River Basin, natural resource management,

Even if they do, however, enough differences remain in mostly unchar- acterized minor antigens to enable immune cells from the donor and the host to recognize the other as “non-

The Advanced Warning Flasher (AWF) is a device that, at certain high-speed locations, has been found to provide additional information to the motorist describing the operation of