More Related Content Similar to Migliora la disponibilità e le prestazioni delle tue applicazioni con Amazon Global Network (20) More from Amazon Web Services (20) Migliora la disponibilità e le prestazioni delle tue applicazioni con Amazon Global Network1. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Improve your application’s availability and
performance with Amazon Global Network
Marco Cagna, Sr. Product Manager, AWS
N E T 1 + N E T 2
2. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Agenda
1. Benefits of the the Amazon Global Network
2. How Universitá Pegaso delivers content via Amazon CloudFront
3. Improve the availability and performance of your applications with
AWS Global Accelerator
4. Transport, Process, Package, Originate, and Monetize your video
content with AWS Elemental Media Services
5. Secure your web applications with AWS Shield and AWS WAF
3. S U M M I T © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
Benefits of the the Amazon Global
Network
4. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Benefits of the Amazon global network
Superior network:
abundant, fast,
always on
5. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
AWS Global Infrastructure
• 19 Regions with 58 Availability Zones
• 5 Regions coming soon: Bahrain,
Cape Town, Hong Kong SAR,
Stockholm, and second USA GovCloud
6. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
150 CloudFront PoPs
• 139 Edge Locations
• 11 Regional Edge Caches
7. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
89 Direct Connect
Locations
8. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Amazon Global Network
• Redundant 100 GbE network
• Private network capacity between
all AWS region, except China
9. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Why have a backbone network?
10. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T © 2018, Amazon Web Services, Inc. or its affiliates. All rights reserved.
11. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Multiple services traverse the backbone
12. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Private connectivity with AWS Direct Connect
Dedicated private connection
from on-premised to AWS
Consistent network
performance
Reduced bandwidth costs
Compatible with all
AWS services
13. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Private connectivity with Inter-region Peering
Private connectivity for two
or more VPCs between regions
Highly available, no single
point of failure
All traffic stays on the AWS
global backbone network
All traffic encrypted and
anonymized
14. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Content Distribution with Amazon CloudFront
Fast, massively scaled and
globally distributed
Highly Programmable
Deep Integration with AWS
Network and application
protection at the edge
15. S U M M I T © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
16. S U M M I T © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
17. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Multiple services traverse the backbone
18. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
AWS Global Accelerator
Global
Accelerator
AWS ApplicationsClient
19. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
AWS Global Accelerator
Availability Ease of UsePerformance
20. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Our customers represent different industries
Digital Publishing Mobile Apps Media
Internet of Things Ad-tech Financial services
AWS Global Accelerator
provides value for any
critical, latency-sensitive
application
Global
Accelerator
21. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Key features
Global
Accelerator
22. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Static anycast IP addresses
1.2.3.4
2.3.4.5
3.4.5.6
23. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Static anycast IP addresses
1.2.3.4
2.3.4.5
3.4.5.6
24. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Static anycast IP addresses
Cache
192.0.2.1
www.example.com
1.2.3.4
2.3.4.5
3.4.5.6
25. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
AWS Global Accelerator
192.0.2.1
192.0.2.1
192.0.2.1
26. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
AWS Global Accelerator
27. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
AWS Global Accelerator
28. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
AWS Global Accelerator
29. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Fault isolating design
192.0.2.0/24
Network Zone A
198.51.100.0/24
Network Zone B
Anycast BGP
announcements
30. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Accelerator configuration
1.2.3.4
us-east-1
us-west-2
us-east-1
Endpoints: ALB
1, ALB 2
TCP
80,443
UDP
53
5.6.7.8
ap-southeast-1
us-east-1
ap-northeast-1
Endpoints: ALB
1, NLB 1
31. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
How is the endpoint selected?
Application health Geo-proximity Customer-
configured policies
Client affinity
settings
32. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Easy traffic control - Regional Traffic dials
Region : us-east-1
Region : us-west-1
Dial values: Min 0%; Max 100%; Default 100%
33. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Easy traffic control - Regional Traffic dials
Region : us-east-1
Region : us-west-1
Dial values: Min 0%; Max 100%; Default 100%
34. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Easy traffic control - Endpoint Weights
Region : us-east-1
Region : us-west-1
Weights values: Min 0; Max 255; Default 128
35. S U M M I T © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
36. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Prep, process and protect (e.g.
DRM, watermark) content
using AWS Media Services
Originate source
content (live feed or
VOD files)
Deliver content via
Amazon CloudFront or
AWS Global Accelerator
Video streaming applications at a glance
39
37. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. 40
AWS Elemental Media Services
AWS Elemental
MediaLive
Live Video
Processing
Live Video
Workflow
Video
On-Demand
Workflow
AWS Elemental
MediaPackage
Origination and
JIT Packaging
Live Channel
Source
AWS Elemental
MediaStore
Media-Optimized
Storage and Origin
AWS Elemental
MediaTailor
Personalization
and Monetization
AWS Elemental
MediaConvert
File-Based
Video Processing
Devices
AWS Elemental
Live
On-Premises
Encoding
Amazon
CloudFront
CDN
Amazon
CloudFront
CDN
Amazon S3
Storage
Amazon S3
VOD Origin
AWS Elemental
MediaConnect
Live Video
Transport
AWS Step
Functions
WorkflowMedia Source
Files
38. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. 41
AWS Elemental MediaConnect
AWS Elemental
MediaLive
Live Video
Processing
Live Video
Workflow
Video
On-Demand
Workflow
AWS Elemental
MediaPackage
Origination and
JIT Packaging
Live Channel
Source
AWS Elemental
MediaStore
Media-Optimized
Storage and Origin
AWS Elemental
MediaTailor
Personalization
and Monetization
AWS Elemental
MediaConvert
File-Based
Video Processing
Devices
AWS Elemental
Live
On-Premises
Encoding
Amazon
CloudFront
CDN
Amazon
CloudFront
CDN
Amazon S3
Storage
Amazon S3
VOD Origin
AWS Elemental
MediaConnect
Live Video
Transport
AWS Step
Functions
WorkflowMedia Source
Files
AWS Elemental MediaConnect is a
high-quality transport service for live
video.
39. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. 42
AWS Elemental MediaLive
AWS Elemental
MediaLive
Live Video
Processing
Live Video
Workflow
Video
On-Demand
Workflow
AWS Elemental
MediaPackage
Origination and
JIT Packaging
Live Channel
Source
AWS Elemental
MediaStore
Media-Optimized
Storage and Origin
AWS Elemental
MediaTailor
Personalization
and Monetization
AWS Elemental
MediaConvert
File-Based
Video Processing
Devices
AWS Elemental
Live
On-Premises
Encoding
Amazon
CloudFront
CDN
Amazon
CloudFront
CDN
Amazon S3
Storage
Amazon S3
VOD Origin
AWS Elemental
MediaConnect
Live Video
Transport
AWS Step
Functions
WorkflowMedia Source
Files
With AWS Elemental MediaLive,
video providers can stand up live
channels in minutes, not months.
40. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. 43
AWS Elemental MediaPackage
AWS Elemental
MediaLive
Live Video
Processing
Live Video
Workflow
Video
On-Demand
Workflow
AWS Elemental
MediaPackage
Origination and
JIT Packaging
Live Channel
Source
AWS Elemental
MediaStore
Media-Optimized
Storage and Origin
AWS Elemental
MediaTailor
Personalization
and Monetization
AWS Elemental
MediaConvert
File-Based
Video Processing
Devices
AWS Elemental
Live
On-Premises
Encoding
Amazon
CloudFront
CDN
Amazon
CloudFront
CDN
Amazon S3
Storage
Amazon S3
VOD Origin
AWS Elemental
MediaConnect
Live Video
Transport
AWS Step
Functions
WorkflowMedia Source
Files
AWS Elemental MediaPackage makes it
easy to enrich audience experiences
with time-shifted TV and to better
protect multiscreen content.
41. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. 44
AWS Elemental MediaStore
AWS Elemental
MediaLive
Live Video
Processing
Live Video
Workflow
Video
On-Demand
Workflow
AWS Elemental
MediaPackage
Origination and
JIT Packaging
Live Channel
Source
AWS Elemental
MediaStore
Media-Optimized
Storage and Origin
AWS Elemental
MediaTailor
Personalization
and Monetization
AWS Elemental
MediaConvert
File-Based
Video Processing
Devices
AWS Elemental
Live
On-Premises
Encoding
Amazon
CloudFront
CDN
Amazon
CloudFront
CDN
Amazon S3
Storage
Amazon S3
VOD Origin
AWS Elemental
MediaConnect
Live Video
Transport
AWS Step
Functions
WorkflowMedia Source
Files
AWS Elemental MediaStore acts as
an HTTP origin optimized for fast, low-
latency writes, decreasing the
risk of buffering video.
42. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. 45
AWS Elemental MediaTailor
AWS Elemental
MediaLive
Live Video
Processing
Live Video
Workflow
Video
On-Demand
Workflow
AWS Elemental
MediaPackage
Origination and
JIT Packaging
Live Channel
Source
AWS Elemental
MediaStore
Media-Optimized
Storage and Origin
AWS Elemental
MediaTailor
Personalization
and Monetization
AWS Elemental
MediaConvert
File-Based
Video Processing
Devices
AWS Elemental
Live
On-Premises
Encoding
Amazon
CloudFront
CDN
Amazon
CloudFront
CDN
Amazon S3
Storage
Amazon S3
VOD Origin
AWS Elemental
MediaConnect
Live Video
Transport
AWS Step
Functions
WorkflowMedia Source
Files
AWS Elemental MediaTailor
personalizes and delivers content while
mitigating ad blocking and providing a
better viewing experience.
43. © 2019, Amazon Web Services, Inc. or its Affiliates. All rights reserved. 46
AWS Elemental MediaConvert
AWS Elemental
MediaLive
Live Video
Processing
Live Video
Workflow
Video
On-Demand
Workflow
AWS Elemental
MediaPackage
Origination and
JIT Packaging
Live Channel
Source
AWS Elemental
MediaStore
Media-Optimized
Storage and Origin
AWS Elemental
MediaTailor
Personalization
and Monetization
AWS Elemental
MediaConvert
File-Based
Video Processing
Devices
AWS Elemental
Live
On-Premises
Encoding
Amazon
CloudFront
CDN
Amazon
CloudFront
CDN
Amazon S3
Storage
Amazon S3
VOD Origin
AWS Elemental
MediaConnect
Live Video
Transport
AWS Step
Functions
WorkflowMedia Source
Files
AWS Elemental MediaConvert provides
transcoding for mezzanine, broadcast
and multiscreen video delivery.
44. S U M M I T © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
45. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Biggest threats to web applications today
App
Vulnerabilities
Bad Bots
DDoS
0
200
400
600
800
1000
1200
1400
1600
1800
Largest DDoS Attacks (Gbps)
Mem
cached
Mirai
botnet
46. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Three layers of perimeter protection
Build a highly scalable, secure, well-monitored,
DDoS-protected application
Objective:
1. Secure content delivery layer with reduced surface area
2. Firewall layer for common and customer specific exploits
3. DDoS protection layer for mitigating availability impact
Software
automation
of security
47. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Layered perimeter protection – Basic AWS Application
EC2 Instance
S3 Bucket
Public
Subnet
Private
Subnet
ALB
48. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
S3 Origin Access Identity
• Prevents direct access to your
Amazon S3 bucket
• No S3 URLs are accessible directly
Custom Origin Security Groups
• Whitelist ONLY the
CloudFront IP range
• Protects origin from overload
Restricting external access to your origin
CloudFront ALB EC2CloudFront S3
49. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Layered perimeter protection – Adding secure
Content Delivery
EC2 Instance
S3 Bucket
Public
Subnet
Private
Subnet
CloudFront
ALB
50. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Choosing a Web Application Firewall:
AWS WAF
Security
Automations
Managed Rules
for AWS WAF
Multiple Rule
Condition Types
Combine and
build hierarchy
Actions : Allow /
Block / Count
CloudWatch
Metrics
Sampled Web
Requests
Full Logs
Lambda
Automations
AWS Firewall
Manager
51. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Layered perimeter protection – Adding a Firewall
EC2 Instance
S3 Bucket
Public
Subnet
Private
Subnet
CloudFront
WAF
ALB
Firewall
Manager
52. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Choosing a DDoS protection provider:
AWS Shield Standard & Advanced
Automatic
Protection across
customers
Enhanced
Protection
baselined to you
24x7 access to
DDoS Response
Team (DRT)
Built-in DDoS
Protection for
Everyone
Point and
Protect Wizard
AWS WAF at no
additional cost
For protected resources
AWS Firewall
Manager at no
additional cost
Cost Protection
for scaling
CloudWatch
Metrics
Attack
Diagnostics
Global Threat
Environment
Dashboard
53. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Layered perimeter protection – Adding DDoS
Protection
EC2 Instance
S3 Bucket
Public
Subnet
Private
Subnet
Shield
Shield
Advanced
ALB
CloudFront
WAF
Firewall
Manager
54. S U M M I T © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.
55. © 2019, Amazon Web Services, Inc. or its affiliates. All rights reserved.S U M M I T
Summary
1. Benefits of the the Amazon Global Network
2. How Universitá Pegaso delivers content via Amazon CloudFront
3. Improve the availability and performance of your applications with
AWS Global Accelerator
4. Transport, Process, Package, Originate, and Monetize your video
content with AWS Elemental Media Services
5. Secure your web applications with AWS Shield and AWS WAF