Advanced DDoS Protection for Service Providers & MSSPsRon Meyran – Director Product Marketing SecurityJuly 2011
AgendaDDoS Is Growing & EvolvingKey Success Criteria for Service Providers & MSSPs Radware’s Advanced SolutionCustomer CasesSummary Slide 2
DDoS is growing and evolving
DDoS Threat is growingSlide 4Attack sizeOperation Sony DDoSOperation Payback II on Codero; Netbot DDoS on Wordpress.comOperation payback – Wikileaks revenge DDoS attacksJuly 2009 cyber attacks (US and south korea)IMDDOS – Commercial BotnetSlowloris - Low & Slow AttacksTwitter DDOS attack on CyxymuTime200920112010Source: Radware ERT report
When you have no Anti-DoS solution in place…Slide 5Wikileaks site outageWestboro Baptist Outage4 sites held down for 6 days
Poll questionHow many DDoS attacks did you (or your customer) face in the past year?NoneOnly onceFew timesMany timesI don’t have the tools to detect DDOS attacksSlide 6
Multi-Vulnerability Attack CampaignsSlide 7Large volume network flood attacksConclusions Attackers use multi-vulnerability attack campaigns making mitigation nearly impossible
  Even if one attack vector is successful – the business is severely impactedLarge volume SYN floodLow & Slow connection DoS attacksBusinessSlow Application flood attack (Slowloris)Application flood attack (HTTP data flood)BUSINESSIMPACT
DDoS Protection: layers of defenseSlide 8Type of DoS attacks:PPS & Bandwidth flood attacksConnection & application flood attacksDirected application DoS attacksHighMedAttack volume:LowChallenges:PPS Processing capacity
Bandwidth capacity
Identify malicious sources
Accurate mitigation – all     sessions are legitimate
Deep packet inspection
Ad-hoc filters creation
   Accurate mitigation – maintain very low false positives
   Time to protectKey criteria to become a successful MSSP
What drives the MSSP success? (1 of 2)BusinessTrue DDoS ProtectionCan you detect and protect emerging DDoS attacks including multi-vulnerability campaign attacks and slow DDoS attacks?How fast can you detect and protect against attacks? In seconds? In minutes?FinancialSolution scalabilityCan your infrastructure grow without painful forklift upgrades?How do you price your service?Monthly feeOn demand / per incidentSLA penalties / rewardsSlide 10
What drives the MSSP success? (1 of 2)Technical Flexible deploymentFit any customer architectureOperationalCustomer centric reportingEasy integration into provider environment (OSS, SEM, SOC)MarketingWhat is unique in your offering?SLA: can you guarantee Time to protect?Coverage – what type of attacks do you protect, and what you don’t?Multi locations vs. single locationCustomers portfolio and testimonialsSlide 11
Radware solution for DDoS service providers
DDoS Protection: Radware coverageSlide 13Radware DDoS Protections:PPS & Bandwidth flood attacksConnection & application flood attacksDirected application DoS attacksASIC-Based DoS Mitigator Engine (DME)Real-time signatures technologyMulti-core CPUsReal-time signatures & challenge -response technologiesStringMatch Engine (SME) RegEx EngineStatic & user filtersUp to 12MPPS of attack preventionUp to 800K new TPS of HTTP Challenge-ResponseFull 10Gbps DPI (RegEx) processing
DDoS Protection: Radware technologiesSlide 14PPS & Bandwidth flood attacksConnection & application flood attacksDirected application DoS attacks Behavioral based real-time signatures blocking
 SYN Protection (SYN cookies; Web cookies)
 Rate based protections
 HTTP & DNS advanced Challenge –Response techniques
 Behavioral based real-time signatures
Rate based protections
 Auto-updated RegEx filters
 Counter attack techniques
 Ad-hoc filters
 Widest DDoS attacks coverage out-of-the-box

Radware Solutions for MSSPs

  • 1.
    Advanced DDoS Protectionfor Service Providers & MSSPsRon Meyran – Director Product Marketing SecurityJuly 2011
  • 2.
    AgendaDDoS Is Growing& EvolvingKey Success Criteria for Service Providers & MSSPs Radware’s Advanced SolutionCustomer CasesSummary Slide 2
  • 3.
    DDoS is growingand evolving
  • 4.
    DDoS Threat isgrowingSlide 4Attack sizeOperation Sony DDoSOperation Payback II on Codero; Netbot DDoS on Wordpress.comOperation payback – Wikileaks revenge DDoS attacksJuly 2009 cyber attacks (US and south korea)IMDDOS – Commercial BotnetSlowloris - Low & Slow AttacksTwitter DDOS attack on CyxymuTime200920112010Source: Radware ERT report
  • 5.
    When you haveno Anti-DoS solution in place…Slide 5Wikileaks site outageWestboro Baptist Outage4 sites held down for 6 days
  • 6.
    Poll questionHow manyDDoS attacks did you (or your customer) face in the past year?NoneOnly onceFew timesMany timesI don’t have the tools to detect DDOS attacksSlide 6
  • 7.
    Multi-Vulnerability Attack CampaignsSlide7Large volume network flood attacksConclusions Attackers use multi-vulnerability attack campaigns making mitigation nearly impossible
  • 8.
    Evenif one attack vector is successful – the business is severely impactedLarge volume SYN floodLow & Slow connection DoS attacksBusinessSlow Application flood attack (Slowloris)Application flood attack (HTTP data flood)BUSINESSIMPACT
  • 9.
    DDoS Protection: layersof defenseSlide 8Type of DoS attacks:PPS & Bandwidth flood attacksConnection & application flood attacksDirected application DoS attacksHighMedAttack volume:LowChallenges:PPS Processing capacity
  • 10.
  • 11.
  • 12.
    Accurate mitigation –all sessions are legitimate
  • 13.
  • 14.
  • 15.
    Accurate mitigation – maintain very low false positives
  • 16.
    Time to protectKey criteria to become a successful MSSP
  • 17.
    What drives theMSSP success? (1 of 2)BusinessTrue DDoS ProtectionCan you detect and protect emerging DDoS attacks including multi-vulnerability campaign attacks and slow DDoS attacks?How fast can you detect and protect against attacks? In seconds? In minutes?FinancialSolution scalabilityCan your infrastructure grow without painful forklift upgrades?How do you price your service?Monthly feeOn demand / per incidentSLA penalties / rewardsSlide 10
  • 18.
    What drives theMSSP success? (1 of 2)Technical Flexible deploymentFit any customer architectureOperationalCustomer centric reportingEasy integration into provider environment (OSS, SEM, SOC)MarketingWhat is unique in your offering?SLA: can you guarantee Time to protect?Coverage – what type of attacks do you protect, and what you don’t?Multi locations vs. single locationCustomers portfolio and testimonialsSlide 11
  • 19.
    Radware solution forDDoS service providers
  • 20.
    DDoS Protection: RadwarecoverageSlide 13Radware DDoS Protections:PPS & Bandwidth flood attacksConnection & application flood attacksDirected application DoS attacksASIC-Based DoS Mitigator Engine (DME)Real-time signatures technologyMulti-core CPUsReal-time signatures & challenge -response technologiesStringMatch Engine (SME) RegEx EngineStatic & user filtersUp to 12MPPS of attack preventionUp to 800K new TPS of HTTP Challenge-ResponseFull 10Gbps DPI (RegEx) processing
  • 21.
    DDoS Protection: RadwaretechnologiesSlide 14PPS & Bandwidth flood attacksConnection & application flood attacksDirected application DoS attacks Behavioral based real-time signatures blocking
  • 22.
    SYN Protection(SYN cookies; Web cookies)
  • 23.
    Rate basedprotections
  • 24.
    HTTP &DNS advanced Challenge –Response techniques
  • 25.
    Behavioral basedreal-time signatures
  • 26.
  • 27.
  • 28.
    Counter attacktechniques
  • 29.
  • 30.
    Widest DDoSattacks coverage out-of-the-box