SlideShare a Scribd company logo
Christian Teuschel | November 2016 | Skopje
DDos Prevention and
Mitigation
Christian Teuschel | Skopje | November 2016 2
Friday, 21 October 2016
http://downdetector.com/
http://dyn.com/blog/dyn-statement-on-10212016-ddos-attack/
Christian Teuschel | Skopje | November 2016 3
Denial-Of-Service 101
• What?
- Attack on IT infrastructure
- Make machine/network resource unavailable
- Temporary or indefinite
- Not a new invention!
Christian Teuschel | Skopje | November 2016 4
Denial-Of-Service 101
• How?
- Crashing service
- Flooding service
• Effect
- Prevent legitimate users to be serviced
Christian Teuschel | Skopje | November 2016 5
Denial-Of-Service 101
• Targets:
- Usually high-profile sites
- But not only
• Initiators
- Hackers
- Script kids
- Criminals
- State actor
- Insider
Christian Teuschel | Skopje | November 2016 6
Denial-Of-Service 101
• Costs
- Mitigation costs
- Lost revenue
- Reputation
Christian Teuschel | Skopje | November 2016 7
Special Forms Of DOS
• Distributed DOS
- Involving multiple devices in the attack
• APDOS
- Involving an advanced persistent thread
- Requires resources and sophistication
• DOS as a service
- Entry barrier is getting lower
- Growing market
Focus
http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-russian-underground-101.pdf
Christian Teuschel | Skopje | November 2016 8
DDoS Attack Classes
• TCP Connection Attack
- Intention to use up available connections
• Volumetric Attack
- Intention to cause congestions
• Fragmentation Attack
- Intention to overwhelm request handling
• Application Attack
- Intention to exploit specific aspects of an application
Christian Teuschel | Skopje | November 2016 9
DDoS Amplification
• DNS Reflection
- Small request, big response
• Chargen Reflection
- Streams of random characters on demand
Christian Teuschel | Skopje | November 2016 10
Statistics on DDos
http://www.digitalattackmap.com/
State of the Internet Security Report by Akamai
Christian Teuschel | Skopje | November 2016 11
Statistics on DDos
State of the Internet Security Report by Akamai
Christian Teuschel | Skopje | November 2016 12
DDos Prevention
• Keep your software up-to-date
• Know your network and services
- Make inventory on a regular basis
- Monitor
• Don’t make enemies and avoid becoming a
target
Christian Teuschel | Skopje | November 2016 13
DDos Prevention
• Recommendations by the Dutch government
- Make an overview and monitor your infrastructure
- Check with each of your third-party suppliers to find out
which (D)DoS countermeasures are in place and what the
relevant contractual agreements are
- Find out which countermeasures have been taken to
protect your in-house infrastructure and take additional
steps, if necessary
- Prepare your incident response and think about failover
scenarios for your online services
- Prepare a communication strategy
Christian Teuschel | Skopje | November 2016 14
DDos Prevention
• Ingress filtering (BCP38)
• RPKI
• BGPSEC
Christian Teuschel | Skopje | November 2016 15
DDos Mitigation
• Detection!!!
- You need to be able to detect an attack
- Popular service vs. attack
Christian Teuschel | Skopje | November 2016 16
DDos Mitigation
• BGP blackholing
Christian Teuschel | Skopje | November 2016 17
DDos Mitigation
• Traffic Scrubbing
- Services like NaWas
https://www.neustar.biz/resources/product-literature/siteprotect-ddos-mitigation-failover-service
Christian Teuschel | Skopje | November 2016 18
DDos Mitigation
• Spread the word and inform the right people
- Abuse-c
- National CERTs
- Affected companies
Christian Teuschel | Skopje | November 2016 19
DDos Mitigation
• Spread it even further
• Working Group mailing list
- Routing WG
- Anti-Abuse WG
• NOG/National lists
- NANOG
- NLNOG, DENOG, PLNOG, SWINOG, etc.
- MKNOG?
Questions
christian.teuschel@ripe.net
@cteuschel

More Related Content

What's hot

Applications of Internet Data
Applications of Internet DataApplications of Internet Data
Applications of Internet Data
RIPE NCC
 
The RIPE Community and Ethical Considerations
The RIPE Community and Ethical ConsiderationsThe RIPE Community and Ethical Considerations
The RIPE Community and Ethical Considerations
RIPE NCC
 
RIPE Routing Information Service
RIPE Routing Information ServiceRIPE Routing Information Service
RIPE Routing Information Service
RIPE NCC
 
RIR Collaboration on RIPEstat
RIR Collaboration on RIPEstatRIR Collaboration on RIPEstat
RIR Collaboration on RIPEstat
RIPE NCC
 
The (IPv6) Internet in Romania - RIPE NCC Data and Tools
The (IPv6) Internet in Romania - RIPE NCC Data and ToolsThe (IPv6) Internet in Romania - RIPE NCC Data and Tools
The (IPv6) Internet in Romania - RIPE NCC Data and Tools
RIPE NCC
 
Data in Switzerland: BFS at OKCon 2013
Data in Switzerland: BFS at OKCon 2013Data in Switzerland: BFS at OKCon 2013
Data in Switzerland: BFS at OKCon 2013
CH_Bundesarchiv
 
GND and URIs: Integration and Identification
GND and URIs: Integration and IdentificationGND and URIs: Integration and Identification
GND and URIs: Integration and Identification
Reinhold Heuvelmann
 
Linked Data at the German National Library
Linked Data at the German National LibraryLinked Data at the German National Library
Linked Data at the German National Library
Reinhold Heuvelmann
 
ION Bucharest - Update on the Why and How of IPv6 Deployment
ION Bucharest - Update on the Why and How of IPv6 DeploymentION Bucharest - Update on the Why and How of IPv6 Deployment
ION Bucharest - Update on the Why and How of IPv6 Deployment
Deploy360 Programme (Internet Society)
 
Global Reports - LACNIC
Global Reports - LACNICGlobal Reports - LACNIC
Global Reports - LACNIC
ARIN
 
RIPE NCC Data Sets for Researchers
RIPE NCC Data Sets for ResearchersRIPE NCC Data Sets for Researchers
RIPE NCC Data Sets for Researchers
RIPE NCC
 
RIPE NCC Update
RIPE NCC UpdateRIPE NCC Update
RIPE NCC Update
RIPE NCC
 
Mapping New Zealand's Broadband Infrastructure
Mapping New Zealand's Broadband InfrastructureMapping New Zealand's Broadband Infrastructure
Mapping New Zealand's Broadband Infrastructure
APNIC
 
2017 iii 3_jiri_polacek_inspire_implementationasalinkbetweenegovernmentandenv...
2017 iii 3_jiri_polacek_inspire_implementationasalinkbetweenegovernmentandenv...2017 iii 3_jiri_polacek_inspire_implementationasalinkbetweenegovernmentandenv...
2017 iii 3_jiri_polacek_inspire_implementationasalinkbetweenegovernmentandenv...
ATTRACTIVE DANUBE
 
IPv6 Observatory outomes
IPv6 Observatory outomesIPv6 Observatory outomes
IPv6 Observatory outomes
Fabrice Clari
 
Archivum rhenanum (Präsentation, ICARUS-Meeting Dublin, 26.6.2013; Elisabeth ...
Archivum rhenanum (Präsentation, ICARUS-Meeting Dublin, 26.6.2013; Elisabeth ...Archivum rhenanum (Präsentation, ICARUS-Meeting Dublin, 26.6.2013; Elisabeth ...
Archivum rhenanum (Präsentation, ICARUS-Meeting Dublin, 26.6.2013; Elisabeth ...
Abteilung Kulturelles Erbe (Stadtarchiv, Museen, Gedenkstätten) Speyer
 
Migration statistics in Eurostat - Definition, statistical production and dis...
Migration statistics in Eurostat - Definition, statistical production and dis...Migration statistics in Eurostat - Definition, statistical production and dis...
Migration statistics in Eurostat - Definition, statistical production and dis...
Giampaolo Lanzieri
 
OpenStreetMap as base layer in a linked open data distribution platform - Ber...
OpenStreetMap as base layer in a linked open data distribution platform - Ber...OpenStreetMap as base layer in a linked open data distribution platform - Ber...
OpenStreetMap as base layer in a linked open data distribution platform - Ber...
OSMFstateofthemap
 
Open-IX: Improving interconnection through industry standards
Open-IX: Improving interconnection through industry standardsOpen-IX: Improving interconnection through industry standards
Open-IX: Improving interconnection through industry standards
Internet Society
 
Unpredictable Traffic Bursts at npIX
Unpredictable Traffic Bursts at npIXUnpredictable Traffic Bursts at npIX
Unpredictable Traffic Bursts at npIX
APNIC
 

What's hot (20)

Applications of Internet Data
Applications of Internet DataApplications of Internet Data
Applications of Internet Data
 
The RIPE Community and Ethical Considerations
The RIPE Community and Ethical ConsiderationsThe RIPE Community and Ethical Considerations
The RIPE Community and Ethical Considerations
 
RIPE Routing Information Service
RIPE Routing Information ServiceRIPE Routing Information Service
RIPE Routing Information Service
 
RIR Collaboration on RIPEstat
RIR Collaboration on RIPEstatRIR Collaboration on RIPEstat
RIR Collaboration on RIPEstat
 
The (IPv6) Internet in Romania - RIPE NCC Data and Tools
The (IPv6) Internet in Romania - RIPE NCC Data and ToolsThe (IPv6) Internet in Romania - RIPE NCC Data and Tools
The (IPv6) Internet in Romania - RIPE NCC Data and Tools
 
Data in Switzerland: BFS at OKCon 2013
Data in Switzerland: BFS at OKCon 2013Data in Switzerland: BFS at OKCon 2013
Data in Switzerland: BFS at OKCon 2013
 
GND and URIs: Integration and Identification
GND and URIs: Integration and IdentificationGND and URIs: Integration and Identification
GND and URIs: Integration and Identification
 
Linked Data at the German National Library
Linked Data at the German National LibraryLinked Data at the German National Library
Linked Data at the German National Library
 
ION Bucharest - Update on the Why and How of IPv6 Deployment
ION Bucharest - Update on the Why and How of IPv6 DeploymentION Bucharest - Update on the Why and How of IPv6 Deployment
ION Bucharest - Update on the Why and How of IPv6 Deployment
 
Global Reports - LACNIC
Global Reports - LACNICGlobal Reports - LACNIC
Global Reports - LACNIC
 
RIPE NCC Data Sets for Researchers
RIPE NCC Data Sets for ResearchersRIPE NCC Data Sets for Researchers
RIPE NCC Data Sets for Researchers
 
RIPE NCC Update
RIPE NCC UpdateRIPE NCC Update
RIPE NCC Update
 
Mapping New Zealand's Broadband Infrastructure
Mapping New Zealand's Broadband InfrastructureMapping New Zealand's Broadband Infrastructure
Mapping New Zealand's Broadband Infrastructure
 
2017 iii 3_jiri_polacek_inspire_implementationasalinkbetweenegovernmentandenv...
2017 iii 3_jiri_polacek_inspire_implementationasalinkbetweenegovernmentandenv...2017 iii 3_jiri_polacek_inspire_implementationasalinkbetweenegovernmentandenv...
2017 iii 3_jiri_polacek_inspire_implementationasalinkbetweenegovernmentandenv...
 
IPv6 Observatory outomes
IPv6 Observatory outomesIPv6 Observatory outomes
IPv6 Observatory outomes
 
Archivum rhenanum (Präsentation, ICARUS-Meeting Dublin, 26.6.2013; Elisabeth ...
Archivum rhenanum (Präsentation, ICARUS-Meeting Dublin, 26.6.2013; Elisabeth ...Archivum rhenanum (Präsentation, ICARUS-Meeting Dublin, 26.6.2013; Elisabeth ...
Archivum rhenanum (Präsentation, ICARUS-Meeting Dublin, 26.6.2013; Elisabeth ...
 
Migration statistics in Eurostat - Definition, statistical production and dis...
Migration statistics in Eurostat - Definition, statistical production and dis...Migration statistics in Eurostat - Definition, statistical production and dis...
Migration statistics in Eurostat - Definition, statistical production and dis...
 
OpenStreetMap as base layer in a linked open data distribution platform - Ber...
OpenStreetMap as base layer in a linked open data distribution platform - Ber...OpenStreetMap as base layer in a linked open data distribution platform - Ber...
OpenStreetMap as base layer in a linked open data distribution platform - Ber...
 
Open-IX: Improving interconnection through industry standards
Open-IX: Improving interconnection through industry standardsOpen-IX: Improving interconnection through industry standards
Open-IX: Improving interconnection through industry standards
 
Unpredictable Traffic Bursts at npIX
Unpredictable Traffic Bursts at npIXUnpredictable Traffic Bursts at npIX
Unpredictable Traffic Bursts at npIX
 

Viewers also liked

How to upgrade a country?
How to upgrade a country?How to upgrade a country?
How to upgrade a country?
RIPE NCC
 
Doyenz Webinar: Disaster Prevention in the Cloud
Doyenz Webinar: Disaster Prevention in the CloudDoyenz Webinar: Disaster Prevention in the Cloud
Doyenz Webinar: Disaster Prevention in the Cloud
Doyenz, Inc.
 
SEO Disaster Prevention & Recovery
SEO Disaster Prevention & RecoverySEO Disaster Prevention & Recovery
SEO Disaster Prevention & Recovery
Allison Fabella
 
Critical Interface Design
Critical Interface DesignCritical Interface Design
Critical Interface Design
Lutz Schmitt
 
Proposed policy measures for fire prevention and mitigation
Proposed policy measures for fire prevention and mitigationProposed policy measures for fire prevention and mitigation
Proposed policy measures for fire prevention and mitigation
CIFOR-ICRAF
 
Behavior basedsafety
Behavior basedsafetyBehavior basedsafety
Behavior basedsafety
Pradeep Nair
 
Safety attitude
Safety attitudeSafety attitude
ICNP - International Classification for Nursing Practice
ICNP - International Classification for Nursing PracticeICNP - International Classification for Nursing Practice
ICNP - International Classification for Nursing Practice
Jay Martinez
 
Natural disasters reduction in thailand
Natural disasters reduction in thailandNatural disasters reduction in thailand
Natural disasters reduction in thailand
Institute of Space Knowledge Development
 
The international council of nurses and the contribution of nursing students
The international council of nurses and the contribution of nursing studentsThe international council of nurses and the contribution of nursing students
The international council of nurses and the contribution of nursing students
Tokyo Ariake University of Medical and Health Sciences
 
Aw101 - THE DIFFERENCES ROLE OF SAFETY AND HEALTH ORGANIZATION IN MALAYSIA
Aw101 - THE DIFFERENCES ROLE OF SAFETY AND HEALTH ORGANIZATION IN MALAYSIAAw101 - THE DIFFERENCES ROLE OF SAFETY AND HEALTH ORGANIZATION IN MALAYSIA
Aw101 - THE DIFFERENCES ROLE OF SAFETY AND HEALTH ORGANIZATION IN MALAYSIA
JGrace Johnny
 
24 june 2009_disaster_nursing_competencies_lite
24 june 2009_disaster_nursing_competencies_lite24 june 2009_disaster_nursing_competencies_lite
24 june 2009_disaster_nursing_competencies_lite
BP KOIRALA INSTITUTE OF HELATH SCIENCS,, NEPAL
 
Industrial Accidents
Industrial Accidents Industrial Accidents
Industrial Accidents
Hassan Ali Junejo
 
Countries, IXPs and RIPE Atlas
Countries, IXPs and RIPE AtlasCountries, IXPs and RIPE Atlas
Countries, IXPs and RIPE Atlas
RIPE NCC
 
The State of the (Danish) Internet – Interpreting RIPE NCC Data and Measurements
The State of the (Danish) Internet – Interpreting RIPE NCC Data and MeasurementsThe State of the (Danish) Internet – Interpreting RIPE NCC Data and Measurements
The State of the (Danish) Internet – Interpreting RIPE NCC Data and Measurements
RIPE NCC
 
Are Dutch Internet Paths Local - A Measurement Study Using RIPE Atlas
Are Dutch Internet Paths Local - A Measurement Study Using RIPE AtlasAre Dutch Internet Paths Local - A Measurement Study Using RIPE Atlas
Are Dutch Internet Paths Local - A Measurement Study Using RIPE Atlas
RIPE NCC
 
RIPE Atlas and RIS at France-IX
RIPE Atlas and RIS at France-IXRIPE Atlas and RIS at France-IX
RIPE Atlas and RIS at France-IX
RIPE NCC
 
RIPE Atlas and IXPs "Stitchin' it up"
RIPE Atlas and IXPs "Stitchin' it up"RIPE Atlas and IXPs "Stitchin' it up"
RIPE Atlas and IXPs "Stitchin' it up"
RIPE NCC
 
Transition of NTIA’s Stewardship of the IANA Functions
Transition of NTIA’s Stewardship of the IANA FunctionsTransition of NTIA’s Stewardship of the IANA Functions
Transition of NTIA’s Stewardship of the IANA Functions
RIPE NCC
 
Network Visualisation: Focus on RIPE Atlas
Network Visualisation: Focus on RIPE AtlasNetwork Visualisation: Focus on RIPE Atlas
Network Visualisation: Focus on RIPE Atlas
RIPE NCC
 

Viewers also liked (20)

How to upgrade a country?
How to upgrade a country?How to upgrade a country?
How to upgrade a country?
 
Doyenz Webinar: Disaster Prevention in the Cloud
Doyenz Webinar: Disaster Prevention in the CloudDoyenz Webinar: Disaster Prevention in the Cloud
Doyenz Webinar: Disaster Prevention in the Cloud
 
SEO Disaster Prevention & Recovery
SEO Disaster Prevention & RecoverySEO Disaster Prevention & Recovery
SEO Disaster Prevention & Recovery
 
Critical Interface Design
Critical Interface DesignCritical Interface Design
Critical Interface Design
 
Proposed policy measures for fire prevention and mitigation
Proposed policy measures for fire prevention and mitigationProposed policy measures for fire prevention and mitigation
Proposed policy measures for fire prevention and mitigation
 
Behavior basedsafety
Behavior basedsafetyBehavior basedsafety
Behavior basedsafety
 
Safety attitude
Safety attitudeSafety attitude
Safety attitude
 
ICNP - International Classification for Nursing Practice
ICNP - International Classification for Nursing PracticeICNP - International Classification for Nursing Practice
ICNP - International Classification for Nursing Practice
 
Natural disasters reduction in thailand
Natural disasters reduction in thailandNatural disasters reduction in thailand
Natural disasters reduction in thailand
 
The international council of nurses and the contribution of nursing students
The international council of nurses and the contribution of nursing studentsThe international council of nurses and the contribution of nursing students
The international council of nurses and the contribution of nursing students
 
Aw101 - THE DIFFERENCES ROLE OF SAFETY AND HEALTH ORGANIZATION IN MALAYSIA
Aw101 - THE DIFFERENCES ROLE OF SAFETY AND HEALTH ORGANIZATION IN MALAYSIAAw101 - THE DIFFERENCES ROLE OF SAFETY AND HEALTH ORGANIZATION IN MALAYSIA
Aw101 - THE DIFFERENCES ROLE OF SAFETY AND HEALTH ORGANIZATION IN MALAYSIA
 
24 june 2009_disaster_nursing_competencies_lite
24 june 2009_disaster_nursing_competencies_lite24 june 2009_disaster_nursing_competencies_lite
24 june 2009_disaster_nursing_competencies_lite
 
Industrial Accidents
Industrial Accidents Industrial Accidents
Industrial Accidents
 
Countries, IXPs and RIPE Atlas
Countries, IXPs and RIPE AtlasCountries, IXPs and RIPE Atlas
Countries, IXPs and RIPE Atlas
 
The State of the (Danish) Internet – Interpreting RIPE NCC Data and Measurements
The State of the (Danish) Internet – Interpreting RIPE NCC Data and MeasurementsThe State of the (Danish) Internet – Interpreting RIPE NCC Data and Measurements
The State of the (Danish) Internet – Interpreting RIPE NCC Data and Measurements
 
Are Dutch Internet Paths Local - A Measurement Study Using RIPE Atlas
Are Dutch Internet Paths Local - A Measurement Study Using RIPE AtlasAre Dutch Internet Paths Local - A Measurement Study Using RIPE Atlas
Are Dutch Internet Paths Local - A Measurement Study Using RIPE Atlas
 
RIPE Atlas and RIS at France-IX
RIPE Atlas and RIS at France-IXRIPE Atlas and RIS at France-IX
RIPE Atlas and RIS at France-IX
 
RIPE Atlas and IXPs "Stitchin' it up"
RIPE Atlas and IXPs "Stitchin' it up"RIPE Atlas and IXPs "Stitchin' it up"
RIPE Atlas and IXPs "Stitchin' it up"
 
Transition of NTIA’s Stewardship of the IANA Functions
Transition of NTIA’s Stewardship of the IANA FunctionsTransition of NTIA’s Stewardship of the IANA Functions
Transition of NTIA’s Stewardship of the IANA Functions
 
Network Visualisation: Focus on RIPE Atlas
Network Visualisation: Focus on RIPE AtlasNetwork Visualisation: Focus on RIPE Atlas
Network Visualisation: Focus on RIPE Atlas
 

Similar to DDos Prevention and Mitigation

Danish National Cyber Crime Centre - Kim Aarenstrup - how to fight cyber crime
Danish National Cyber Crime Centre - Kim Aarenstrup - how to fight cyber crimeDanish National Cyber Crime Centre - Kim Aarenstrup - how to fight cyber crime
Danish National Cyber Crime Centre - Kim Aarenstrup - how to fight cyber crime
Kevin Duffey
 
Nuix webinar presentation: See the bigger picture faster – early case assessm...
Nuix webinar presentation: See the bigger picture faster – early case assessm...Nuix webinar presentation: See the bigger picture faster – early case assessm...
Nuix webinar presentation: See the bigger picture faster – early case assessm...
Nina Ananiasvili
 
GIP-November-2016-briefing-final.ppt, Internet governance
GIP-November-2016-briefing-final.ppt, Internet governanceGIP-November-2016-briefing-final.ppt, Internet governance
GIP-November-2016-briefing-final.ppt, Internet governance
StorianJames1
 
Resilience Under Pressure: Perspectives on the Ukrainian Internet in 2022 fro...
Resilience Under Pressure: Perspectives on the Ukrainian Internet in 2022 fro...Resilience Under Pressure: Perspectives on the Ukrainian Internet in 2022 fro...
Resilience Under Pressure: Perspectives on the Ukrainian Internet in 2022 fro...
RIPE NCC
 
Insider threats: protecting data during eDiscovery (Nuix webinar)
Insider threats: protecting data during eDiscovery (Nuix webinar)Insider threats: protecting data during eDiscovery (Nuix webinar)
Insider threats: protecting data during eDiscovery (Nuix webinar)
Nina Ananiasvili
 
Toward a National Digital Network: An Update from DPLA and ESDN - Metro Annua...
Toward a National Digital Network: An Update from DPLA and ESDN - Metro Annua...Toward a National Digital Network: An Update from DPLA and ESDN - Metro Annua...
Toward a National Digital Network: An Update from DPLA and ESDN - Metro Annua...
kerriwillette
 
Ethics in Technology
Ethics in TechnologyEthics in Technology
Ethics in Technology
RIPE NCC
 
Ed Rios - New ncc brief
Ed Rios - New ncc briefEd Rios - New ncc brief
Ed Rios - New ncc brief
Trish McGinity, CCSK
 
APT or not - does it make a difference if you are compromised?
APT or not - does it make a difference if you are compromised?APT or not - does it make a difference if you are compromised?
APT or not - does it make a difference if you are compromised?
Thomas Malmberg
 
Working Collaboratively to Share and Analyse Data to Prevent, Detect and Dete...
Working Collaboratively to Share and Analyse Data to Prevent, Detect and Dete...Working Collaboratively to Share and Analyse Data to Prevent, Detect and Dete...
Working Collaboratively to Share and Analyse Data to Prevent, Detect and Dete...
Govnet Events
 
ODC BarCamp 2013 - Introduction to Data Journalism
ODC BarCamp 2013 - Introduction to Data JournalismODC BarCamp 2013 - Introduction to Data Journalism
ODC BarCamp 2013 - Introduction to Data Journalism
Open Development Cambodia
 
Ken Czekaj & Robert Wright - Leveraging APM NPM Solutions to Compliment Cyber...
Ken Czekaj & Robert Wright - Leveraging APM NPM Solutions to Compliment Cyber...Ken Czekaj & Robert Wright - Leveraging APM NPM Solutions to Compliment Cyber...
Ken Czekaj & Robert Wright - Leveraging APM NPM Solutions to Compliment Cyber...
centralohioissa
 
Jisc and janet network updates from network operations, operational services ...
Jisc and janet network updates from network operations, operational services ...Jisc and janet network updates from network operations, operational services ...
Jisc and janet network updates from network operations, operational services ...
Jisc
 
The digital strategy of the youngest territory in France (2016)
The digital strategy of the youngest territory in France (2016)The digital strategy of the youngest territory in France (2016)
The digital strategy of the youngest territory in France (2016)
Carole Stromboni
 
ADEQUATe and CommuniData
ADEQUATe and CommuniDataADEQUATe and CommuniData
ADEQUATe and CommuniData
Stadt Wien
 
Balancing global and local needs - Hanna Karppi
Balancing global and local needs - Hanna KarppiBalancing global and local needs - Hanna Karppi
Balancing global and local needs - Hanna Karppi
Intranet Now
 
CiNPA / CiNPA Security SIG History
CiNPA / CiNPA Security SIG HistoryCiNPA / CiNPA Security SIG History
CiNPA / CiNPA Security SIG History
ThreatReel Podcast
 
Introduction to Streaming Analytics
Introduction to Streaming AnalyticsIntroduction to Streaming Analytics
Introduction to Streaming Analytics
Guido Schmutz
 
Janet network DDoS experiences - Networkshop44
Janet network DDoS experiences - Networkshop44Janet network DDoS experiences - Networkshop44
Janet network DDoS experiences - Networkshop44
Jisc
 
Importance of data
Importance of dataImportance of data
Importance of data
Jay Daley
 

Similar to DDos Prevention and Mitigation (20)

Danish National Cyber Crime Centre - Kim Aarenstrup - how to fight cyber crime
Danish National Cyber Crime Centre - Kim Aarenstrup - how to fight cyber crimeDanish National Cyber Crime Centre - Kim Aarenstrup - how to fight cyber crime
Danish National Cyber Crime Centre - Kim Aarenstrup - how to fight cyber crime
 
Nuix webinar presentation: See the bigger picture faster – early case assessm...
Nuix webinar presentation: See the bigger picture faster – early case assessm...Nuix webinar presentation: See the bigger picture faster – early case assessm...
Nuix webinar presentation: See the bigger picture faster – early case assessm...
 
GIP-November-2016-briefing-final.ppt, Internet governance
GIP-November-2016-briefing-final.ppt, Internet governanceGIP-November-2016-briefing-final.ppt, Internet governance
GIP-November-2016-briefing-final.ppt, Internet governance
 
Resilience Under Pressure: Perspectives on the Ukrainian Internet in 2022 fro...
Resilience Under Pressure: Perspectives on the Ukrainian Internet in 2022 fro...Resilience Under Pressure: Perspectives on the Ukrainian Internet in 2022 fro...
Resilience Under Pressure: Perspectives on the Ukrainian Internet in 2022 fro...
 
Insider threats: protecting data during eDiscovery (Nuix webinar)
Insider threats: protecting data during eDiscovery (Nuix webinar)Insider threats: protecting data during eDiscovery (Nuix webinar)
Insider threats: protecting data during eDiscovery (Nuix webinar)
 
Toward a National Digital Network: An Update from DPLA and ESDN - Metro Annua...
Toward a National Digital Network: An Update from DPLA and ESDN - Metro Annua...Toward a National Digital Network: An Update from DPLA and ESDN - Metro Annua...
Toward a National Digital Network: An Update from DPLA and ESDN - Metro Annua...
 
Ethics in Technology
Ethics in TechnologyEthics in Technology
Ethics in Technology
 
Ed Rios - New ncc brief
Ed Rios - New ncc briefEd Rios - New ncc brief
Ed Rios - New ncc brief
 
APT or not - does it make a difference if you are compromised?
APT or not - does it make a difference if you are compromised?APT or not - does it make a difference if you are compromised?
APT or not - does it make a difference if you are compromised?
 
Working Collaboratively to Share and Analyse Data to Prevent, Detect and Dete...
Working Collaboratively to Share and Analyse Data to Prevent, Detect and Dete...Working Collaboratively to Share and Analyse Data to Prevent, Detect and Dete...
Working Collaboratively to Share and Analyse Data to Prevent, Detect and Dete...
 
ODC BarCamp 2013 - Introduction to Data Journalism
ODC BarCamp 2013 - Introduction to Data JournalismODC BarCamp 2013 - Introduction to Data Journalism
ODC BarCamp 2013 - Introduction to Data Journalism
 
Ken Czekaj & Robert Wright - Leveraging APM NPM Solutions to Compliment Cyber...
Ken Czekaj & Robert Wright - Leveraging APM NPM Solutions to Compliment Cyber...Ken Czekaj & Robert Wright - Leveraging APM NPM Solutions to Compliment Cyber...
Ken Czekaj & Robert Wright - Leveraging APM NPM Solutions to Compliment Cyber...
 
Jisc and janet network updates from network operations, operational services ...
Jisc and janet network updates from network operations, operational services ...Jisc and janet network updates from network operations, operational services ...
Jisc and janet network updates from network operations, operational services ...
 
The digital strategy of the youngest territory in France (2016)
The digital strategy of the youngest territory in France (2016)The digital strategy of the youngest territory in France (2016)
The digital strategy of the youngest territory in France (2016)
 
ADEQUATe and CommuniData
ADEQUATe and CommuniDataADEQUATe and CommuniData
ADEQUATe and CommuniData
 
Balancing global and local needs - Hanna Karppi
Balancing global and local needs - Hanna KarppiBalancing global and local needs - Hanna Karppi
Balancing global and local needs - Hanna Karppi
 
CiNPA / CiNPA Security SIG History
CiNPA / CiNPA Security SIG HistoryCiNPA / CiNPA Security SIG History
CiNPA / CiNPA Security SIG History
 
Introduction to Streaming Analytics
Introduction to Streaming AnalyticsIntroduction to Streaming Analytics
Introduction to Streaming Analytics
 
Janet network DDoS experiences - Networkshop44
Janet network DDoS experiences - Networkshop44Janet network DDoS experiences - Networkshop44
Janet network DDoS experiences - Networkshop44
 
Importance of data
Importance of dataImportance of data
Importance of data
 

More from RIPE NCC

Know Your Network: Why every network operator should host a RIPE Atlas probe
Know Your Network: Why every network operator should host a RIPE Atlas probeKnow Your Network: Why every network operator should host a RIPE Atlas probe
Know Your Network: Why every network operator should host a RIPE Atlas probe
RIPE NCC
 
Know Your Network; why every network operator should host a RIPE Atlas probe
Know Your Network; why every network operator should host a RIPE Atlas probeKnow Your Network; why every network operator should host a RIPE Atlas probe
Know Your Network; why every network operator should host a RIPE Atlas probe
RIPE NCC
 
Taiwan's Digital Landscape with RIPE NCC Tools
Taiwan's Digital Landscape with RIPE NCC ToolsTaiwan's Digital Landscape with RIPE NCC Tools
Taiwan's Digital Landscape with RIPE NCC Tools
RIPE NCC
 
Navigating IP Addresses: Insights from your Regional Internet Registry
Navigating IP Addresses: Insights from your Regional Internet RegistryNavigating IP Addresses: Insights from your Regional Internet Registry
Navigating IP Addresses: Insights from your Regional Internet Registry
RIPE NCC
 
Traces of Power: Internet Governance and Climate Action
Traces of Power: Internet Governance and Climate ActionTraces of Power: Internet Governance and Climate Action
Traces of Power: Internet Governance and Climate Action
RIPE NCC
 
Governing Environmental Sustainability in Tech
Governing Environmental Sustainability in TechGoverning Environmental Sustainability in Tech
Governing Environmental Sustainability in Tech
RIPE NCC
 
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdf
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdfGerardo-Viviers-RPKI-presentation-DKNOG14.pdf
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdf
RIPE NCC
 
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RISLIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS
RIPE NCC
 
Intro to RIPE and RIPE NCC: RIPE Atlas workshop
Intro to RIPE and RIPE NCC: RIPE Atlas workshopIntro to RIPE and RIPE NCC: RIPE Atlas workshop
Intro to RIPE and RIPE NCC: RIPE Atlas workshop
RIPE NCC
 
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdfIGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
RIPE NCC
 
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdfOpportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
RIPE NCC
 
RIPE NCC Internet Measurement Tools
RIPE NCC Internet Measurement ToolsRIPE NCC Internet Measurement Tools
RIPE NCC Internet Measurement Tools
RIPE NCC
 
IPv6 in Central Europe and the Baltics
IPv6 in Central Europe and the BalticsIPv6 in Central Europe and the Baltics
IPv6 in Central Europe and the Baltics
RIPE NCC
 
RPKI For Routing Security
RPKI For Routing SecurityRPKI For Routing Security
RPKI For Routing Security
RIPE NCC
 
SEEDIG 8 - Alena Muravska RIPE NCC.pdf
SEEDIG 8 - Alena Muravska RIPE NCC.pdfSEEDIG 8 - Alena Muravska RIPE NCC.pdf
SEEDIG 8 - Alena Muravska RIPE NCC.pdf
RIPE NCC
 
Know Your Network: Why Every Network Operator Should Host RIPE Atlas
Know Your Network: Why Every Network Operator Should Host RIPE AtlasKnow Your Network: Why Every Network Operator Should Host RIPE Atlas
Know Your Network: Why Every Network Operator Should Host RIPE Atlas
RIPE NCC
 
Minimising Impact When Incidents Occur With RIPE Atlas
Minimising Impact When Incidents Occur With RIPE AtlasMinimising Impact When Incidents Occur With RIPE Atlas
Minimising Impact When Incidents Occur With RIPE Atlas
RIPE NCC
 
RIPE NCC Internet Measurement Services
RIPE NCC Internet Measurement ServicesRIPE NCC Internet Measurement Services
RIPE NCC Internet Measurement Services
RIPE NCC
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE Atlas
RIPE NCC
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE Atlas
RIPE NCC
 

More from RIPE NCC (20)

Know Your Network: Why every network operator should host a RIPE Atlas probe
Know Your Network: Why every network operator should host a RIPE Atlas probeKnow Your Network: Why every network operator should host a RIPE Atlas probe
Know Your Network: Why every network operator should host a RIPE Atlas probe
 
Know Your Network; why every network operator should host a RIPE Atlas probe
Know Your Network; why every network operator should host a RIPE Atlas probeKnow Your Network; why every network operator should host a RIPE Atlas probe
Know Your Network; why every network operator should host a RIPE Atlas probe
 
Taiwan's Digital Landscape with RIPE NCC Tools
Taiwan's Digital Landscape with RIPE NCC ToolsTaiwan's Digital Landscape with RIPE NCC Tools
Taiwan's Digital Landscape with RIPE NCC Tools
 
Navigating IP Addresses: Insights from your Regional Internet Registry
Navigating IP Addresses: Insights from your Regional Internet RegistryNavigating IP Addresses: Insights from your Regional Internet Registry
Navigating IP Addresses: Insights from your Regional Internet Registry
 
Traces of Power: Internet Governance and Climate Action
Traces of Power: Internet Governance and Climate ActionTraces of Power: Internet Governance and Climate Action
Traces of Power: Internet Governance and Climate Action
 
Governing Environmental Sustainability in Tech
Governing Environmental Sustainability in TechGoverning Environmental Sustainability in Tech
Governing Environmental Sustainability in Tech
 
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdf
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdfGerardo-Viviers-RPKI-presentation-DKNOG14.pdf
Gerardo-Viviers-RPKI-presentation-DKNOG14.pdf
 
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RISLIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS
LIA HESTINA - Minimising impact before incidents occur with RIPE Atlas and RIS
 
Intro to RIPE and RIPE NCC: RIPE Atlas workshop
Intro to RIPE and RIPE NCC: RIPE Atlas workshopIntro to RIPE and RIPE NCC: RIPE Atlas workshop
Intro to RIPE and RIPE NCC: RIPE Atlas workshop
 
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdfIGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
IGF UA - Dialog with I_ organisations - Alena Muavska RIPE NCC.pdf
 
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdfOpportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
Opportunities for Youth in IG - Alena Muravska RIPE NCC.pdf
 
RIPE NCC Internet Measurement Tools
RIPE NCC Internet Measurement ToolsRIPE NCC Internet Measurement Tools
RIPE NCC Internet Measurement Tools
 
IPv6 in Central Europe and the Baltics
IPv6 in Central Europe and the BalticsIPv6 in Central Europe and the Baltics
IPv6 in Central Europe and the Baltics
 
RPKI For Routing Security
RPKI For Routing SecurityRPKI For Routing Security
RPKI For Routing Security
 
SEEDIG 8 - Alena Muravska RIPE NCC.pdf
SEEDIG 8 - Alena Muravska RIPE NCC.pdfSEEDIG 8 - Alena Muravska RIPE NCC.pdf
SEEDIG 8 - Alena Muravska RIPE NCC.pdf
 
Know Your Network: Why Every Network Operator Should Host RIPE Atlas
Know Your Network: Why Every Network Operator Should Host RIPE AtlasKnow Your Network: Why Every Network Operator Should Host RIPE Atlas
Know Your Network: Why Every Network Operator Should Host RIPE Atlas
 
Minimising Impact When Incidents Occur With RIPE Atlas
Minimising Impact When Incidents Occur With RIPE AtlasMinimising Impact When Incidents Occur With RIPE Atlas
Minimising Impact When Incidents Occur With RIPE Atlas
 
RIPE NCC Internet Measurement Services
RIPE NCC Internet Measurement ServicesRIPE NCC Internet Measurement Services
RIPE NCC Internet Measurement Services
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE Atlas
 
Spotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE AtlasSpotting Latency Issues with RIPE Atlas
Spotting Latency Issues with RIPE Atlas
 

Recently uploaded

Freshworks Rethinks NoSQL for Rapid Scaling & Cost-Efficiency
Freshworks Rethinks NoSQL for Rapid Scaling & Cost-EfficiencyFreshworks Rethinks NoSQL for Rapid Scaling & Cost-Efficiency
Freshworks Rethinks NoSQL for Rapid Scaling & Cost-Efficiency
ScyllaDB
 
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
Jason Yip
 
What is an RPA CoE? Session 1 – CoE Vision
What is an RPA CoE?  Session 1 – CoE VisionWhat is an RPA CoE?  Session 1 – CoE Vision
What is an RPA CoE? Session 1 – CoE Vision
DianaGray10
 
A Deep Dive into ScyllaDB's Architecture
A Deep Dive into ScyllaDB's ArchitectureA Deep Dive into ScyllaDB's Architecture
A Deep Dive into ScyllaDB's Architecture
ScyllaDB
 
Demystifying Knowledge Management through Storytelling
Demystifying Knowledge Management through StorytellingDemystifying Knowledge Management through Storytelling
Demystifying Knowledge Management through Storytelling
Enterprise Knowledge
 
Skybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoptionSkybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoption
Tatiana Kojar
 
“Temporal Event Neural Networks: A More Efficient Alternative to the Transfor...
“Temporal Event Neural Networks: A More Efficient Alternative to the Transfor...“Temporal Event Neural Networks: A More Efficient Alternative to the Transfor...
“Temporal Event Neural Networks: A More Efficient Alternative to the Transfor...
Edge AI and Vision Alliance
 
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
saastr
 
The Microsoft 365 Migration Tutorial For Beginner.pptx
The Microsoft 365 Migration Tutorial For Beginner.pptxThe Microsoft 365 Migration Tutorial For Beginner.pptx
The Microsoft 365 Migration Tutorial For Beginner.pptx
operationspcvita
 
Monitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdfMonitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdf
Tosin Akinosho
 
AppSec PNW: Android and iOS Application Security with MobSF
AppSec PNW: Android and iOS Application Security with MobSFAppSec PNW: Android and iOS Application Security with MobSF
AppSec PNW: Android and iOS Application Security with MobSF
Ajin Abraham
 
Leveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and StandardsLeveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and Standards
Neo4j
 
Biomedical Knowledge Graphs for Data Scientists and Bioinformaticians
Biomedical Knowledge Graphs for Data Scientists and BioinformaticiansBiomedical Knowledge Graphs for Data Scientists and Bioinformaticians
Biomedical Knowledge Graphs for Data Scientists and Bioinformaticians
Neo4j
 
GNSS spoofing via SDR (Criptored Talks 2024)
GNSS spoofing via SDR (Criptored Talks 2024)GNSS spoofing via SDR (Criptored Talks 2024)
GNSS spoofing via SDR (Criptored Talks 2024)
Javier Junquera
 
Main news related to the CCS TSI 2023 (2023/1695)
Main news related to the CCS TSI 2023 (2023/1695)Main news related to the CCS TSI 2023 (2023/1695)
Main news related to the CCS TSI 2023 (2023/1695)
Jakub Marek
 
Mutation Testing for Task-Oriented Chatbots
Mutation Testing for Task-Oriented ChatbotsMutation Testing for Task-Oriented Chatbots
Mutation Testing for Task-Oriented Chatbots
Pablo Gómez Abajo
 
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Pitangent Analytics & Technology Solutions Pvt. Ltd
 
"$10 thousand per minute of downtime: architecture, queues, streaming and fin...
"$10 thousand per minute of downtime: architecture, queues, streaming and fin..."$10 thousand per minute of downtime: architecture, queues, streaming and fin...
"$10 thousand per minute of downtime: architecture, queues, streaming and fin...
Fwdays
 
Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |
AstuteBusiness
 
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectorsConnector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
DianaGray10
 

Recently uploaded (20)

Freshworks Rethinks NoSQL for Rapid Scaling & Cost-Efficiency
Freshworks Rethinks NoSQL for Rapid Scaling & Cost-EfficiencyFreshworks Rethinks NoSQL for Rapid Scaling & Cost-Efficiency
Freshworks Rethinks NoSQL for Rapid Scaling & Cost-Efficiency
 
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
[OReilly Superstream] Occupy the Space: A grassroots guide to engineering (an...
 
What is an RPA CoE? Session 1 – CoE Vision
What is an RPA CoE?  Session 1 – CoE VisionWhat is an RPA CoE?  Session 1 – CoE Vision
What is an RPA CoE? Session 1 – CoE Vision
 
A Deep Dive into ScyllaDB's Architecture
A Deep Dive into ScyllaDB's ArchitectureA Deep Dive into ScyllaDB's Architecture
A Deep Dive into ScyllaDB's Architecture
 
Demystifying Knowledge Management through Storytelling
Demystifying Knowledge Management through StorytellingDemystifying Knowledge Management through Storytelling
Demystifying Knowledge Management through Storytelling
 
Skybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoptionSkybuffer SAM4U tool for SAP license adoption
Skybuffer SAM4U tool for SAP license adoption
 
“Temporal Event Neural Networks: A More Efficient Alternative to the Transfor...
“Temporal Event Neural Networks: A More Efficient Alternative to the Transfor...“Temporal Event Neural Networks: A More Efficient Alternative to the Transfor...
“Temporal Event Neural Networks: A More Efficient Alternative to the Transfor...
 
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
Overcoming the PLG Trap: Lessons from Canva's Head of Sales & Head of EMEA Da...
 
The Microsoft 365 Migration Tutorial For Beginner.pptx
The Microsoft 365 Migration Tutorial For Beginner.pptxThe Microsoft 365 Migration Tutorial For Beginner.pptx
The Microsoft 365 Migration Tutorial For Beginner.pptx
 
Monitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdfMonitoring and Managing Anomaly Detection on OpenShift.pdf
Monitoring and Managing Anomaly Detection on OpenShift.pdf
 
AppSec PNW: Android and iOS Application Security with MobSF
AppSec PNW: Android and iOS Application Security with MobSFAppSec PNW: Android and iOS Application Security with MobSF
AppSec PNW: Android and iOS Application Security with MobSF
 
Leveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and StandardsLeveraging the Graph for Clinical Trials and Standards
Leveraging the Graph for Clinical Trials and Standards
 
Biomedical Knowledge Graphs for Data Scientists and Bioinformaticians
Biomedical Knowledge Graphs for Data Scientists and BioinformaticiansBiomedical Knowledge Graphs for Data Scientists and Bioinformaticians
Biomedical Knowledge Graphs for Data Scientists and Bioinformaticians
 
GNSS spoofing via SDR (Criptored Talks 2024)
GNSS spoofing via SDR (Criptored Talks 2024)GNSS spoofing via SDR (Criptored Talks 2024)
GNSS spoofing via SDR (Criptored Talks 2024)
 
Main news related to the CCS TSI 2023 (2023/1695)
Main news related to the CCS TSI 2023 (2023/1695)Main news related to the CCS TSI 2023 (2023/1695)
Main news related to the CCS TSI 2023 (2023/1695)
 
Mutation Testing for Task-Oriented Chatbots
Mutation Testing for Task-Oriented ChatbotsMutation Testing for Task-Oriented Chatbots
Mutation Testing for Task-Oriented Chatbots
 
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
Crafting Excellence: A Comprehensive Guide to iOS Mobile App Development Serv...
 
"$10 thousand per minute of downtime: architecture, queues, streaming and fin...
"$10 thousand per minute of downtime: architecture, queues, streaming and fin..."$10 thousand per minute of downtime: architecture, queues, streaming and fin...
"$10 thousand per minute of downtime: architecture, queues, streaming and fin...
 
Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |Astute Business Solutions | Oracle Cloud Partner |
Astute Business Solutions | Oracle Cloud Partner |
 
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectorsConnector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
Connector Corner: Seamlessly power UiPath Apps, GenAI with prebuilt connectors
 

DDos Prevention and Mitigation

  • 1. Christian Teuschel | November 2016 | Skopje DDos Prevention and Mitigation
  • 2. Christian Teuschel | Skopje | November 2016 2 Friday, 21 October 2016 http://downdetector.com/ http://dyn.com/blog/dyn-statement-on-10212016-ddos-attack/
  • 3. Christian Teuschel | Skopje | November 2016 3 Denial-Of-Service 101 • What? - Attack on IT infrastructure - Make machine/network resource unavailable - Temporary or indefinite - Not a new invention!
  • 4. Christian Teuschel | Skopje | November 2016 4 Denial-Of-Service 101 • How? - Crashing service - Flooding service • Effect - Prevent legitimate users to be serviced
  • 5. Christian Teuschel | Skopje | November 2016 5 Denial-Of-Service 101 • Targets: - Usually high-profile sites - But not only • Initiators - Hackers - Script kids - Criminals - State actor - Insider
  • 6. Christian Teuschel | Skopje | November 2016 6 Denial-Of-Service 101 • Costs - Mitigation costs - Lost revenue - Reputation
  • 7. Christian Teuschel | Skopje | November 2016 7 Special Forms Of DOS • Distributed DOS - Involving multiple devices in the attack • APDOS - Involving an advanced persistent thread - Requires resources and sophistication • DOS as a service - Entry barrier is getting lower - Growing market Focus http://www.trendmicro.com/cloud-content/us/pdfs/security-intelligence/white-papers/wp-russian-underground-101.pdf
  • 8. Christian Teuschel | Skopje | November 2016 8 DDoS Attack Classes • TCP Connection Attack - Intention to use up available connections • Volumetric Attack - Intention to cause congestions • Fragmentation Attack - Intention to overwhelm request handling • Application Attack - Intention to exploit specific aspects of an application
  • 9. Christian Teuschel | Skopje | November 2016 9 DDoS Amplification • DNS Reflection - Small request, big response • Chargen Reflection - Streams of random characters on demand
  • 10. Christian Teuschel | Skopje | November 2016 10 Statistics on DDos http://www.digitalattackmap.com/ State of the Internet Security Report by Akamai
  • 11. Christian Teuschel | Skopje | November 2016 11 Statistics on DDos State of the Internet Security Report by Akamai
  • 12. Christian Teuschel | Skopje | November 2016 12 DDos Prevention • Keep your software up-to-date • Know your network and services - Make inventory on a regular basis - Monitor • Don’t make enemies and avoid becoming a target
  • 13. Christian Teuschel | Skopje | November 2016 13 DDos Prevention • Recommendations by the Dutch government - Make an overview and monitor your infrastructure - Check with each of your third-party suppliers to find out which (D)DoS countermeasures are in place and what the relevant contractual agreements are - Find out which countermeasures have been taken to protect your in-house infrastructure and take additional steps, if necessary - Prepare your incident response and think about failover scenarios for your online services - Prepare a communication strategy
  • 14. Christian Teuschel | Skopje | November 2016 14 DDos Prevention • Ingress filtering (BCP38) • RPKI • BGPSEC
  • 15. Christian Teuschel | Skopje | November 2016 15 DDos Mitigation • Detection!!! - You need to be able to detect an attack - Popular service vs. attack
  • 16. Christian Teuschel | Skopje | November 2016 16 DDos Mitigation • BGP blackholing
  • 17. Christian Teuschel | Skopje | November 2016 17 DDos Mitigation • Traffic Scrubbing - Services like NaWas https://www.neustar.biz/resources/product-literature/siteprotect-ddos-mitigation-failover-service
  • 18. Christian Teuschel | Skopje | November 2016 18 DDos Mitigation • Spread the word and inform the right people - Abuse-c - National CERTs - Affected companies
  • 19. Christian Teuschel | Skopje | November 2016 19 DDos Mitigation • Spread it even further • Working Group mailing list - Routing WG - Anti-Abuse WG • NOG/National lists - NANOG - NLNOG, DENOG, PLNOG, SWINOG, etc. - MKNOG?