snoc Snoc DDoS Protection Fast Secure Cost effective Introduction Snoc 3.0 Global Scrubbing Centers Web Application DNS Protection

Similar documents
Comprehensive DDoS Attack Protection: Cloud-based, Enterprise Grade Mitigation F5 Silverline

A10 DDOS PROTECTION CLOUD

WEB DDOS PROTECTION APPLICATION PROTECTION VIA DNS FORWARDING

Imperva Incapsula Product Overview

Comprehensive datacenter protection

Enterprise Overview. Benefits and features of Cloudflare s Enterprise plan FLARE

NETWORK DDOS PROTECTION STANDBY OR PERMANENT INFRASTRUCTURE PROTECTION VIA BGP ROUTING

Silverline DDoS Protection. Filip Verlaeckt

CLOUD-BASED DDOS PROTECTION FOR HOSTING PROVIDERS

ERT Threat Alert New Risks Revealed by Mirai Botnet November 2, 2016

2nd SIG-NOC meeting and DDoS Mitigation Workshop Scrubbing Away DDOS Attacks. 9 th November 2015

Cloudflare Advanced DDoS Protection

DNS SECURITY BENEFITS OF OUTSOURCING YOUR DNS TO AN IP ANYCAST+ PROVIDER

EFFECTIVE SERVICE PROVIDER DDOS PROTECTION THAT SAVES DOLLARS AND MAKES SENSE

Arbor Solution Brief Arbor Cloud for Enterprises

August 14th, 2018 PRESENTED BY:

INTRODUCTION: DDOS ATTACKS GLOBAL THREAT INTELLIGENCE REPORT 2015 :: COPYRIGHT 2015 NTT INNOVATION INSTITUTE 1 LLC

DDoS Detection&Mitigation: Radware Solution

TOP TEN DNS ATTACKS PROTECTING YOUR ORGANIZATION AGAINST TODAY S FAST-GROWING THREATS

Insight Guide into Securing your Connectivity

haltdos - Web Application Firewall

Radware Attack Mitigation Solution (AMS) Protect Online Businesses and Data Centers Against Emerging Application & Network Threats - Whitepaper

Radware s Attack Mitigation Solution Protect Online Businesses and Data Centers Against Emerging Application & Network Threats - Whitepaper

Secure your Web Applications with AWS WAF & AWS Shield. James Chiang ( 蔣宗恩 ) AWS Solution Architect

DDoS attack patterns across the APJ cloud market. Samuel Chen CCIE#9607 Enterprise Security Architect, Manager - APJ

VERISIGN DISTRIBUTED DENIAL OF SERVICE TRENDS REPORT

Think You re Safe from DDoS Attacks? As an AWS customer, you probably need more protection. Discover the vulnerabilities and how Neustar can help.

What s next for your data center? Power Your Evolution with Physical and Virtual ADCs. Jeppe Koefoed Wim Zandee Field sales, Nordics

HOW TO HANDLE A RANSOM- DRIVEN DDOS ATTACK

Practical Guide to Choosing a DDoS Mitigation Service WHITEPAPER

Advanced Techniques for DDoS Mitigation and Web Application Defense

AKAMAI SOLUTION BROCHURE CLOUD SECURITY SOLUTIONS FAST RELIABLE SECURE.

Herding Cats. Carl Brothers, F5 Field Systems Engineer

Advanced Attack Response and Mitigation

Radware DefensePro DDoS Mitigation Release Notes Software Version Last Updated: December, 2017

雲服務比你想像更安全? 陳建宏 Akamai 大中華區資安業務總監

A GUIDE TO DDoS PROTECTION

Imma Chargin Mah Lazer

Inline DDoS Protection versus Scrubbing Center Solutions. Solution Brief

VERISIGN DISTRIBUTED DENIAL OF SERVICE TRENDS REPORT

The Interactive Guide to Protecting Your Election Website

Cloud DNS. High Performance under any traffic conditions from anywhere in the world. Reliable. Performance

Safeguard Your Internet Presence with Sophisticated DDoS Mitigation.

Fighting the Shadows: How to Stop Real-world Cybersecurity Application Threats That You Can t See

DNS SECURITY BEST PRACTICES

Prolexic Attack Report Q4 2011

THE UTILITY OF DNS TRAFFIC MANAGEMENT

Arbor White Paper Keeping the Lights On

Denial of Service Protection Standardize Defense or Loose the War

Additional Security Services on AWS

WHITE PAPER Hybrid Approach to DDoS Mitigation

Asset Discovery with Symantec Control Compliance Suite WHITE PAPER

Distributed Denial of Service (DDoS)

WHITE PAPER. DDoS of Things SURVIVAL GUIDE. Proven DDoS Defense in the New Era of 1 Tbps Attacks

Vulnerability Management & Vulnerability Assessment. Nessus Attack Scripting Language (NASL). CVE databases, NVD database

Technical White Paper June 2016

DDoS Managed Security Services Playbook

Downtime by DDoS: Taking an Integrated Multi-Layered Approach. Arbor Solution Brief

Are You Fully Prepared to Withstand DNS Attacks?

Imperva Incapsula Website Security

Internet2 DDoS Mitigation Update

DDoS Protection in Backbone Networks

A custom excerpt from Frost & Sullivan s Global DDoS Mitigation Market Research Report (NDD2-72) July, 2014 NDD2-74

Distributed Denial of Service (DDoS)

AKAMAI CLOUD SECURITY SOLUTIONS

Cybersecurity. Anna Chan, Marketing Director, Akamai Technologies

Thunder TPS. Overview. A10 Networks, Inc.

FortiDDoS Deployment Guide for Cloud Signaling with Verisign OpenHybrid

Check Point DDoS Protector Simple and Easy Mitigation

VERISIGN DISTRIBUTED DENIAL OF SERVICE TRENDS REPORT

CSE 565 Computer Security Fall 2018

(DNS, and DNSSEC and DDOS) Geoff Huston APNIC

Incapsula Guide to Selecting a DDoS Solution WHITE PAPER

ddos-guard.net Protecting your business DDoS-GUARD: Distributed protection against distributed attacks

VERISIGN DISTRIBUTED DENIAL OF SERVICE TRENDS REPORT

Chapter 7. Denial of Service Attacks

Chapter 10: Denial-of-Services

Protect vital DNS assets and identify malware

THE PIONEER IN REAL-TIME CYBER SITUATIONAL AWARENESS

DDOS RESILIENCY SCORE (DRS) "An open standard for quantifying an Organization's resiliency to withstand DDoS attacks" Version July

Security Whitepaper. DNS Resource Exhaustion

The IBM Platform Computing HPC Cloud Service. Solution Overview

DENIAL OF SERVICE ATTACKS

Beyond Blind Defense: Gaining Insights from Proactive App Sec

VERISIGN DISTRIBUTED DENIAL OF SERVICE TRENDS REPORT

PROTECTING INFORMATION ASSETS NETWORK SECURITY

Check Point DDoS Protector Introduction

Clean Pipe Solution 2.0

DDoS Protector. Simon Yu Senior Security Consultant. Block Denial of Service attacks within seconds CISSP-ISSAP, MBCS, CEH

86% of websites has at least 1 vulnerability and an average of 56 per website WhiteHat Security Statistics Report 2013

F5 DDoS Hybrid Defender : Setup. Version

Sucuri Technical Overview

Fregata. DDoS Mitigation Solution. Technical Specifications & Datasheet 1G-5G

Threat Pragmatics. Target 6/19/ June 2018 PacNOG 22, Honiara, Solomon Islands Supported by:

Cisco Firepower with Radware DDoS Mitigation

Estrategias de mitigación de amenazas a las aplicaciones bancarias. Carlos Valencia Sales Engineer - LATAM

Enterprise D/DoS Mitigation Solution offering

Anti-DDoS. FAQs. Issue 11 Date HUAWEI TECHNOLOGIES CO., LTD.

Imperva Incapsula DDoS Protection

Cyber War Chronicles Stories from the Virtual Trenches

Transcription:

Snoc DDoS Protection Fast Secure Cost effective sales@.co.th www..co.th securenoc Introduction Snoc 3.0 Snoc DDoS Protection provides organizations with comprehensive protection against the most challenging Distributed Denial-of-Service (DDoS) attacks, protecting their brand, customers and earning potential. Snoc s globally distributed cloud infrastructure prevents downtime on network assets, protects critical applications and ensures availability for domain resolution. Web Application Protection Origin Protection DNS Protection Global Scrubbing Centers Globally distributed scrubbing centers located in San Jose, Los Angeles, Miami, Ashburn, London, Amsterdam, Hong Kong, Taiwan, Singapore and Thailand. LONDON AMSTERDAM SAN JOSE LOS ANGELES ASHBURN MIAMI TAIWAN HONG KONG THAILAND SINGAPORE

Introduction Snoc 3.0 Largest Global Footprint Global Scrubbing Centers Total Active Mitigation Capacity Security Response Center Coverage 10 1.44Tb 24x7 World - Class Reliability Proprietary Mitigation Technology Flexible Solutions for Complex Applications, Networks and DNS Advanced Detection & Analytics Real-time Monitoring - Live Attack Mitigation Map & Threat Analytic - Real User Experience & Services Monitoring - Attack Source Tracking & Uptime Monitoring Snoc s Cybersecurity Platform, which encompasses Web Application Protection (AP), Origin Protection (OP), and DNS Protection (DNSP). The three pillars work with and complement each other to provide comprehensive protection on websites, applications, backend infrastructure, and DNS servers from the latest threats, without software and hardware. Visibility - Customer Portal Designed with ease of use in mind, the Customer Portal boasts a comprehensive dashboard and controls, through which you can easily track network traffic, monitor current attacks, review event logs and monthly report. 24x7 NOC Staffed with DDoS Experts Solely relying on automated filtering tools and large bandwidth for DDoS mitigation is not enough. Snoc has a 24x7x365 staffed with security experts to monitor and respond to attacks and threats around the clock while providing seamless support to you and your end-customers. Their experiences, skills and availability are essential part of our comprehensive mitigation mechanism, all being combined can flexibly and timely respond to the changing techniques used by attackers. Sales Support: (+66) 2690 3999 sales@.co.th NOC Support 24x7: (+66) 2639 7999 noc@.co.th www..co.th

Introduction Snoc 3.0 Business Benefit from this Service 1. To Mitigate Service Downtime : You will get high availability with prevent high mitigation capacity for very high network traffic volume and sophisticated attacks. 2. To reduces CAPEX by Pay-As-You-Grow : You can starting the service with-out investment and we will help you saving of network and security equipment capacity that would be required to process unwanted traffic. 3. To Reduced OPEX by Ease of Security Management : Worry free and let s Snoc to manage security with prevent cyber-attacks. 4. To Reduced Total Cost of Ownership (TCO) of Security Management : We re readiness to serve you for prevent cyber-attacks and we re have security management team and we invests for you. Awards and Mentions DSS COMPLIANT Sales Support: (+66) 2690 3999 sales@.co.th NOC Support 24x7: (+66) 2639 7999 noc@.co.th www..co.th

Snoc DDoS Protection Fast Secure Cost effective Web Protection Service (AP) sales@.co.th www..co.th securenoc Web Protection Service (AP) Web Application Protection (AP) is designed to deliver a perfect balance of protection and performance for public-facing websites and applications utilizing a multi-layered mitigation platform, which features various proprietary and patented technologies, security best practices and a 24x7x365 Security Operations Center (SOC) to detect, mitigate and analyze attack traffic. How AP Works During normal, peacetime operations, protected applications are served from the edge of provider s network, and content is securely cached and passed along to the origin server. The AP solution leverages TCP Anycast, assigning each of protected business resources a secure Anycast Virtual IP (VIP) address and providing high-performance global accessibility. Technology at a Glance Volumetric DDoS Mitigation Web Application Firewall Application DDoS Mitigation Caching and Load Balancing

Web Protection Service (AP) Web Application Protection Diagram Valid Visitor Request TCP SYN Flood TCP Spoofing SSL Attack HTTP Get Flood Botnet Attack XSS Slow Rate Attack SQL Injection Response to Valid User! DANGER Reflection User Agent Spoofing Ping Flood High Orbit Ion Canon UDP Flood Tier 1 Border Filtering Clean Traffic Customer Cached Data Performance Layer Response Tier 2 Protocol Verification Tier 3 Application Filtering DDoS PROTECTION Customer Network Located Anywhere Internet Snoc Scrubbing Center 1.44 Tbps [10 Data Center] San Jose, Los Angeles, Miami, Ashburn, London, Amsterdam, Hong Kong, Taiwan, Singapore and Thailand. Sales Support: (+66) 2690 3999 sales@.co.th NOC Support 24x7: (+66) 2639 7999 noc@.co.th www..co.th

Snoc DDoS Protection Fast Secure Cost effective Origin Protection (Clean Pipe Service) sales@.co.th www..co.th securenoc Origin Protection (Clean Pipe Service) Snoc s Origin Protection covers all elements of a customer s network, e.g. internal websites, email servers, FTP servers, and other applications, against all volumetric and protocol-based DDoS attacks, such as UDP, SMTP or SYN floods. All incoming traffic is routed through all the scrubbing centers using BGP announcements and only clean traffic will be routed through secure GRE tunnels back to customer s servers. How OP works Using BGP announcements, all incoming traffic is routed through all the scrubbing centers, collectively equipped with over 1.44 Tbps of mitigation capacity. Only clean traffic is routed through a secure Generic Routing Encapsulation (GRE) tunnel back to your customers servers. Snoc advertises all protected IP range announcements on your behalf. INTERNET DDoS PROTECTION via GRE/MPLS Enterprise: ASN65000 99.99.99.0/24 99.99.100.0/24

Origin Protection (Clean Pipe Service) Highlight Features OP Protect Entire Backend Infrastructure Protect entire backend infrastructure, e.g. internal websites, email servers, FTP servers, DNS and all other applications Multi-layered Mitigation System Multi-layered mitigation system blocks known bad source IPs outright, filters out bad traffic (spoofed IPs, botnets, etc.), and let legitimate traffic in. Protection Down to Single IP Address Customizable mitigation profile on network level and host level Built-in GRE Tunnel and BGP Routing Capability simplifies network setup and configuration management Remote DDoS Monitoring and Traffic Analysis Detects attacks through flows collected from customers without the need to swing traffic; defines alert triggering thresholds based on different network protocols, TCP, UDP, ICMP, and IP Sales Support: (+66) 2690 3999 sales@.co.th NOC Support 24x7: (+66) 2639 7999 noc@.co.th www..co.th

Snoc DDoS Protection Fast Secure Cost effective DNS Protection Service sales@.co.th www..co.th securenoc DNS Protection Service Snoc s DNS Protection protects mission-critical online services from all DNS attacks. The solution leverages Snoc s globally distributed scrubbing centers to resolve incoming DNS queries quickly and reliably. How DNSP Works In a typical recursive DNS query, a client requests the resolution of a domain name or the reverse resolution of an IP address on a local DNS server. The DNS server performs the queries on behalf of the client and returns a response packet with the correct information or an error message. The specification does not allow for unsolicited responses. In a DNS amplification attack, the main indicator is a query response without a matching request. Residing in front of a customer s infrastructure, Snoc DNS Protection Service replaces the DNS server by directly fetching zone records from the customer s servers and caching them in our globally distributed scrubbing centers. The client first has to change the name servers for the domain and point the domain name to Snoc s name servers, which can be accomplished at Snoc s Self-service Customer Portal. As the destination for all incoming queries, Snoc s cloud-based DNS caches absorb all DNS attacks, while filtering out malicious traffic from incoming queries. Your DNS servers never need to respond to any malicious DNS query Snoc handles everything. Our service protects against direct attacks on DNS services, and abuses of server vulnerabilities as a leverage to launch DNS amplification attacks on other servers.

DNS Protection Service Highlight Feature DNSP DNS Server Cache Snooping Loophole Closed Snoc does not cache any DNS records while acting as the authoritative DNS servers on behalf of its clients, so that attackers cannot snoop specific DNS records to reveal sensitive information. Dynamic Update Security Threats Eliminated Dynamic updates are not permitted and so there is no such dynamic update threat. Fingerprinting Tools Blocked Fingerprinting tools such as fpdns, Nmap, and Nessus are unable to identify any information about the software or operating systems our clients are using. Full Control by End-Customers End-customers have full control over the DNSP service and configuration through the Customer Portal, reducing the partner s workload in ongoing operations. Sales Support: (+66) 2690 3999 sales@.co.th NOC Support 24x7: (+66) 2639 7999 noc@.co.th www..co.th