RE: DDoS protection

Jácint TÓTH <[email protected]> Mon, 16 Jun 2014 14:15:36 +0200
Newsgroups gmane.comp.security.basics
Message-ID <[email protected]>
Hi,

The answer to the first question is "it depends". At bandwidths that Your I=
SP can easily handle, the answer is probably no, their equipment is better =
placed and probably of a higher grade, so it is better to handle the DDoS p=
rotection there, and just put some "of sound mind" sort of things on Your e=
nd to handle small-scale stuff that may no even trigger detection threshold=
s at the ISP.

Now on the other hand, if you are in a large hosted environment like a serv=
er hotel hooked up directly to an Internet Exchange, or are handling huge a=
mounts of traffic in a datacenter, maybe even function as a traffic concent=
rator for a larger MAN/WAN/GAN, then it does make sense to have an own solu=
tion for the purpose of DDoS protection and maybe firewalling integrated wi=
th it. At 10G and higher traffic links and/or several 100s of thousands of =
RPS on NORMAL traffic, You would probably want to know exactly what You are=
 working with, what's happening to it, and eliminate the delays with having=
 an external entity manage the service.

Cost-wise, You have to measure cost vs. potential risk and loss of income i=
f You don't have these, and this calculation will almost always happen to b=
ring You into the 6-digit range in a year at least (USD), as there are sign=
ificant costs associated with procuring/implementing/operating/supporting s=
uch devices. So if you are far beneath that range budget-wise or traffic-wi=
se, don't bother, go with the managed service of the ISP.

As for the second question, at first thought there is A10 Networks who have=
 several appliances up to N*40Gb bandwidth for both dedicated DDoS protecti=
on and integrated into an application firewall/load balancer, and Cisco's G=
uard XT series is also an option if You are playing in this league. Ctrix's=
 Netscalers are balancers /ALGs that can help You with DDoS-protection for =
certain protocols, but these are not really dedicated security devices.=20

If you just want to go for "something", or build something small-scale, the=
n You coul do some testing with say Aache mod_security on an OpenBSD or Fre=
eBSD with pf, these are working fine on a small scale and are cheap to buil=
d and maintain, but You'll probably end up managing them Yourself and bear =
in mind, community support is nothing compared to what a large vendor will =
provide.=20

Cheers,
--
Jacint


-----Original Message-----
From: [email protected] [mailto:[email protected]] On=
 Behalf Of [email protected]
Sent: Monday, June 16, 2014 10:17 AM
To: [email protected]
Subject: DDoS protection

Hi,

My question is about the DDoS protection appliances. Is it really worth spe=
nding $$$$$ buying a DDoS appliance if we already had DDoS subscription fro=
m the ISPs?

And apart from Arbor and Fortinet, do we have any other big player in this =
technology?

PS: we are not evaluating cloud based DDoS protection.

Please advise.

Thanks,
KT

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate In this guide we=
 examine the importance of Apache-SSL and who needs an SSL certificate.  We=
 look at how SSL works, how it benefits your company and how your customers=
 can tell if a site is secure. You will find out how to test, purchase, ins=
tall and use a thawte Digital Certificate on your Apache web server. Throug=
hout, best practices for set-up are highlighted to help you ensure efficien=
t ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f72=
7d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------