RE: DDoS protection

"Sable, Amol" <[email protected]> Mon, 16 Jun 2014 08:18:40 -0500
Newsgroups gmane.comp.security.basics
Message-ID <1F87439ECCA4B54DADC9DE89122FDD07089F88B74F@PHXCCRPRD03.adprod.bmc.com>
Hi Kartik,

Greetings!

DDS vs IPS (for DoS protection aspect only)

The following capabilities are essential as part of any DoS Defense solutio=
n. I'm trying to add my comments for IPS in the same area.=20

1. Detect and mitigate rate-based and protocol attacks
	--> Hard to comment on ability of IPS boxes here. I feel, DDS are more foc=
used on the problem than IPS

2. Resistant to known evasion techniques
	--> Based on my observation, IPS vendors are continually improving on dete=
cting attacks combining evasion techniques

3. Be highly resilient and stable  and provide legitimate access to protect=
ed resources while under DDoS attack
	-->IPS boxes undergo rigorous stress testing these days

4. Ability to operate at layer 3
	--> An IPS monitors traffic at Layer 3 and Layer 4 to ensure that their he=
aders, states, and so on are those specified in the protocol suite. However=
, the IPS sensor analyzes at Layer 2 to Layer 7 the payload of the packets =
for more sophisticated embedded attacks that might include malicious data. =
This deeper analysis lets the IPS identify, stop, and block attacks that wo=
uld normally pass through a traditional firewall devices, even DDS devices

If anti DDoS solutions are really solving the purpose needs to be evaluated=
. May be some benchmark reports will help. Some vendors are providing such =
reports for both - IPS appliances as well as DDS devices. That would be a g=
ood starting point.

I'd not buy DDS unless it is an absolute necessity and there are no budget =
constraints.

The question is really good. Let's see what other's views are.=20

Regards,
Amol

-----Original Message-----
From: [email protected] [mailto:[email protected]] On=
 Behalf Of [email protected]
Sent: 16 June 2014 13:47
To: [email protected]
Subject: DDoS protection

Hi,

My question is about the DDoS protection appliances. Is it really worth spe=
nding $$$$$ buying a DDoS appliance if we already had DDoS subscription fro=
m the ISPs?

And apart from Arbor and Fortinet, do we have any other big player in this =
technology?

PS: we are not evaluating cloud based DDoS protection.

Please advise.

Thanks,
KT

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate In this guide we=
 examine the importance of Apache-SSL and who needs an SSL certificate.  We=
 look at how SSL works, how it benefits your company and how your customers=
 can tell if a site is secure. You will find out how to test, purchase, ins=
tall and use a thawte Digital Certificate on your Apache web server. Throug=
hout, best practices for set-up are highlighted to help you ensure efficien=
t ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f72=
7d1
------------------------------------------------------------------------


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------