Re: DDoS protection

"Hartley, Christopher J." <[email protected]> Fri, 20 Jun 2014 14:47:50 +0000
Newsgroups gmane.comp.security.basics
Message-ID <[email protected]>
This is a little confusing; =93cloud=94, =93on-premise=94 etc=85 weird.

By =93Cloud,=94 it seem like we mean =93by provider=94 (makes sense).

On-premise is the best way to detect an attack imo, since the victim networ=
k knows what=92s good and what=92s not (or should=85.).

So I think the best solution involves some kind of remote blackhole or idea=
lly, perhaps flowspec.

I don=92t think it=92s a problem that requires spending significant money.

Chris

On Jun 19, 2014, at 12:50 PM, Kellstr <[email protected]> wrote:

> Disclaimer: I work for a company which offers a DDoS Protection Service.
>=20
> The advantage of a service "in the cloud" is that if an attack exceeds
> your circuit bandwidth the provider will be able to drop the malicious
> traffic. That cannot be done at your premise. Both Arbor and Radware
> offer strong appliances that can clean up smaller attacks at your
> premise and can send a signal to the provider if they support that
> service. You can block traffic using IPS's but keep in mind they are
> not designed for a volumetric attack and may be overwhelmed.
>=20
> On Wed, Jun 18, 2014 at 11:10 AM, Lance Lassetter
> <[email protected]> wrote:
>> What about Suricata or Snort IDS in IPS mode?
>>=20
>> On Jun 18, 2014 8:43 AM, "Mikhail A. Utin" <[email protected]> =
wrote:
>>>=20
>>> As you indicated " Although we're small, We're an organization playing =
with ($,=A5,=80,=A3) exchanges" you are on client side rather than on serve=
r. If that is right, you do not need to bother with DDoS protection, which =
is against server side.
>>> Mikhail
>>>=20
>>> -----Original Message-----
>>> From: [email protected] [mailto:[email protected]=
] On Behalf Of [email protected]
>>> Sent: Wednesday, June 18, 2014 12:49 AM
>>> To: [email protected]
>>> Subject: Re: Re: DDoS protection
>>>=20
>>> Hi,
>>>=20
>>> Thanks for your replies.
>>>=20
>>> Noted the points raised by Jacint and Kelly Keeton. I appreciate that.
>>>=20
>>> May I be kind to seek an opinion/ arguments suggesting if the In-house =
appliances are more "intelligent" thwarting the application level DOS/ DDoS=
 attacks as compared to ISP provided DOS protection wherein it may even fai=
l to detect them. or if there are other benefits owning an In-house product=
?
>>>=20
>>> As far as Cons are concerned, I feel that the appliance may add some la=
tency which may create issues wherein a latency of milliseconds count.
>>>=20
>>> Although we're small, We're an organization playing with ($,=A5,=80,=A3=
) exchanges and heavily regulated by the Government.
>>>=20
>>> Thanks,
>>> KT
>>>=20
>>> -----------------------------------------------------------------------=
-
>>> Securing Apache Web Server with thawte Digital Certificate In this guid=
e we examine the importance of Apache-SSL and who needs an SSL certificate.=
  We look at how SSL works, how it benefits your company and how your custo=
mers can tell if a site is secure. You will find out how to test, purchase,=
 install and use a thawte Digital Certificate on your Apache web server. Th=
roughout, best practices for set-up are highlighted to help you ensure effi=
cient ongoing management of your encryption keys and digital certificates.
>>>=20
>>> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be44=
2f727d1
>>> -----------------------------------------------------------------------=
-
>>>=20
>>>=20
>>> CONFIDENTIALITY NOTICE: This email communication and any attachments ma=
y contain confidential
>>> and privileged information for the use of the designated recipients nam=
ed above. If you are
>>> not the intended recipient, you are hereby notified that you have recei=
ved this communication
>>> in error and that any review, disclosure, dissemination, distribution o=
r copying of it or its
>>> contents is prohibited. If you have received this communication in erro=
r, please reply to the
>>> sender immediately or by telephone at (617) 426-0600 and destroy all co=
pies of this communication
>>> and any attachments. For further information regarding Commonwealth Car=
e Alliance's privacy policy,
>>> please visit our Internet web site at http://www.commonwealthcare.org.
>>>=20
>=20
>=20
>=20
> --=20
> Laws alone cannot secure freedom of expression; in order that every
> man present his views without penalty there must be spirit of
> tolerance in the entire population. - Albert Einstein
>=20
> ------------------------------------------------------------------------
> Securing Apache Web Server with thawte Digital Certificate
> In this guide we examine the importance of Apache-SSL and who needs an SS=
L certificate.  We look at how SSL works, how it benefits your company and =
how your customers can tell if a site is secure. You will find out how to t=
est, purchase, install and use a thawte Digital Certificate on your Apache =
web server. Throughout, best practices for set-up are highlighted to help y=
ou ensure efficient ongoing management of your encryption keys and digital =
certificates.
>=20
> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f=
727d1
> ------------------------------------------------------------------------
>=20
>=20



------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------