Re: DDoS protection
"Hartley, Christopher J." <[email protected]> Fri, 20 Jun 2014 14:47:50 +0000
| Newsgroups | gmane.comp.security.basics |
|---|---|
| Message-ID | <[email protected]> |
This is a little confusing; =93cloud=94, =93on-premise=94 etc=85 weird. By =93Cloud,=94 it seem like we mean =93by provider=94 (makes sense). On-premise is the best way to detect an attack imo, since the victim networ= k knows what=92s good and what=92s not (or should=85.). So I think the best solution involves some kind of remote blackhole or idea= lly, perhaps flowspec. I don=92t think it=92s a problem that requires spending significant money. Chris On Jun 19, 2014, at 12:50 PM, Kellstr <[email protected]> wrote: > Disclaimer: I work for a company which offers a DDoS Protection Service. >=20 > The advantage of a service "in the cloud" is that if an attack exceeds > your circuit bandwidth the provider will be able to drop the malicious > traffic. That cannot be done at your premise. Both Arbor and Radware > offer strong appliances that can clean up smaller attacks at your > premise and can send a signal to the provider if they support that > service. You can block traffic using IPS's but keep in mind they are > not designed for a volumetric attack and may be overwhelmed. >=20 > On Wed, Jun 18, 2014 at 11:10 AM, Lance Lassetter > <[email protected]> wrote: >> What about Suricata or Snort IDS in IPS mode? >>=20 >> On Jun 18, 2014 8:43 AM, "Mikhail A. Utin" <[email protected]> = wrote: >>>=20 >>> As you indicated " Although we're small, We're an organization playing = with ($,=A5,=80,=A3) exchanges" you are on client side rather than on serve= r. If that is right, you do not need to bother with DDoS protection, which = is against server side. >>> Mikhail >>>=20 >>> -----Original Message----- >>> From: [email protected] [mailto:[email protected]= ] On Behalf Of [email protected] >>> Sent: Wednesday, June 18, 2014 12:49 AM >>> To: [email protected] >>> Subject: Re: Re: DDoS protection >>>=20 >>> Hi, >>>=20 >>> Thanks for your replies. >>>=20 >>> Noted the points raised by Jacint and Kelly Keeton. I appreciate that. >>>=20 >>> May I be kind to seek an opinion/ arguments suggesting if the In-house = appliances are more "intelligent" thwarting the application level DOS/ DDoS= attacks as compared to ISP provided DOS protection wherein it may even fai= l to detect them. or if there are other benefits owning an In-house product= ? >>>=20 >>> As far as Cons are concerned, I feel that the appliance may add some la= tency which may create issues wherein a latency of milliseconds count. >>>=20 >>> Although we're small, We're an organization playing with ($,=A5,=80,=A3= ) exchanges and heavily regulated by the Government. >>>=20 >>> Thanks, >>> KT >>>=20 >>> -----------------------------------------------------------------------= - >>> Securing Apache Web Server with thawte Digital Certificate In this guid= e we examine the importance of Apache-SSL and who needs an SSL certificate.= We look at how SSL works, how it benefits your company and how your custo= mers can tell if a site is secure. You will find out how to test, purchase,= install and use a thawte Digital Certificate on your Apache web server. Th= roughout, best practices for set-up are highlighted to help you ensure effi= cient ongoing management of your encryption keys and digital certificates. >>>=20 >>> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be44= 2f727d1 >>> -----------------------------------------------------------------------= - >>>=20 >>>=20 >>> CONFIDENTIALITY NOTICE: This email communication and any attachments ma= y contain confidential >>> and privileged information for the use of the designated recipients nam= ed above. If you are >>> not the intended recipient, you are hereby notified that you have recei= ved this communication >>> in error and that any review, disclosure, dissemination, distribution o= r copying of it or its >>> contents is prohibited. If you have received this communication in erro= r, please reply to the >>> sender immediately or by telephone at (617) 426-0600 and destroy all co= pies of this communication >>> and any attachments. For further information regarding Commonwealth Car= e Alliance's privacy policy, >>> please visit our Internet web site at http://www.commonwealthcare.org. >>>=20 >=20 >=20 >=20 > --=20 > Laws alone cannot secure freedom of expression; in order that every > man present his views without penalty there must be spirit of > tolerance in the entire population. - Albert Einstein >=20 > ------------------------------------------------------------------------ > Securing Apache Web Server with thawte Digital Certificate > In this guide we examine the importance of Apache-SSL and who needs an SS= L certificate. We look at how SSL works, how it benefits your company and = how your customers can tell if a site is secure. You will find out how to t= est, purchase, install and use a thawte Digital Certificate on your Apache = web server. Throughout, best practices for set-up are highlighted to help y= ou ensure efficient ongoing management of your encryption keys and digital = certificates. >=20 > http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f= 727d1 > ------------------------------------------------------------------------ >=20 >=20 ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------