RE: DDoS protection

"Marios Stylianou" <[email protected]> Wed, 25 Jun 2014 13:56:40 +0300
Newsgroups gmane.comp.security.basics
Message-ID <[email protected]>
You can try Incapsula services.


Mindbets


-----Original Message-----
From: [email protected] [mailto:[email protected]] =
On Behalf Of Mikhail A. Utin
Sent: Monday, June 23, 2014 7:02 PM
To: Sardina, Dominick; [email protected]
Subject: RE: DDoS protection

Hello,
Yes, all has been known for a while. I got two presentations discussing =
partially "cloud" matter at OWASP AppSec DC 2012 and DeepSec 2012 and =
2013.
You can check both for presentations or ask me personally.
Basically, all "clouds" are simply application hosting web sites. And =
technically a "cloud" is a datacenter. Whether such app is a virtual =
network or Mom&Dad Pizza shop HTML site does not matter.
So named "cloud computing concept" has nothing in common with computing, =
and not a concept at all. Models are useless and in such case as =
"Community Cloud" and "Hybrid Cloud" is legal nonsense, simply because a =
service provider cannot have legal binding relationship (aka a contract) =
with a community, which is not a legal entity.
I tried to dig out where "cloud" came from. It is an invention of IBM =
circle companies hosting site reselling IBM services. And in essence is =
the replacement of Google and next IBM funded academic cluster project =
"Academia Cluster Computing Initiative" or ACCI, see: Let a Thousand =
servers bloom =E2=80=93 Google official post, Posted by Christophe =
Bisciglia, October 8, 2007 =
http://googleblog.blogspot.com/2007/10/let-thousand-servers-bloom.html
IBM circle guys replaced "cluster" with "cloud" and renamed ACCI as =
"Academia Cloud Computing Initiative". Bingo! Next they needed something =
looking like science in a form of "models".
However, guys violated Google intellectual property rights on the =
original ACCI project name.

Regards

Mikhail



-----Original Message-----
From: [email protected] [mailto:[email protected]] =
On Behalf Of Sardina, Dominick
Sent: Friday, June 20, 2014 2:49 PM
To: [email protected]
Subject: RE: DDoS protection

Brett, I have to agree 100%.


Regards,
Dominick=20


-----Original Message-----
From: [email protected] [mailto:[email protected]] =
On Behalf Of Wagner, Brett
Sent: Friday, June 20, 2014 12:57 PM
To: Hartley, Christopher J.; Kellstr
Cc: [email protected]
Subject: RE: DDoS protection

IMHO - I am not a fan of all the mumbo jumbo that goes along with the =
"Cloud" like it is a new invention. I worked at GTE/BBN in 1999 and we =
were selling all the same crap back then. With that said and having =
worked at EMC for a while you can have a "Cloud" on premises just means =
you have the hardware in one of your company locations. You can have =
private, shared, public or a combo.=20

It is the same evolution as IT security circa 1970-80s (Rainbow Book =
Series days), then Information Security circa 1990s, then Information =
Assurance circa late 90s early 2000s and now Cyber Security. With each =
name change consultants and companies can charge more for the same =
ultimate goal with each name change.

OK I will now get off my soapbox.
-----Original Message-----
From: [email protected] [mailto:[email protected]] =
On Behalf Of Hartley, Christopher J.
Sent: Friday, June 20, 2014 10:48 AM
To: Kellstr
Cc: [email protected]
Subject: Re: DDoS protection

This is a little confusing; =E2=80=9Ccloud=E2=80=9D, =
=E2=80=9Con-premise=E2=80=9D etc=E2=80=A6 weird.

By =E2=80=9CCloud,=E2=80=9D it seem like we mean =E2=80=9Cby =
provider=E2=80=9D (makes sense).

On-premise is the best way to detect an attack imo, since the victim =
network knows what=E2=80=99s good and what=E2=80=99s not (or =
should=E2=80=A6.).

So I think the best solution involves some kind of remote blackhole or =
ideally, perhaps flowspec.

I don=E2=80=99t think it=E2=80=99s a problem that requires spending =
significant money.

Chris

On Jun 19, 2014, at 12:50 PM, Kellstr <[email protected]> wrote:

> Disclaimer: I work for a company which offers a DDoS Protection =
Service.
>=20
> The advantage of a service "in the cloud" is that if an attack exceeds =

> your circuit bandwidth the provider will be able to drop the malicious =

> traffic. That cannot be done at your premise. Both Arbor and Radware=20
> offer strong appliances that can clean up smaller attacks at your=20
> premise and can send a signal to the provider if they support that=20
> service. You can block traffic using IPS's but keep in mind they are=20
> not designed for a volumetric attack and may be overwhelmed.
>=20
> On Wed, Jun 18, 2014 at 11:10 AM, Lance Lassetter=20
> <[email protected]> wrote:
>> What about Suricata or Snort IDS in IPS mode?
>>=20
>> On Jun 18, 2014 8:43 AM, "Mikhail A. Utin" =
<[email protected]> wrote:
>>>=20
>>> As you indicated " Although we're small, We're an organization =
playing with ($,=C2=A5,=E2=82=AC,=C2=A3) exchanges" you are on client =
side rather than on server. If that is right, you do not need to bother =
with DDoS protection, which is against server side.
>>> Mikhail
>>>=20
>>> -----Original Message-----
>>> From: [email protected]
>>> [mailto:[email protected]] On Behalf Of=20
>>> [email protected]
>>> Sent: Wednesday, June 18, 2014 12:49 AM
>>> To: [email protected]
>>> Subject: Re: Re: DDoS protection
>>>=20
>>> Hi,
>>>=20
>>> Thanks for your replies.
>>>=20
>>> Noted the points raised by Jacint and Kelly Keeton. I appreciate =
that.
>>>=20
>>> May I be kind to seek an opinion/ arguments suggesting if the =
In-house appliances are more "intelligent" thwarting the application =
level DOS/ DDoS attacks as compared to ISP provided DOS protection =
wherein it may even fail to detect them. or if there are other benefits =
owning an In-house product?
>>>=20
>>> As far as Cons are concerned, I feel that the appliance may add some =
latency which may create issues wherein a latency of milliseconds count.
>>>=20
>>> Although we're small, We're an organization playing with =
($,=C2=A5,=E2=82=AC,=C2=A3) exchanges and heavily regulated by the =
Government.
>>>=20
>>> Thanks,
>>> KT
>>>=20
>>> --------------------------------------------------------------------
>>> ---- Securing Apache Web Server with thawte Digital Certificate In=20
>>> this guide we examine the importance of Apache-SSL and who needs an =
SSL certificate.  We look at how SSL works, how it benefits your company =
and how your customers can tell if a site is secure. You will find out =
how to test, purchase, install and use a thawte Digital Certificate on =
your Apache web server. Throughout, best practices for set-up are =
highlighted to help you ensure efficient ongoing management of your =
encryption keys and digital certificates.
>>>=20
>>> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6b
>>> e442f727d1
>>> --------------------------------------------------------------------
>>> ----
>>>=20
>>>=20
>>> CONFIDENTIALITY NOTICE: This email communication and any attachments =

>>> may contain confidential and privileged information for the use of=20
>>> the designated recipients named above. If you are not the intended=20
>>> recipient, you are hereby notified that you have received this=20
>>> communication in error and that any review, disclosure,=20
>>> dissemination, distribution or copying of it or its contents is=20
>>> prohibited. If you have received this communication in error, please =

>>> reply to the sender immediately or by telephone at (617) 426-0600 =
and destroy all copies of this communication and any attachments. For =
further information regarding Commonwealth Care Alliance's privacy =
policy, please visit our Internet web site at =
http://www.commonwealthcare.org.
>>>=20
>=20
>=20
>=20
> --
> Laws alone cannot secure freedom of expression; in order that every=20
> man present his views without penalty there must be spirit of=20
> tolerance in the entire population. - Albert Einstein
>=20
> ----------------------------------------------------------------------
> -- Securing Apache Web Server with thawte Digital Certificate In this=20
> guide we examine the importance of Apache-SSL and who needs an SSL =
certificate.  We look at how SSL works, how it benefits your company and =
how your customers can tell if a site is secure. You will find out how =
to test, purchase, install and use a thawte Digital Certificate on your =
Apache web server. Throughout, best practices for set-up are highlighted =
to help you ensure efficient ongoing management of your encryption keys =
and digital certificates.
>=20
> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4
> 42f727d1
> ----------------------------------------------------------------------
> --
>=20
>=20



------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate In this guide =
we examine the importance of Apache-SSL and who needs an SSL =
certificate.  We look at how SSL works, how it benefits your company and =
how your customers can tell if a site is secure. You will find out how =
to test, purchase, install and use a thawte Digital Certificate on your =
Apache web server. Throughout, best practices for set-up are highlighted =
to help you ensure efficient ongoing management of your encryption keys =
and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f=
727d1
------------------------------------------------------------------------



-----------------------------------------
The information contained in this e-mail, including any attachment(s), =
is intended solely for use by the named addressee(s).  If you are not =
the intended recipient, or a person designated as responsible for =
delivering such messages to the intended recipient, you are not =
authorized to disclose, copy, distribute or retain this message, in =
whole or in part, without written authorization from PSEG.  This e-mail =
may contain proprietary, confidential or privileged information. If you =
have received this message in error, please notify the sender =
immediately. This notice is included in all e-mail messages leaving =
PSEG.  Thank you for your cooperation.

CONFIDENTIALITY NOTICE: This email communication and any attachments may =
contain confidential and privileged information for the use of the =
designated recipients named above. If you are not the intended =
recipient, you are hereby notified that you have received this =
communication in error and that any review, disclosure, dissemination, =
distribution or copying of it or its contents is prohibited. If you have =
received this communication in error, please reply to the sender =
immediately or by telephone at (617) 426-0600 and destroy all copies of =
this communication and any attachments. For further information =
regarding Commonwealth Care Alliance's privacy policy, please visit our =
Internet web site at http://www.commonwealthcare.org.



------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------