Re: DDoS protection

Comp Pycho <[email protected]> Wed, 25 Jun 2014 08:52:25 -0400
Newsgroups gmane.comp.security.basics
Message-ID <[email protected]>
Cloud computing is an IBM concept that was blow up by NIST. NIST pushed this=
 "Cloud" BS for external parties to make money. The cloud is nothing but a d=
ata center. The secure clouds are data centers which have gone through the Fe=
dRamp certification program for security compliance.=20

Do what you know
-Dame Dash


> On Jun 25, 2014, at 6:56 AM, "Marios Stylianou" <[email protected]> w=
rote:
>=20
> You can try Incapsula services.
>=20
>=20
> Mindbets
>=20
>=20
> -----Original Message-----
> From: [email protected] [mailto:[email protected]] O=
n Behalf Of Mikhail A. Utin
> Sent: Monday, June 23, 2014 7:02 PM
> To: Sardina, Dominick; [email protected]
> Subject: RE: DDoS protection
>=20
> Hello,
> Yes, all has been known for a while. I got two presentations discussing pa=
rtially "cloud" matter at OWASP AppSec DC 2012 and DeepSec 2012 and 2013.
> You can check both for presentations or ask me personally.
> Basically, all "clouds" are simply application hosting web sites. And tech=
nically a "cloud" is a datacenter. Whether such app is a virtual network or M=
om&Dad Pizza shop HTML site does not matter.
> So named "cloud computing concept" has nothing in common with computing, a=
nd not a concept at all. Models are useless and in such case as "Community C=
loud" and "Hybrid Cloud" is legal nonsense, simply because a service provide=
r cannot have legal binding relationship (aka a contract) with a community, w=
hich is not a legal entity.
> I tried to dig out where "cloud" came from. It is an invention of IBM circ=
le companies hosting site reselling IBM services. And in essence is the repl=
acement of Google and next IBM funded academic cluster project "Academia Clu=
ster Computing Initiative" or ACCI, see: Let a Thousand servers bloom =E2=80=
=93 Google official post, Posted by Christophe Bisciglia, October 8, 2007 ht=
tp://googleblog.blogspot.com/2007/10/let-thousand-servers-bloom.html
> IBM circle guys replaced "cluster" with "cloud" and renamed ACCI as "Acade=
mia Cloud Computing Initiative". Bingo! Next they needed something looking l=
ike science in a form of "models".
> However, guys violated Google intellectual property rights on the original=
 ACCI project name.
>=20
> Regards
>=20
> Mikhail
>=20
>=20
>=20
> -----Original Message-----
> From: [email protected] [mailto:[email protected]] O=
n Behalf Of Sardina, Dominick
> Sent: Friday, June 20, 2014 2:49 PM
> To: [email protected]
> Subject: RE: DDoS protection
>=20
> Brett, I have to agree 100%.
>=20
>=20
> Regards,
> Dominick=20
>=20
>=20
> -----Original Message-----
> From: [email protected] [mailto:[email protected]] O=
n Behalf Of Wagner, Brett
> Sent: Friday, June 20, 2014 12:57 PM
> To: Hartley, Christopher J.; Kellstr
> Cc: [email protected]
> Subject: RE: DDoS protection
>=20
> IMHO - I am not a fan of all the mumbo jumbo that goes along with the "Clo=
ud" like it is a new invention. I worked at GTE/BBN in 1999 and we were sell=
ing all the same crap back then. With that said and having worked at EMC for=
 a while you can have a "Cloud" on premises just means you have the hardware=
 in one of your company locations. You can have private, shared, public or a=
 combo.=20
>=20
> It is the same evolution as IT security circa 1970-80s (Rainbow Book Serie=
s days), then Information Security circa 1990s, then Information Assurance c=
irca late 90s early 2000s and now Cyber Security. With each name change cons=
ultants and companies can charge more for the same ultimate goal with each n=
ame change.
>=20
> OK I will now get off my soapbox.
> -----Original Message-----
> From: [email protected] [mailto:[email protected]] O=
n Behalf Of Hartley, Christopher J.
> Sent: Friday, June 20, 2014 10:48 AM
> To: Kellstr
> Cc: [email protected]
> Subject: Re: DDoS protection
>=20
> This is a little confusing; =E2=80=9Ccloud=E2=80=9D, =E2=80=9Con-premise=E2=
=80=9D etc=E2=80=A6 weird.
>=20
> By =E2=80=9CCloud,=E2=80=9D it seem like we mean =E2=80=9Cby provider=E2=80=
=9D (makes sense).
>=20
> On-premise is the best way to detect an attack imo, since the victim netwo=
rk knows what=E2=80=99s good and what=E2=80=99s not (or should=E2=80=A6.).
>=20
> So I think the best solution involves some kind of remote blackhole or ide=
ally, perhaps flowspec.
>=20
> I don=E2=80=99t think it=E2=80=99s a problem that requires spending signif=
icant money.
>=20
> Chris
>=20
>> On Jun 19, 2014, at 12:50 PM, Kellstr <[email protected]> wrote:
>>=20
>> Disclaimer: I work for a company which offers a DDoS Protection Service.
>>=20
>> The advantage of a service "in the cloud" is that if an attack exceeds=20=

>> your circuit bandwidth the provider will be able to drop the malicious=20=

>> traffic. That cannot be done at your premise. Both Arbor and Radware=20
>> offer strong appliances that can clean up smaller attacks at your=20
>> premise and can send a signal to the provider if they support that=20
>> service. You can block traffic using IPS's but keep in mind they are=20
>> not designed for a volumetric attack and may be overwhelmed.
>>=20
>> On Wed, Jun 18, 2014 at 11:10 AM, Lance Lassetter=20
>> <[email protected]> wrote:
>>> What about Suricata or Snort IDS in IPS mode?
>>>=20
>>>> On Jun 18, 2014 8:43 AM, "Mikhail A. Utin" <[email protected]>=
 wrote:
>>>>=20
>>>> As you indicated " Although we're small, We're an organization playing w=
ith ($,=C2=A5,=E2=82=AC,=C2=A3) exchanges" you are on client side rather tha=
n on server. If that is right, you do not need to bother with DDoS protectio=
n, which is against server side.
>>>> Mikhail
>>>>=20
>>>> -----Original Message-----
>>>> From: [email protected]
>>>> [mailto:[email protected]] On Behalf Of=20
>>>> [email protected]
>>>> Sent: Wednesday, June 18, 2014 12:49 AM
>>>> To: [email protected]
>>>> Subject: Re: Re: DDoS protection
>>>>=20
>>>> Hi,
>>>>=20
>>>> Thanks for your replies.
>>>>=20
>>>> Noted the points raised by Jacint and Kelly Keeton. I appreciate that.
>>>>=20
>>>> May I be kind to seek an opinion/ arguments suggesting if the In-house a=
ppliances are more "intelligent" thwarting the application level DOS/ DDoS a=
ttacks as compared to ISP provided DOS protection wherein it may even fail t=
o detect them. or if there are other benefits owning an In-house product?
>>>>=20
>>>> As far as Cons are concerned, I feel that the appliance may add some la=
tency which may create issues wherein a latency of milliseconds count.
>>>>=20
>>>> Although we're small, We're an organization playing with ($,=C2=A5,=E2=82=
=AC,=C2=A3) exchanges and heavily regulated by the Government.
>>>>=20
>>>> Thanks,
>>>> KT
>>>>=20
>>>> --------------------------------------------------------------------
>>>> ---- Securing Apache Web Server with thawte Digital Certificate In=20
>>>> this guide we examine the importance of Apache-SSL and who needs an SSL=
 certificate.  We look at how SSL works, how it benefits your company and ho=
w your customers can tell if a site is secure. You will find out how to test=
, purchase, install and use a thawte Digital Certificate on your Apache web s=
erver. Throughout, best practices for set-up are highlighted to help you ens=
ure efficient ongoing management of your encryption keys and digital certifi=
cates.
>>>>=20
>>>> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6b
>>>> e442f727d1
>>>> --------------------------------------------------------------------
>>>> ----
>>>>=20
>>>>=20
>>>> CONFIDENTIALITY NOTICE: This email communication and any attachments=20=

>>>> may contain confidential and privileged information for the use of=20
>>>> the designated recipients named above. If you are not the intended=20
>>>> recipient, you are hereby notified that you have received this=20
>>>> communication in error and that any review, disclosure,=20
>>>> dissemination, distribution or copying of it or its contents is=20
>>>> prohibited. If you have received this communication in error, please=20=

>>>> reply to the sender immediately or by telephone at (617) 426-0600 and d=
estroy all copies of this communication and any attachments. For further inf=
ormation regarding Commonwealth Care Alliance's privacy policy, please visit=
 our Internet web site at http://www.commonwealthcare.org.
>>=20
>>=20
>>=20
>> --
>> Laws alone cannot secure freedom of expression; in order that every=20
>> man present his views without penalty there must be spirit of=20
>> tolerance in the entire population. - Albert Einstein
>>=20
>> ----------------------------------------------------------------------
>> -- Securing Apache Web Server with thawte Digital Certificate In this=20
>> guide we examine the importance of Apache-SSL and who needs an SSL certif=
icate.  We look at how SSL works, how it benefits your company and how your c=
ustomers can tell if a site is secure. You will find out how to test, purcha=
se, install and use a thawte Digital Certificate on your Apache web server. T=
hroughout, best practices for set-up are highlighted to help you ensure effi=
cient ongoing management of your encryption keys and digital certificates.
>>=20
>> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4
>> 42f727d1
>> ----------------------------------------------------------------------
>> --
>=20
>=20
>=20
> ------------------------------------------------------------------------
> Securing Apache Web Server with thawte Digital Certificate In this guide w=
e examine the importance of Apache-SSL and who needs an SSL certificate.  We=
 look at how SSL works, how it benefits your company and how your customers c=
an tell if a site is secure. You will find out how to test, purchase, instal=
l and use a thawte Digital Certificate on your Apache web server. Throughout=
, best practices for set-up are highlighted to help you ensure efficient ong=
oing management of your encryption keys and digital certificates.
>=20
> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f7=
27d1
> ------------------------------------------------------------------------
>=20
>=20
>=20
> -----------------------------------------
> The information contained in this e-mail, including any attachment(s), is i=
ntended solely for use by the named addressee(s).  If you are not the intend=
ed recipient, or a person designated as responsible for delivering such mess=
ages to the intended recipient, you are not authorized to disclose, copy, di=
stribute or retain this message, in whole or in part, without written author=
ization from PSEG.  This e-mail may contain proprietary, confidential or pri=
vileged information. If you have received this message in error, please noti=
fy the sender immediately. This notice is included in all e-mail messages le=
aving PSEG.  Thank you for your cooperation.
>=20
> CONFIDENTIALITY NOTICE: This email communication and any attachments may c=
ontain confidential and privileged information for the use of the designated=
 recipients named above. If you are not the intended recipient, you are here=
by notified that you have received this communication in error and that any r=
eview, disclosure, dissemination, distribution or copying of it or its conte=
nts is prohibited. If you have received this communication in error, please r=
eply to the sender immediately or by telephone at (617) 426-0600 and destroy=
 all copies of this communication and any attachments. For further informati=
on regarding Commonwealth Care Alliance's privacy policy, please visit our I=
nternet web site at http://www.commonwealthcare.org.
>=20
>=20
>=20
> ------------------------------------------------------------------------
> Securing Apache Web Server with thawte Digital Certificate
> In this guide we examine the importance of Apache-SSL and who needs an SSL=
 certificate.  We look at how SSL works, how it benefits your company and ho=
w your customers can tell if a site is secure. You will find out how to test=
, purchase, install and use a thawte Digital Certificate on your Apache web s=
erver. Throughout, best practices for set-up are highlighted to help you ens=
ure efficient ongoing management of your encryption keys and digital certifi=
cates.
>=20
> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f7=
27d1
> ------------------------------------------------------------------------
>=20

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------