Re: DDoS protection
Comp Pycho <[email protected]> Wed, 25 Jun 2014 10:23:58 -0400
| Newsgroups | gmane.comp.security.basics |
|---|---|
| Message-ID | <[email protected]> |
The concept of cloud computing did not get popular until NIST made it a stan= dard and ordered the gov't to move 30% of their IT infrastructure to the clo= ud. Cloud was a concept of IBM sine 1984 it was not coined cloud computing b= y them but the concept is theirs. FedRamp is always based off the latest NIS= T controls so I don't understand your claim with that. FedRamp is a govt wid= e program that standardizes approach to security assessment, authorization a= nd continuous monitoring for cloud products and services. This is from the G= SA website whom provide the service by definitions it shoulda like a complia= nce standard. It applies the NIST 800- 53 controls.=20 Do what you know -Dame Dash > On Jun 25, 2014, at 9:36 AM, "Mikhail A. Utin" <[email protected]= > wrote: >=20 > Some remarks. > 1. Cloud Computing, yes, is just about datacenters serving hosting, i.e. a= pplication hosting service. > 2. First appeared as Amazon AWS > 3. CC is not actually IBM own concept as there is no concept in CC at all,= see #1 > 4. NIST actually was far later than other parties in "cloudization" (I cla= im this term :) ) > 5. FedRAMP is not certification program at all. Plus, its security control= s list is outdated - it is based on NIST SP800-53 R3, pretty outdated versio= n. Current is R4. So, absolutely cannot be used for anything like certificat= ion. >=20 > Mikhail >=20 > -----Original Message----- > From: Comp Pycho [mailto:[email protected]] > Sent: Wednesday, June 25, 2014 8:52 AM > To: Marios Stylianou > Cc: Mikhail A. Utin; <[email protected]>; <security-basics@securit= yfocus.com> > Subject: Re: DDoS protection >=20 > Cloud computing is an IBM concept that was blow up by NIST. NIST pushed th= is "Cloud" BS for external parties to make money. The cloud is nothing but a= data center. The secure clouds are data centers which have gone through the= FedRamp certification program for security compliance.=20 >=20 > Do what you know > -Dame Dash >=20 >=20 >> On Jun 25, 2014, at 6:56 AM, "Marios Stylianou" <[email protected]>= wrote: >>=20 >> You can try Incapsula services. >>=20 >>=20 >> Mindbets >>=20 >>=20 >> -----Original Message----- >> From: [email protected]=20 >> [mailto:[email protected]] On Behalf Of Mikhail A. Utin >> Sent: Monday, June 23, 2014 7:02 PM >> To: Sardina, Dominick; [email protected] >> Subject: RE: DDoS protection >>=20 >> Hello, >> Yes, all has been known for a while. I got two presentations discussing p= artially "cloud" matter at OWASP AppSec DC 2012 and DeepSec 2012 and 2013. >> You can check both for presentations or ask me personally. >> Basically, all "clouds" are simply application hosting web sites. And tec= hnically a "cloud" is a datacenter. Whether such app is a virtual network or= Mom&Dad Pizza shop HTML site does not matter. >> So named "cloud computing concept" has nothing in common with computing, a= nd not a concept at all. Models are useless and in such case as "Community C= loud" and "Hybrid Cloud" is legal nonsense, simply because a service provide= r cannot have legal binding relationship (aka a contract) with a community, w= hich is not a legal entity. >> I tried to dig out where "cloud" came from. It is an invention of IBM=20 >> circle companies hosting site reselling IBM services. And in essence=20 >> is the replacement of Google and next IBM funded academic cluster=20 >> project "Academia Cluster Computing Initiative" or ACCI, see: Let a=20 >> Thousand servers bloom =E2=80=93 Google official post, Posted by Christop= he=20 >> Bisciglia, October 8, 2007=20 >> http://googleblog.blogspot.com/2007/10/let-thousand-servers-bloom.html >> IBM circle guys replaced "cluster" with "cloud" and renamed ACCI as "Acad= emia Cloud Computing Initiative". Bingo! Next they needed something looking l= ike science in a form of "models". >> However, guys violated Google intellectual property rights on the origina= l ACCI project name. >>=20 >> Regards >>=20 >> Mikhail >>=20 >>=20 >>=20 >> -----Original Message----- >> From: [email protected]=20 >> [mailto:[email protected]] On Behalf Of Sardina, Dominick >> Sent: Friday, June 20, 2014 2:49 PM >> To: [email protected] >> Subject: RE: DDoS protection >>=20 >> Brett, I have to agree 100%. >>=20 >>=20 >> Regards, >> Dominick >>=20 >>=20 >> -----Original Message----- >> From: [email protected]=20 >> [mailto:[email protected]] On Behalf Of Wagner, Brett >> Sent: Friday, June 20, 2014 12:57 PM >> To: Hartley, Christopher J.; Kellstr >> Cc: [email protected] >> Subject: RE: DDoS protection >>=20 >> IMHO - I am not a fan of all the mumbo jumbo that goes along with the "Cl= oud" like it is a new invention. I worked at GTE/BBN in 1999 and we were sel= ling all the same crap back then. With that said and having worked at EMC fo= r a while you can have a "Cloud" on premises just means you have the hardwar= e in one of your company locations. You can have private, shared, public or a= combo.=20 >>=20 >> It is the same evolution as IT security circa 1970-80s (Rainbow Book Seri= es days), then Information Security circa 1990s, then Information Assurance c= irca late 90s early 2000s and now Cyber Security. With each name change cons= ultants and companies can charge more for the same ultimate goal with each n= ame change. >>=20 >> OK I will now get off my soapbox. >> -----Original Message----- >> From: [email protected] [mailto:[email protected]] O= n Behalf Of Hartley, Christopher J. >> Sent: Friday, June 20, 2014 10:48 AM >> To: Kellstr >> Cc: [email protected] >> Subject: Re: DDoS protection >>=20 >> This is a little confusing; =E2=80=9Ccloud=E2=80=9D, =E2=80=9Con-premise=E2= =80=9D etc=E2=80=A6 weird. >>=20 >> By =E2=80=9CCloud,=E2=80=9D it seem like we mean =E2=80=9Cby provider=E2=80= =9D (makes sense). >>=20 >> On-premise is the best way to detect an attack imo, since the victim netw= ork knows what=E2=80=99s good and what=E2=80=99s not (or should=E2=80=A6.). >>=20 >> So I think the best solution involves some kind of remote blackhole or id= eally, perhaps flowspec. >>=20 >> I don=E2=80=99t think it=E2=80=99s a problem that requires spending signi= ficant money. >>=20 >> Chris >>=20 >>> On Jun 19, 2014, at 12:50 PM, Kellstr <[email protected]> wrote: >>>=20 >>> Disclaimer: I work for a company which offers a DDoS Protection Service.= >>>=20 >>> The advantage of a service "in the cloud" is that if an attack=20 >>> exceeds your circuit bandwidth the provider will be able to drop the=20 >>> malicious traffic. That cannot be done at your premise. Both Arbor=20 >>> and Radware offer strong appliances that can clean up smaller attacks=20= >>> at your premise and can send a signal to the provider if they support=20= >>> that service. You can block traffic using IPS's but keep in mind they=20= >>> are not designed for a volumetric attack and may be overwhelmed. >>>=20 >>> On Wed, Jun 18, 2014 at 11:10 AM, Lance Lassetter=20 >>> <[email protected]> wrote: >>>> What about Suricata or Snort IDS in IPS mode? >>>>=20 >>>>> On Jun 18, 2014 8:43 AM, "Mikhail A. Utin" <[email protected]= > wrote: >>>>>=20 >>>>> As you indicated " Although we're small, We're an organization playing= with ($,=C2=A5,=E2=82=AC,=C2=A3) exchanges" you are on client side rather t= han on server. If that is right, you do not need to bother with DDoS protect= ion, which is against server side. >>>>> Mikhail >>>>>=20 >>>>> -----Original Message----- >>>>> From: [email protected] >>>>> [mailto:[email protected]] On Behalf Of=20 >>>>> [email protected] >>>>> Sent: Wednesday, June 18, 2014 12:49 AM >>>>> To: [email protected] >>>>> Subject: Re: Re: DDoS protection >>>>>=20 >>>>> Hi, >>>>>=20 >>>>> Thanks for your replies. >>>>>=20 >>>>> Noted the points raised by Jacint and Kelly Keeton. I appreciate that.= >>>>>=20 >>>>> May I be kind to seek an opinion/ arguments suggesting if the In-house= appliances are more "intelligent" thwarting the application level DOS/ DDoS= attacks as compared to ISP provided DOS protection wherein it may even fail= to detect them. or if there are other benefits owning an In-house product? >>>>>=20 >>>>> As far as Cons are concerned, I feel that the appliance may add some l= atency which may create issues wherein a latency of milliseconds count. >>>>>=20 >>>>> Although we're small, We're an organization playing with ($,=C2=A5,=E2= =82=AC,=C2=A3) exchanges and heavily regulated by the Government. >>>>>=20 >>>>> Thanks, >>>>> KT >>>>>=20 >>>>> ------------------------------------------------------------------- >>>>> - >>>>> ---- Securing Apache Web Server with thawte Digital Certificate In=20 >>>>> this guide we examine the importance of Apache-SSL and who needs an SS= L certificate. We look at how SSL works, how it benefits your company and h= ow your customers can tell if a site is secure. You will find out how to tes= t, purchase, install and use a thawte Digital Certificate on your Apache web= server. Throughout, best practices for set-up are highlighted to help you e= nsure efficient ongoing management of your encryption keys and digital certi= ficates. >>>>>=20 >>>>> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6 >>>>> b >>>>> e442f727d1 >>>>> ------------------------------------------------------------------- >>>>> - >>>>> ---- >>>>>=20 >>>>>=20 >>>>> CONFIDENTIALITY NOTICE: This email communication and any=20 >>>>> attachments may contain confidential and privileged information for=20= >>>>> the use of the designated recipients named above. If you are not=20 >>>>> the intended recipient, you are hereby notified that you have=20 >>>>> received this communication in error and that any review,=20 >>>>> disclosure, dissemination, distribution or copying of it or its=20 >>>>> contents is prohibited. If you have received this communication in=20 >>>>> error, please reply to the sender immediately or by telephone at (617)= 426-0600 and destroy all copies of this communication and any attachments. = For further information regarding Commonwealth Care Alliance's privacy polic= y, please visit our Internet web site at http://www.commonwealthcare.org. >>>=20 >>>=20 >>>=20 >>> -- >>> Laws alone cannot secure freedom of expression; in order that every=20 >>> man present his views without penalty there must be spirit of=20 >>> tolerance in the entire population. - Albert Einstein >>>=20 >>> --------------------------------------------------------------------- >>> - >>> -- Securing Apache Web Server with thawte Digital Certificate In this=20= >>> guide we examine the importance of Apache-SSL and who needs an SSL certi= ficate. We look at how SSL works, how it benefits your company and how your= customers can tell if a site is secure. You will find out how to test, purc= hase, install and use a thawte Digital Certificate on your Apache web server= . Throughout, best practices for set-up are highlighted to help you ensure e= fficient ongoing management of your encryption keys and digital certificates= . >>>=20 >>> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be >>> 4 >>> 42f727d1 >>> --------------------------------------------------------------------- >>> - >>> -- >>=20 >>=20 >>=20 >> ---------------------------------------------------------------------- >> -- Securing Apache Web Server with thawte Digital Certificate In this=20 >> guide we examine the importance of Apache-SSL and who needs an SSL certif= icate. We look at how SSL works, how it benefits your company and how your c= ustomers can tell if a site is secure. You will find out how to test, purcha= se, install and use a thawte Digital Certificate on your Apache web server. T= hroughout, best practices for set-up are highlighted to help you ensure effi= cient ongoing management of your encryption keys and digital certificates. >>=20 >> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4 >> 42f727d1 >> ---------------------------------------------------------------------- >> -- >>=20 >>=20 >>=20 >> ----------------------------------------- >> The information contained in this e-mail, including any attachment(s), is= intended solely for use by the named addressee(s). If you are not the inte= nded recipient, or a person designated as responsible for delivering such me= ssages to the intended recipient, you are not authorized to disclose, copy, d= istribute or retain this message, in whole or in part, without written autho= rization from PSEG. This e-mail may contain proprietary, confidential or pr= ivileged information. If you have received this message in error, please not= ify the sender immediately. This notice is included in all e-mail messages l= eaving PSEG. Thank you for your cooperation. >>=20 >> CONFIDENTIALITY NOTICE: This email communication and any attachments may c= ontain confidential and privileged information for the use of the designated= recipients named above. If you are not the intended recipient, you are here= by notified that you have received this communication in error and that any r= eview, disclosure, dissemination, distribution or copying of it or its conte= nts is prohibited. If you have received this communication in error, please r= eply to the sender immediately or by telephone at (617) 426-0600 and destroy= all copies of this communication and any attachments. For further informati= on regarding Commonwealth Care Alliance's privacy policy, please visit our I= nternet web site at http://www.commonwealthcare.org. >>=20 >>=20 >>=20 >> ---------------------------------------------------------------------- >> -- Securing Apache Web Server with thawte Digital Certificate In this=20 >> guide we examine the importance of Apache-SSL and who needs an SSL certif= icate. We look at how SSL works, how it benefits your company and how your c= ustomers can tell if a site is secure. You will find out how to test, purcha= se, install and use a thawte Digital Certificate on your Apache web server. T= hroughout, best practices for set-up are highlighted to help you ensure effi= cient ongoing management of your encryption keys and digital certificates. >>=20 >> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4 >> 42f727d1 >> ---------------------------------------------------------------------- >> -- >=20 > CONFIDENTIALITY NOTICE: This email communication and any attachments may c= ontain confidential=20 > and privileged information for the use of the designated recipients named a= bove. If you are=20 > not the intended recipient, you are hereby notified that you have received= this communication=20 > in error and that any review, disclosure, dissemination, distribution or c= opying of it or its=20 > contents is prohibited. If you have received this communication in error, p= lease reply to the=20 > sender immediately or by telephone at (617) 426-0600 and destroy all copie= s of this communication=20 > and any attachments. For further information regarding Commonwealth Care A= lliance's privacy policy,=20 > please visit our Internet web site at http://www.commonwealthcare.org. >=20 ------------------------------------------------------------------------ Securing Apache Web Server with thawte Digital Certificate In this guide we examine the importance of Apache-SSL and who needs an SSL certificate. We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates. http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1 ------------------------------------------------------------------------