Re: DDoS protection

Comp Pycho <[email protected]> Wed, 25 Jun 2014 10:23:58 -0400
Newsgroups gmane.comp.security.basics
Message-ID <[email protected]>
The concept of cloud computing did not get popular until NIST made it a stan=
dard and ordered the gov't to move 30% of their IT infrastructure to the clo=
ud. Cloud was a concept of IBM sine 1984 it was not coined cloud computing b=
y them but the concept is theirs. FedRamp is always based off the latest NIS=
T controls so I don't understand your claim with that. FedRamp is a govt wid=
e program that standardizes approach to security assessment, authorization a=
nd continuous monitoring for cloud products and services. This is from the G=
SA website whom provide the service by definitions it shoulda like a complia=
nce standard. It applies the NIST 800- 53 controls.=20

Do what you know
-Dame Dash


> On Jun 25, 2014, at 9:36 AM, "Mikhail A. Utin" <[email protected]=
> wrote:
>=20
> Some remarks.
> 1. Cloud Computing, yes, is just about datacenters serving hosting, i.e. a=
pplication hosting service.
> 2. First appeared as Amazon AWS
> 3. CC is not actually IBM own concept as there is no concept in CC at all,=
 see #1
> 4. NIST actually was far later than other parties in "cloudization" (I cla=
im this term :) )
> 5. FedRAMP is not certification program at all. Plus, its security control=
s list is outdated - it is based on NIST SP800-53 R3, pretty outdated versio=
n. Current is R4. So, absolutely cannot be used for anything like certificat=
ion.
>=20
> Mikhail
>=20
> -----Original Message-----
> From: Comp Pycho [mailto:[email protected]]
> Sent: Wednesday, June 25, 2014 8:52 AM
> To: Marios Stylianou
> Cc: Mikhail A. Utin; <[email protected]>; <security-basics@securit=
yfocus.com>
> Subject: Re: DDoS protection
>=20
> Cloud computing is an IBM concept that was blow up by NIST. NIST pushed th=
is "Cloud" BS for external parties to make money. The cloud is nothing but a=
 data center. The secure clouds are data centers which have gone through the=
 FedRamp certification program for security compliance.=20
>=20
> Do what you know
> -Dame Dash
>=20
>=20
>> On Jun 25, 2014, at 6:56 AM, "Marios Stylianou" <[email protected]>=
 wrote:
>>=20
>> You can try Incapsula services.
>>=20
>>=20
>> Mindbets
>>=20
>>=20
>> -----Original Message-----
>> From: [email protected]=20
>> [mailto:[email protected]] On Behalf Of Mikhail A. Utin
>> Sent: Monday, June 23, 2014 7:02 PM
>> To: Sardina, Dominick; [email protected]
>> Subject: RE: DDoS protection
>>=20
>> Hello,
>> Yes, all has been known for a while. I got two presentations discussing p=
artially "cloud" matter at OWASP AppSec DC 2012 and DeepSec 2012 and 2013.
>> You can check both for presentations or ask me personally.
>> Basically, all "clouds" are simply application hosting web sites. And tec=
hnically a "cloud" is a datacenter. Whether such app is a virtual network or=
 Mom&Dad Pizza shop HTML site does not matter.
>> So named "cloud computing concept" has nothing in common with computing, a=
nd not a concept at all. Models are useless and in such case as "Community C=
loud" and "Hybrid Cloud" is legal nonsense, simply because a service provide=
r cannot have legal binding relationship (aka a contract) with a community, w=
hich is not a legal entity.
>> I tried to dig out where "cloud" came from. It is an invention of IBM=20
>> circle companies hosting site reselling IBM services. And in essence=20
>> is the replacement of Google and next IBM funded academic cluster=20
>> project "Academia Cluster Computing Initiative" or ACCI, see: Let a=20
>> Thousand servers bloom =E2=80=93 Google official post, Posted by Christop=
he=20
>> Bisciglia, October 8, 2007=20
>> http://googleblog.blogspot.com/2007/10/let-thousand-servers-bloom.html
>> IBM circle guys replaced "cluster" with "cloud" and renamed ACCI as "Acad=
emia Cloud Computing Initiative". Bingo! Next they needed something looking l=
ike science in a form of "models".
>> However, guys violated Google intellectual property rights on the origina=
l ACCI project name.
>>=20
>> Regards
>>=20
>> Mikhail
>>=20
>>=20
>>=20
>> -----Original Message-----
>> From: [email protected]=20
>> [mailto:[email protected]] On Behalf Of Sardina, Dominick
>> Sent: Friday, June 20, 2014 2:49 PM
>> To: [email protected]
>> Subject: RE: DDoS protection
>>=20
>> Brett, I have to agree 100%.
>>=20
>>=20
>> Regards,
>> Dominick
>>=20
>>=20
>> -----Original Message-----
>> From: [email protected]=20
>> [mailto:[email protected]] On Behalf Of Wagner, Brett
>> Sent: Friday, June 20, 2014 12:57 PM
>> To: Hartley, Christopher J.; Kellstr
>> Cc: [email protected]
>> Subject: RE: DDoS protection
>>=20
>> IMHO - I am not a fan of all the mumbo jumbo that goes along with the "Cl=
oud" like it is a new invention. I worked at GTE/BBN in 1999 and we were sel=
ling all the same crap back then. With that said and having worked at EMC fo=
r a while you can have a "Cloud" on premises just means you have the hardwar=
e in one of your company locations. You can have private, shared, public or a=
 combo.=20
>>=20
>> It is the same evolution as IT security circa 1970-80s (Rainbow Book Seri=
es days), then Information Security circa 1990s, then Information Assurance c=
irca late 90s early 2000s and now Cyber Security. With each name change cons=
ultants and companies can charge more for the same ultimate goal with each n=
ame change.
>>=20
>> OK I will now get off my soapbox.
>> -----Original Message-----
>> From: [email protected] [mailto:[email protected]] O=
n Behalf Of Hartley, Christopher J.
>> Sent: Friday, June 20, 2014 10:48 AM
>> To: Kellstr
>> Cc: [email protected]
>> Subject: Re: DDoS protection
>>=20
>> This is a little confusing; =E2=80=9Ccloud=E2=80=9D, =E2=80=9Con-premise=E2=
=80=9D etc=E2=80=A6 weird.
>>=20
>> By =E2=80=9CCloud,=E2=80=9D it seem like we mean =E2=80=9Cby provider=E2=80=
=9D (makes sense).
>>=20
>> On-premise is the best way to detect an attack imo, since the victim netw=
ork knows what=E2=80=99s good and what=E2=80=99s not (or should=E2=80=A6.).
>>=20
>> So I think the best solution involves some kind of remote blackhole or id=
eally, perhaps flowspec.
>>=20
>> I don=E2=80=99t think it=E2=80=99s a problem that requires spending signi=
ficant money.
>>=20
>> Chris
>>=20
>>> On Jun 19, 2014, at 12:50 PM, Kellstr <[email protected]> wrote:
>>>=20
>>> Disclaimer: I work for a company which offers a DDoS Protection Service.=

>>>=20
>>> The advantage of a service "in the cloud" is that if an attack=20
>>> exceeds your circuit bandwidth the provider will be able to drop the=20
>>> malicious traffic. That cannot be done at your premise. Both Arbor=20
>>> and Radware offer strong appliances that can clean up smaller attacks=20=

>>> at your premise and can send a signal to the provider if they support=20=

>>> that service. You can block traffic using IPS's but keep in mind they=20=

>>> are not designed for a volumetric attack and may be overwhelmed.
>>>=20
>>> On Wed, Jun 18, 2014 at 11:10 AM, Lance Lassetter=20
>>> <[email protected]> wrote:
>>>> What about Suricata or Snort IDS in IPS mode?
>>>>=20
>>>>> On Jun 18, 2014 8:43 AM, "Mikhail A. Utin" <[email protected]=
> wrote:
>>>>>=20
>>>>> As you indicated " Although we're small, We're an organization playing=
 with ($,=C2=A5,=E2=82=AC,=C2=A3) exchanges" you are on client side rather t=
han on server. If that is right, you do not need to bother with DDoS protect=
ion, which is against server side.
>>>>> Mikhail
>>>>>=20
>>>>> -----Original Message-----
>>>>> From: [email protected]
>>>>> [mailto:[email protected]] On Behalf Of=20
>>>>> [email protected]
>>>>> Sent: Wednesday, June 18, 2014 12:49 AM
>>>>> To: [email protected]
>>>>> Subject: Re: Re: DDoS protection
>>>>>=20
>>>>> Hi,
>>>>>=20
>>>>> Thanks for your replies.
>>>>>=20
>>>>> Noted the points raised by Jacint and Kelly Keeton. I appreciate that.=

>>>>>=20
>>>>> May I be kind to seek an opinion/ arguments suggesting if the In-house=
 appliances are more "intelligent" thwarting the application level DOS/ DDoS=
 attacks as compared to ISP provided DOS protection wherein it may even fail=
 to detect them. or if there are other benefits owning an In-house product?
>>>>>=20
>>>>> As far as Cons are concerned, I feel that the appliance may add some l=
atency which may create issues wherein a latency of milliseconds count.
>>>>>=20
>>>>> Although we're small, We're an organization playing with ($,=C2=A5,=E2=
=82=AC,=C2=A3) exchanges and heavily regulated by the Government.
>>>>>=20
>>>>> Thanks,
>>>>> KT
>>>>>=20
>>>>> -------------------------------------------------------------------
>>>>> -
>>>>> ---- Securing Apache Web Server with thawte Digital Certificate In=20
>>>>> this guide we examine the importance of Apache-SSL and who needs an SS=
L certificate.  We look at how SSL works, how it benefits your company and h=
ow your customers can tell if a site is secure. You will find out how to tes=
t, purchase, install and use a thawte Digital Certificate on your Apache web=
 server. Throughout, best practices for set-up are highlighted to help you e=
nsure efficient ongoing management of your encryption keys and digital certi=
ficates.
>>>>>=20
>>>>> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6
>>>>> b
>>>>> e442f727d1
>>>>> -------------------------------------------------------------------
>>>>> -
>>>>> ----
>>>>>=20
>>>>>=20
>>>>> CONFIDENTIALITY NOTICE: This email communication and any=20
>>>>> attachments may contain confidential and privileged information for=20=

>>>>> the use of the designated recipients named above. If you are not=20
>>>>> the intended recipient, you are hereby notified that you have=20
>>>>> received this communication in error and that any review,=20
>>>>> disclosure, dissemination, distribution or copying of it or its=20
>>>>> contents is prohibited. If you have received this communication in=20
>>>>> error, please reply to the sender immediately or by telephone at (617)=
 426-0600 and destroy all copies of this communication and any attachments. =
For further information regarding Commonwealth Care Alliance's privacy polic=
y, please visit our Internet web site at http://www.commonwealthcare.org.
>>>=20
>>>=20
>>>=20
>>> --
>>> Laws alone cannot secure freedom of expression; in order that every=20
>>> man present his views without penalty there must be spirit of=20
>>> tolerance in the entire population. - Albert Einstein
>>>=20
>>> ---------------------------------------------------------------------
>>> -
>>> -- Securing Apache Web Server with thawte Digital Certificate In this=20=

>>> guide we examine the importance of Apache-SSL and who needs an SSL certi=
ficate.  We look at how SSL works, how it benefits your company and how your=
 customers can tell if a site is secure. You will find out how to test, purc=
hase, install and use a thawte Digital Certificate on your Apache web server=
. Throughout, best practices for set-up are highlighted to help you ensure e=
fficient ongoing management of your encryption keys and digital certificates=
.
>>>=20
>>> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be
>>> 4
>>> 42f727d1
>>> ---------------------------------------------------------------------
>>> -
>>> --
>>=20
>>=20
>>=20
>> ----------------------------------------------------------------------
>> -- Securing Apache Web Server with thawte Digital Certificate In this=20
>> guide we examine the importance of Apache-SSL and who needs an SSL certif=
icate.  We look at how SSL works, how it benefits your company and how your c=
ustomers can tell if a site is secure. You will find out how to test, purcha=
se, install and use a thawte Digital Certificate on your Apache web server. T=
hroughout, best practices for set-up are highlighted to help you ensure effi=
cient ongoing management of your encryption keys and digital certificates.
>>=20
>> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4
>> 42f727d1
>> ----------------------------------------------------------------------
>> --
>>=20
>>=20
>>=20
>> -----------------------------------------
>> The information contained in this e-mail, including any attachment(s), is=
 intended solely for use by the named addressee(s).  If you are not the inte=
nded recipient, or a person designated as responsible for delivering such me=
ssages to the intended recipient, you are not authorized to disclose, copy, d=
istribute or retain this message, in whole or in part, without written autho=
rization from PSEG.  This e-mail may contain proprietary, confidential or pr=
ivileged information. If you have received this message in error, please not=
ify the sender immediately. This notice is included in all e-mail messages l=
eaving PSEG.  Thank you for your cooperation.
>>=20
>> CONFIDENTIALITY NOTICE: This email communication and any attachments may c=
ontain confidential and privileged information for the use of the designated=
 recipients named above. If you are not the intended recipient, you are here=
by notified that you have received this communication in error and that any r=
eview, disclosure, dissemination, distribution or copying of it or its conte=
nts is prohibited. If you have received this communication in error, please r=
eply to the sender immediately or by telephone at (617) 426-0600 and destroy=
 all copies of this communication and any attachments. For further informati=
on regarding Commonwealth Care Alliance's privacy policy, please visit our I=
nternet web site at http://www.commonwealthcare.org.
>>=20
>>=20
>>=20
>> ----------------------------------------------------------------------
>> -- Securing Apache Web Server with thawte Digital Certificate In this=20
>> guide we examine the importance of Apache-SSL and who needs an SSL certif=
icate.  We look at how SSL works, how it benefits your company and how your c=
ustomers can tell if a site is secure. You will find out how to test, purcha=
se, install and use a thawte Digital Certificate on your Apache web server. T=
hroughout, best practices for set-up are highlighted to help you ensure effi=
cient ongoing management of your encryption keys and digital certificates.
>>=20
>> http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be4
>> 42f727d1
>> ----------------------------------------------------------------------
>> --
>=20
> CONFIDENTIALITY NOTICE: This email communication and any attachments may c=
ontain confidential=20
> and privileged information for the use of the designated recipients named a=
bove. If you are=20
> not the intended recipient, you are hereby notified that you have received=
 this communication=20
> in error and that any review, disclosure, dissemination, distribution or c=
opying of it or its=20
> contents is prohibited. If you have received this communication in error, p=
lease reply to the=20
> sender immediately or by telephone at (617) 426-0600 and destroy all copie=
s of this communication=20
> and any attachments. For further information regarding Commonwealth Care A=
lliance's privacy policy,=20
> please visit our Internet web site at http://www.commonwealthcare.org.
>=20

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------