Networks ∙ Services ∙ People GEANT Information & Infrastructure Security Team TNC16 – Networking Conference Introduction DDoS at GÉANT Prague June 13 th 2016 Evangelos Spatharas/Temoor Khan Security Engineer
Networks ∙ Services ∙ People INDEX DDoS Statistics, Highlights and Countermeasures How GÉANT Deals with DDoS Firewall on Demand Future of DDoS 2
Networks ∙ Services ∙ People 3 Who Sees DDoS Attacks?
Networks ∙ Services ∙ People 4 DDoS Profile UDP
Networks ∙ Services ∙ People DDoS – Ramifications Network Performance degradation Services malfunction Outages Staff & Company Productivity reduction Wasted resources Reputation Profit reduction Users Dissatisfaction Change upstream? 5
Networks ∙ Services ∙ People Manual ACLs Time Consuming Prone to mistakes Highly effective RTBH Fast Too coarse BGP FlowSpec Fast Highly effective DDoS Scrubbing Highly effective Very expensive 6 Mitigating DDoS?
Networks ∙ Services ∙ People Manual ACLs Time Consuming Prone to mistakes Highly effective RTBH Fast Too coarse BGP FlowSpec Fast Highly effective DDoS Scrubbing Highly effective Very expensive 7 Mitigating DDoS?
Networks ∙ Services ∙ People Manual ACLs Time Consuming Prone to mistakes Highly effective RTBH Fast Too coarse BGP FlowSpec Fast Highly effective DDoS Scrubbing Highly effective Very expensive 8 Mitigating DDoS?
Networks ∙ Services ∙ People fod.geant.net 9 From RFC to a WEB Based Tool
Networks ∙ Services ∙ People fod.geant.net 9 From RFC to a WEB Based Tool Speed
Networks ∙ Services ∙ People fod.geant.net 9 From RFC to a WEB Based Tool Speed Effectiveness
Networks ∙ Services ∙ People fod.geant.net 9 From RFC to a WEB Based Tool Speed Effectiveness Efficiency
Networks ∙ Services ∙ People 13 Under the hood – Current Status IX A GÈANT Internet IX B NREN A FoD NSHaRP
Networks ∙ Services ∙ People 14 Under the hood – Current Status IX A GÈANT Internet IX B NREN A Flowspec FoD NSHaRP
Networks ∙ Services ∙ People 15 Upgrade – Future Plans IX A GÈANT Internet IX B NREN A Flowspec FoD NSHaRP
Networks ∙ Services ∙ People 16 DDoS in Future
Networks ∙ Services ∙ People In case you have any issues or queries in relation to FoD, please contact GÉANT Infrastructure & Security team at 17 How to Contact us
Networks ∙ Services ∙ People Thank you Networks ∙ Services ∙ People 18 GEANT OPS Security Team