NORDUnet Nordic Infrastructure for Research & Education DDoS Mitigation at NORDUnet Lars Fischer (w/ big thanks to Martin Aldrin) TF-MSP Meeting Malta,

Slides:



Advertisements
Similar presentations
Barracuda Link Balancer Link Reliability and Bandwidth Optimization.
Advertisements

Logically Centralized Control Class 2. Types of Networks ISP Networks – Entity only owns the switches – Throughput: 100GB-10TB – Heterogeneous devices:
TERENA General Assembly meeting, Poznań 9-10 June 2005 Workshop on FP7 Brussels, 11 April Theme: “Research Networking: Where do we go next?”. Attendees:
NORDUnet Nordic Infrastructure for Research & Education Service Sharing at NORDUnet Lars Fischer TF-MSP Meeting Malta, 27 November 2014.
Use Cases for I2RS I2RS Interim Meeting Nicolai Leymann, Deutsche Telekom AG
Dynamic Routing Scalable Infrastructure Workshop, AfNOG2008.
Report back from Parallel Group 1 Shirley Wood UKERNA and TERENA Executive.
COPYRIGHT © 2013 ALCATEL-LUCENT. ALL RIGHTS RESERVED. ALCATEL-LUCENT — CONFIDENTIAL — SOLELY FOR AUTHORIZED PERSONS HAVING A NEED TO KNOW — PROPRIETARY.
SDN and Openflow.
A Routing Control Platform for Managing IP Networks Jennifer Rexford Princeton University
Security Towards a coherent portfolio Walter van Dijk TF-MSP - 27 November 2014.
Arbor Multi-Layer Cloud DDoS Protection
NORDUnet Nordic Infrastructure for Research & Education NORDUnet Collaborations with Africa Lars Fischer CTO, NORDUnet 2010 EURO-AFRICA E-INFRASTRUCTURES.
Bandwidth on Demand Dave Wilson DW238-RIPE
Putting the Tools to Work – DDOS Attack 111. DDOS = SLA Violation! ISPCPETarget Hacker What do you tell the Boss? SP’s Operations Teams have found that.
Firewall on Demand A multidomain approach Leonidas Poulopoulos, Yannis Mitsos – GRNET NOC Firewall on Demand workshop TF-MSP meeting.
Extension to LDP-VPLS for Ethernet Broadcast and Multicast draft-delord-l2vpn-ldp-vpls-broadcast-exten-03 Presenter: Zhihua Liu, China Telecom IETF79,
PacNOG 6: Nadi, Fiji Dealing with DDoS Attacks Hervey Allen Network Startup Resource Center.
BGP Flow specification Update
Connect communicate collaborate Anomaly Detection in Backbone Networks: Building A Security Service Upon An Innovative Tool Wayne Routly, Maurizio Molina.
INDIANAUNIVERSITYINDIANAUNIVERSITY TransPAC2 Security John Hicks TransPAC2 Indiana University 22nd APAN Conference – Singapore 20-July-2006.
A Lightweight Platform for Integration of Resource Limited Devices into Pervasive Grids Stavros Isaiadis and Vladimir Getov University of Westminster
Presented by Xiaoyu Qin Virtualized Access Control & Firewall Virtualization.
Alberto Rivai Teknologi pemantauan jaringan internet untuk pendeteksian dini terhadap ancaman dan gangguan Alberto Rivai
BCOP on Anti-Spoofing Long known problem Deployment status Reason for this work Where more input needed.
Operational Security Capabilities for IP Network Infrastructure
Wolfgang EffelsbergUniversity of Mannheim1 Differentiated Services for the Internet Wolfgang Effelsberg University of Mannheim September 2001.
1 4/23/2007 Introduction to Grid computing Sunil Avutu Graduate Student Dept.of Computer Science.
Module 8: Planning and Troubleshooting IPSec. Overview Understanding Default Policy Rules Planning an IPSec Deployment Troubleshooting IPSec Communications.
LHC Open Network Environment LHCONE David Foster CERN IT LCG OB 30th September
MENU Implications of Securing Router Infrastructure NANOG 31 May 24, 2004 Ryan McDowell
A Firewall for Routers: Protecting Against Routing Misbehavior1 June 26, A Firewall for Routers: Protecting Against Routing Misbehavior Jia Wang.
Remote Trigger Black Hole 111. Remotely Triggered Black Hole Filtering We use BGP to trigger a network wide response to a range of attack flows. A simple.
Interdomain IPv6 multicast Stig Venaas UNINETT. PIM-SM and Rendezvous Points Interdomain multicast routing is usually done with a protocol called PIM-SM.
Congestion exposure BoF candidate protocol: re-ECN Bob Briscoe Chief Researcher, BT Nov 2009 This work is partly funded by Trilogy, a research project.
ERP SIMULATOR ERP FACILITATOR Arufa Uzair Shahmeen Mehboob Uzair Tajuddin Instructors: Dr. Abdul Basit Shams Naveed Zia.
FOR INTERNAL USE ONLY [Your business] exceeds with COLT Network Response to DDoS attacks – TNC 2006 Nicolas FISCHBACH Senior Manager, Network Engineering.
Routing integrity in a world of Bandwidth on Demand Dave Wilson DW238-RIPE
© 2003, Cisco Systems, Inc. All rights reserved. CSIDS 4.0—15-1 Chapter 15 Blocking Configuration.
NORDUnet Nordic Infrastructure for Research & Education LHCone P2P routing without dynamic router configuration Magnus Bergroth.
1 Evolution Towards Global Routing Scalability draft-zhang-evolution-01 Varun Khare Beichuan Zhang
Building Dynamic Lightpaths in GÉANT Tangui Coulouarn, DeIC E-Infrastructure Autumn Workshop, Chiinău 8 September 2014.
5 Firewalls in VoIP Selected Topics in Information Security – Bazara Barry.
Internet Security Trends LACNOG 2011 Julio Arruda LATAM Engineering Manager.
Guidance for Running Multiple IPv6 Prefixes (draft-liu-v6ops-running-multiple-prefixes-02) Bing Liu, Sheng Jiang (Speaker), Yang Bo IETF91
Introduction & Vision. Introduction MANTICORE provides a software implementation and tools for providing and managing routers and IP networks as services.
NORDUnet Nordic Infrastructure for Research & Education Workshop Introduction - Finding the Match Lars Fischer LHCONE Workshop CERN, December 2012.
Nordic NREN Jari Miettinen 21st NORDUnet Networking Conference Reykjavik, August 24 th 2003.
GÉANT - Implementing Security at Terabit Speed
Filtering Spoofed Packets Network Ingress Filtering (BCP 38) What are spoofed or forged packets? Why are they bad? How to keep them out.
Brocade Flow Optimizer
© 2005 Cisco Systems, Inc. All rights reserved. BGP v3.2—6-1 Scaling Service Provider Networks Scaling IGP and BGP in Service Provider Networks.
© 2005 Cisco Systems, Inc. All rights reserved. BGP v3.2—1-1 Course Introduction.
NORDUnet NORDUnet e-Infrastrucure: Grids and Hybrid Networks Lars Fischer CTO, NORDUnet Fall 2006 Internet2 Member Meeting, Chicago.
NORDUnet Nordic Infrastructure for Research & Education Report of the CERN LHCONE Workshop May 2013 Lars Fischer LHCONE Meeting Paris, June 2013.
Building SDN-ready high bandwidth IXP M.Sc.E.E. Goran Slavić
Networks ∙ Services ∙ People GEANT Information & Infrastructure Security Team TNC16 – Networking Conference Introduction DDoS at GÉANT Prague.
1 SENSS Security Service for the Internet Jelena Mirkovic (USC/ISI), Minlan Yu (USC), Ying Zhang (HP Labs), Sivaram Ramanathan (USC)
Multi Point VPN Service
Evolution Towards Global Routing Scalability
Huajin Jeng, Jeffrey Haas, Yakov Rekhter, Jeffrey Zhang
Operating Wide-Area Ethernet Networks
Introducing To Networking
Cooperative Takes Control of IT with Barracuda Security Solutions Deployed on Microsoft Azure “Barracuda has provided us with a logical, easy, very intuitive.
Extending MPLS/BGP VPNs to End-Systems
Data collection methodology and NM paradigms
Content Delivery and Remote DNS services
Terabit Scale Edge DDoS Protection
Large-Scale Edge DDoS Protection
SwiNOG May 2013 Ian Cleary – Director Internet Services EMEA
Presentation transcript:

NORDUnet Nordic Infrastructure for Research & Education DDoS Mitigation at NORDUnet Lars Fischer (w/ big thanks to Martin Aldrin) TF-MSP Meeting Malta, 27 November 2014

NORDUnet Nordic infrastructure for Research & Education Basic DDoS is a major issue; every responsible network must be working on the best ways to counter it So far NORDUnet is doing blackholing It works It kills an entire network Creates ”Innocent bystander” problem Creates reluctance to deploy

NORDUnet Nordic infrastructure for Research & Education DDoS structure

NORDUnet Nordic infrastructure for Research & Education Options Scrubbing Intelligence DDoS Mitigation Systems (IDMS) Commercial products available (i.e., Arbor Networks) Costly Unlike carriers, we cannot sell it as a service Enterprise-level solutions IP rewrite, running traffic through filter or firewall Does not scale to our needs Flowspec Promising This is our bet for a future solution

NORDUnet Nordic infrastructure for Research & Education What is FlowSpec? Flow Specification (RFC 5575) Designed for DDoS mitigation Remote triggered ACLs Extension to BGP Can match in various events and traffic types Can act to rate-limit, redirect, mark, etc Bleeding edge technology, working it’s way through IETF Per-interface capability only came this summer

NORDUnet Nordic infrastructure for Research & Education Trying FlowSpec Objective Investigate what a FlowSpec-based solution might look like Is there a good match for NREN environment? DIY, since there’s nothing in the market Can we create a controller to dynamically assign FlowSpec rules? Student project MSc student: Martin Aldrin Controller design and development Full implementation and test Lab exercise

NORDUnet Nordic infrastructure for Research & Education DDoS Attack (w/ NTP)

NORDUnet Nordic infrastructure for Research & Education Blackhole Real traffic lost

NORDUnet Nordic infrastructure for Research & Education Flowspec – edge limit Better, but still load on core

NORDUnet Nordic infrastructure for Research & Education Limit w/ FlowSpec controllers Co-operating networks reduce core load

NORDUnet Nordic infrastructure for Research & Education Lab w/FlowSpec controllers

NORDUnet Nordic infrastructure for Research & Education Attack traffic flow

NORDUnet Nordic infrastructure for Research & Education Real traffic flow

NORDUnet Nordic infrastructure for Research & Education Status We have done the experiment We have it working in the lab Decision point: is this something we’re pushing towards production? Live network trial? We have not decided We need a customer / border to try it on Solution has network effect Value go up with more deployments There’s mutual benefit (and there’s additional technical work we’d like to do)

NORDUnet Nordic infrastructure for Research & Education Joint Effort? Collaborative DDoS effort based on FlowSpec? Are we solving a problem? Is this something other networks see value in? Community adopting the technology? GÉANT Firewall-as-a-service based on FlowSpec What next? Is the idea liked? How do we set up a collaboration? What is the way forward?

NORDUnet Nordic infrastructure for Research & Education Conclusions We must have something better than blackhole Right now that means FlowSpec We have to go DIY It works in the lab We want to work with YOU Real value comes of many are doing it