Presentation is loading. Please wait.

Presentation is loading. Please wait.

Networks ∙ Services ∙ People www.geant.org GEANT Information & Infrastructure Security Team TNC16 – Networking Conference Introduction DDoS at GÉANT Prague.

Similar presentations


Presentation on theme: "Networks ∙ Services ∙ People www.geant.org GEANT Information & Infrastructure Security Team TNC16 – Networking Conference Introduction DDoS at GÉANT Prague."— Presentation transcript:

1 Networks ∙ Services ∙ People www.geant.org GEANT Information & Infrastructure Security Team TNC16 – Networking Conference Introduction DDoS at GÉANT Prague June 13 th 2016 Evangelos Spatharas/Temoor Khan Security Engineer

2 Networks ∙ Services ∙ People www.geant.org INDEX DDoS Statistics, Highlights and Countermeasures How GÉANT Deals with DDoS Firewall on Demand Future of DDoS 2

3 Networks ∙ Services ∙ People www.geant.org 3 Who Sees DDoS Attacks?

4 Networks ∙ Services ∙ People www.geant.org 4 DDoS Profile UDP

5 Networks ∙ Services ∙ People www.geant.org DDoS – Ramifications Network Performance degradation Services malfunction Outages Staff & Company Productivity reduction Wasted resources Reputation Profit reduction Users Dissatisfaction Change upstream? 5

6 Networks ∙ Services ∙ People www.geant.org Manual ACLs  Time Consuming  Prone to mistakes  Highly effective RTBH  Fast  Too coarse BGP FlowSpec  Fast  Highly effective DDoS Scrubbing  Highly effective  Very expensive 6 Mitigating DDoS?

7 Networks ∙ Services ∙ People www.geant.org Manual ACLs  Time Consuming  Prone to mistakes  Highly effective RTBH  Fast  Too coarse BGP FlowSpec  Fast  Highly effective DDoS Scrubbing  Highly effective  Very expensive 7 Mitigating DDoS?

8 Networks ∙ Services ∙ People www.geant.org Manual ACLs  Time Consuming  Prone to mistakes  Highly effective RTBH  Fast  Too coarse BGP FlowSpec  Fast  Highly effective DDoS Scrubbing  Highly effective  Very expensive 8 Mitigating DDoS?

9 Networks ∙ Services ∙ People www.geant.org fod.geant.net 9 From RFC to a WEB Based Tool

10 Networks ∙ Services ∙ People www.geant.org fod.geant.net 9 From RFC to a WEB Based Tool Speed

11 Networks ∙ Services ∙ People www.geant.org fod.geant.net 9 From RFC to a WEB Based Tool Speed Effectiveness

12 Networks ∙ Services ∙ People www.geant.org fod.geant.net 9 From RFC to a WEB Based Tool Speed Effectiveness Efficiency

13 Networks ∙ Services ∙ People www.geant.org 13 Under the hood – Current Status IX A GÈANT Internet IX B NREN A FoD NSHaRP

14 Networks ∙ Services ∙ People www.geant.org 14 Under the hood – Current Status IX A GÈANT Internet IX B NREN A Flowspec FoD NSHaRP

15 Networks ∙ Services ∙ People www.geant.org 15 Upgrade – Future Plans IX A GÈANT Internet IX B NREN A Flowspec FoD NSHaRP

16 Networks ∙ Services ∙ People www.geant.org 16 DDoS in Future

17 Networks ∙ Services ∙ People www.geant.org In case you have any issues or queries in relation to FoD, please contact GÉANT Infrastructure & Security team at security@geant.org security@geant.org 17 How to Contact us

18 Networks ∙ Services ∙ People www.geant.org Thank you Networks ∙ Services ∙ People www.geant.org 18 GEANT OPS Security Team security@geant.net


Download ppt "Networks ∙ Services ∙ People www.geant.org GEANT Information & Infrastructure Security Team TNC16 – Networking Conference Introduction DDoS at GÉANT Prague."

Similar presentations


Ads by Google