Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015.

12
Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015

Transcript of Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015.

Page 1: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015.

Project FENIXby NIX.CZ

Tomas Marsalek

APRICOT 2015Fukuoka, 3. 3. 2015

Page 2: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015.

NIX.CZ introduction

• Neutral platform• 5 data centers in Prague• 123 connected networks• 41 international networks• 360 Gbps peek data flow• Project FENIX

Page 3: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015.

FENIX

• Reaction to DOS attacks in 3/20134 days long

• Multiple CZ targetsmedia, banks, cell phone operators, Seznam.cz (CZ “Google”)

• Source of attacks out of CZ• Nothing from CZ• Through upstream and NIX.CZ• No response source

Page 4: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015.

FENIX

• Club of “trustworthy” companies• Technical tool “Secure VLAN”• Czech eyeballs can connect to local content

home banking, media, email …

• Island modelast resort

• Faster than regulations• High joining criteria

Page 5: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015.

FENIXorganization rules

• End user terms and conditionsspam, attacks

• 24x7 technical conditionsno IVR

• CSIRT teamlisted by Trusted Introducer, Terena

• Active participation• Recommendation from 2 members, no veto

Page 6: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015.

FENIXtechnical rules

• BCP-38/SAC004 – granularity /24 (/48)• RTBH filtering using RS• IPv6, DNSSEC• Full redundancy on NIX.CZ• Network monitoring (MRTG, NetFlow, ...)• Control plane policy RFC6192• DNS, NTP, SNMP amplification protection• Security incident time <30min• BGP – TCP MD5

Page 7: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015.

FENIXstart

• 6 founding companies – January 2014Active 24CESNET (NREN)CZ.NICDial TelecomSeznam.czTelefonica Czech Republic (incumbent operator)

• NIX.CZ supervisor over rules

Page 8: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015.
Page 9: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015.

Year of FENIX

• 3 new members• Technical implementation• RTBH testing• Brand name announcement• Micro web site fe.nix.cz• Island mode test

Page 10: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015.

Members of FENIX

• New candidates

Page 11: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015.

FENIX at Slovakia

• Take over of SITELiX• CSIRT.SK discusions• More info at Peering Day • www.peeringday.eu

Page 12: Project FENIX by NIX.CZ Tomas Marsalek APRICOT 2015 Fukuoka, 3. 3. 2015.

Follow us

.. and at www.nix.cz