Proven Practices For Securing Your Website Against DDoS Attacks

17
Proven Practices for Securing Your Website Against DDoS Attacks Kevin Beaver, Principle Logic, LLC Andrew Sullivan, Dyn

description

Join subject matter experts Kevin Beaver, author of Hacking For Dummies and Andrew Sullivan, Director of Architecture at Dyn, for a discussion on real-world practices to protect your enterprise against web-focused attacks including DNS, NTP amplification, and Web application-specific exploits. They discuss the vulnerabilities of web environments and why simply jumping on the cloud provider bandwagon won’t prevent DDoS attacks.

Transcript of Proven Practices For Securing Your Website Against DDoS Attacks

Page 1: Proven Practices For Securing Your Website Against DDoS Attacks

Proven Practices for Securing Your Website Against DDoS Attacks

Kevin Beaver, Principle Logic, LLC Andrew Sullivan, Dyn

Page 2: Proven Practices For Securing Your Website Against DDoS Attacks

A bit about Kevin Beaver

●  Independent consultant ­  25 years experience in IT –

19 years in information security ­  Focus on performing technical

security assessments ●  Expert witness

­  Data breaches, security best practices/due diligence, compliance, and intellectual property cases

●  Speaker ●  Writer

●  Creator/author of Security On Wheels audiobooks & blog

(securityonwheels.com)

Page 3: Proven Practices For Securing Your Website Against DDoS Attacks

A bit about Andrew Sullivan

●  Director of Architecture for Dyn, an Internet performance company ●  15 years in the Internet industry ●  Co-author of the DNS 64 specification ●  Active in the Internet

Engineering Task Force ●  Member of the Internet

Architecture Board

Page 4: Proven Practices For Securing Your Website Against DDoS Attacks

Insanity is…

“Doing the same thing over and over again and expecting different results.”  

-­‐Albert  Einstein  

Page 5: Proven Practices For Securing Your Website Against DDoS Attacks

Defining the term

Page 6: Proven Practices For Securing Your Website Against DDoS Attacks

More than one soft underbelly

P SYN floods P UDP amplification P Botnets SYN floods

UDP amplification

Botnets

Page 7: Proven Practices For Securing Your Website Against DDoS Attacks

Botnets are cheap and easy!

Page 8: Proven Practices For Securing Your Website Against DDoS Attacks

Why do they do it?

Page 9: Proven Practices For Securing Your Website Against DDoS Attacks

The main driver

Page 10: Proven Practices For Securing Your Website Against DDoS Attacks

Common vulnerabilities

Page 11: Proven Practices For Securing Your Website Against DDoS Attacks

How do DNS attacks work?

Page 12: Proven Practices For Securing Your Website Against DDoS Attacks

Someone else performs attack

Page 13: Proven Practices For Securing Your Website Against DDoS Attacks

Response size is key

Page 14: Proven Practices For Securing Your Website Against DDoS Attacks

In the words of Kevin…

“You cannot secure (or respond to) what you don’t understand.”  -­‐Kevin  Beaver  

Page 15: Proven Practices For Securing Your Website Against DDoS Attacks

Situational awareness

Page 16: Proven Practices For Securing Your Website Against DDoS Attacks

Additional Resources

●  Kevin’s website: principlelogic.com/resources

●  Kevin’s blog: securityonwheels.com/blog

●  Kevin’s audio programs: securityonwheels.com

●  Kevin’s latest books:

●  Three Ways Companies Can Avoid DDoS Attacks (webinar) brighttalk.com/webcast/10729/113345?ContentHub

●  DDoS 101 (video): dyn.com/dynedu what_is_a_ddos_attack/

●  The Cost of a DDoS Attack (whitepaper) pages.dyn.com/evaluating-cost-of-ddos.html

Page 17: Proven Practices For Securing Your Website Against DDoS Attacks

Your plan of action

“Before everything else, getting ready is the secret to success.”  

         -­‐Henry  Ford