Showing posts with label network behavioral analysis. Show all posts
Showing posts with label network behavioral analysis. Show all posts

Monday, December 12, 2011

Security Win: $2M Wireless Tier1 Deal for Radware's Attack Mitigation System

  
A year ago Yankee Group predicted that - "A Denial-of-Service Attack Will Take a 4G Network Down"(here) saying  that "With clean-up costs (including the network, IT, customer care, media relations, etc.), fewer new subscriptions and increased churn, the bill for this DoS outage will be a minimum of U.S.$10 million in the first month alone .. The winners include vendors like Arbor Networks and Radware that help operators address these issues. But equipment vendors like Alcatel-Lucent (ALU), Cisco, Ericsson and Huawei will also be called on to assist, as will their professional services organizations".
   
One year after that, Radware announced a "a $2 million sale of its Attack Mitigation System (AMS) security solution to a leading Tier 1 wireless carrier in North America .. Radware's AMS solution will integrate the carrier's existing point security capabilities - such as firewall and proxy protection, signature-based intrusion prevention, anti-spam gateways and scrubbing center denial of service mitigation - into an holistic attack mitigation system."

"Radware's AMS is a real-time network and application attack mitigation solution that protects the application infrastructure against network and application downtime, application vulnerability exploitation, malware spread, information theft, Web service attacks and Web defacement. It contains a protection layer with security modules including denial-of-service (DoS) protection, network behavioral analysis (NBA), intrusion prevention system (IPS), reputation engine and Web application firewall (WAF) to fully safeguard networks, servers and applications against known and emerging network security threats"

See "Radware to Deliver Attack Mitigation System Solution To Tier 1 Wireless Carrier in North America" - here.

See also "[Juniper] Anomaly Detection and DPI Defend Against Application-Layer DDoS"- here and "NetScout: "Outages at NTT, AT&T and Verizon could have been detected and averted" - here.

Thursday, August 18, 2011

[Juniper] Anomaly Detection and DPI Defend Against Application-Layer DDoS

  
Raju Manthena, from Juniper's Security Services and Research team published a new article to Juniper's "Networking & Security Now" blog about "Application-layer Denial of Service" (here).

"Sony PlayStation Network experienced Distributed Denial of Service (DDoS) attacks that compromised millions of user accounts and resulted in 3 weeks of outage [see "PlayStation Network Outage the Worst Service Outage Ever?" - here - and chart below] .. Application-layer DoS exploits vulnerabilities in application software such as buffer overflows or null pointer dereferences in database or web server software. These attacks can appear to be legitimate application-layer traffic and are not easily detectable. Although a single or slow application request rate may trigger DoS, DDoS involves engaging large botnets (with millions of nodes) to send minimal per-client traffic that is large enough to overwhelm and exhaust application resources".



According to Arbor Networks' "Network Infrastructure Security Report" (here, registration required) - "Application-Layer DDoS Attacks Are Increasing in Sophistication and Operational Impact .. IDC and mobile/fixed wireless operators in particular are reporting significant outages, increased OPEX, customer churn and revenue loss due to application-layer DDoS attacks. These attacks are targeting both their customers and their own ancillary supporting services, such as DNS, Web portals, etc" (see chart).

Back to Juniper's article - "The ability to defend against application-layer DoS attacks and implementing an optimal mitigation solution relies on understanding the nature of the attack and the objectives of the attacker. Using information collected by Network/Application Anomaly Detection, Deep Packet Inspection (DPI/IPS), and Network Access Control systems, it may be possible to identify attack traffic.  Depending on the nature of attack, several mitigation strategies need to be considered"


Tuesday, March 8, 2011

NetScout: "Outages at NTT, AT&T and Verizon could have been detected and averted"

 
James Heath interviews Steven Shalita (picture), VP of Marketing, NetScout to B/OSS about "network behavioral analysis (NBA), and why NBA is becoming necessary to provide security and service assurance in IP networks".

See "LTE Monitoring: The Virtue of Combining Service and Security Assurance"  - here.

Some quotes:
  • "For a mobile network the No. 1 location of problem generation is DNS, whether it be DNS flooding or other types of performance issues. So operators typically start in that area, in the authentication or federation layer, which includes DNS, the AAA server and the HLR"
      
  • "Carriers are pretty guarded about sharing information like this and unfortunately all my anecdotes would be too specific and identify a carrier. Yet if you look at the most spectacular telecom outages as example – and I am not saying we detected any of them – these outages at NTT, AT&T and Verizon all started out as little things that could have been detected and averted"
See also:
  • Arbor Networks: Mobile Operators Lack Visibility and Control over Security threats - here
  • Recent Cyber Monday DDoS Attacks "revealed a sophisticated and motivated attacker” - here
  • Yankee Group Prediction: A Denial-of-Service Attack Will Take a 4G Network Down - here