SlideShare ist ein Scribd-Unternehmen logo
1 von 16
Downloaden Sie, um offline zu lesen
Monitoring Your Network During a
DDoS Attack
Archana Kesavan, Product Marketing Manager
1
About ThousandEyes
ThousandEyes delivers visibility into every network your organization relies on.
Founded by network
experts; strong
investor backing
Relied on for
critical operations by
leading enterprises
Recognized as
an innovative
new approach
31 Fortune 500
5 top 5 SaaS Companies
4 top 6 US Banks
2
• Saturate bandwidth
of the target.
• Amplification
attacks.
• Easy to generate.
• Examples: TCP
Flood, NTP
Amplification
Distributed Denial of Service
• Target Layer 7 of
the protocol stack
• Monopolize
application
transactions
• Sophisticated &
challenging
• Examples: HTTP
Flood, Attack on
DNS
Volumetric Application
• Exploit a Layer 3 or
Layer 4 weakness
• Consume
processing capacity
of the target
• Examples: Syn
Flood, Ping of
Death
Protocol
3
Impact of DDoS Attacks
• The target of the attack.
– Attacking critical infrastructure
can bring down the entire
Internet
– Load-balancer/firewalls
• The type of attack.
• Network architecture
• Anycast networks are more
resilient
• Redundancy
• Mitigation strategies
Well, it depends!
4
Visibility Across Critical Services
Enterprise
Agents
Branch
Data
Center
Hosting / SaaS
Provider
ConsumersCloud
Agents
Internet
Visibility across
ISPs, DNS, online
DDOS mitigation,
and corporate
networks
5
Mitigation Strategy 1:On-Premise
Chicago, IL
YourBank.comLondon
Tokyo
Atlanta
Portland, OR
Sydney
Appliance at network edge
monitors and mitigates
application-layer attacks
Internet EnterpriseOn-Premises DDoS
Mitigation Appliance
6
Mitigation Strategy 2: ISP Collaboration
Chicago, IL
YourBank.comLondon
Tokyo
Atlanta
Portland, OR
Sydney
Attack traffic is routed by ISPs to a
remote-triggered black hole
Internet EnterpriseRemote-Triggered
Black Hole
ISP 1
ISP 2
7
Mitigation Strategy 3: Cloud-based
Chicago, IL
London
Tokyo
Atlanta
Portland, OR
Sydney
Traffic is rerouted, using DNS or
BGP, to cloud-based scrubbing
centers and ‘real’ traffic is routed
back to your network
Internet EnterpriseScrubbing
Center
8
Monitor For DDoS Attacks
Global Availability Layered Error Detection
Identify Bottlenecks Mitigation Performance
9
Demo
10
Understand Global Availability and Faults
Availability dip to 0%
Global Availability Issues
Problems at
TCP
connection
and HTTP
receive
phases
11
Understand Network Connectivity Metrics
Loss,
latency &
jitter
Loss during the
height of attack
12
Find Congested Nodes and Links
Bank website
under attackPacket loss in
upstream ISPs
High packet
loss from all
testing points
13
Monitor and Visualize Mitigation Performance
Highlighted nodes indicate
mitigation vendor networks
Search for specific networks
Quickly select interesting
data points
14
Confirm Mitigation Handoff Using BGP
New Autonomous
System (Verisign)
Prior
autonomous
system (HSBC)
Mitigation vendor in the forefront of the
attack by altering BGP routes to
Bank’s prefix under attack
15
See what you’re missing.
Watch the webinar
www.thousandeyes.com/webinars/ddos

Weitere ähnliche Inhalte

Andere mochten auch

Automatic generation of slide
Automatic generation of slide Automatic generation of slide
Automatic generation of slide
KedarBiradar
 
No te rindas antes de empezar la guerra
No te rindas antes de empezar la guerraNo te rindas antes de empezar la guerra
No te rindas antes de empezar la guerra
Juan Dv
 
FC Shakhtar: Digital marketing in Shakhtar (Yuriy Sviridov)
FC Shakhtar: Digital marketing in Shakhtar (Yuriy Sviridov)FC Shakhtar: Digital marketing in Shakhtar (Yuriy Sviridov)
FC Shakhtar: Digital marketing in Shakhtar (Yuriy Sviridov)
ResultSportsUkraine
 

Andere mochten auch (12)

Roadhouse seats
Roadhouse seatsRoadhouse seats
Roadhouse seats
 
"La super-pirámide"
"La super-pirámide""La super-pirámide"
"La super-pirámide"
 
Automatic generation of slide
Automatic generation of slide Automatic generation of slide
Automatic generation of slide
 
Yl essential-oils
Yl essential-oilsYl essential-oils
Yl essential-oils
 
Using Data to Determine Where to Build a New Data Center at Shutterstock from...
Using Data to Determine Where to Build a New Data Center at Shutterstock from...Using Data to Determine Where to Build a New Data Center at Shutterstock from...
Using Data to Determine Where to Build a New Data Center at Shutterstock from...
 
Executive branding implementation utilizing virtual workforce/virtual assistants
Executive branding implementation utilizing virtual workforce/virtual assistantsExecutive branding implementation utilizing virtual workforce/virtual assistants
Executive branding implementation utilizing virtual workforce/virtual assistants
 
No te rindas antes de empezar la guerra
No te rindas antes de empezar la guerraNo te rindas antes de empezar la guerra
No te rindas antes de empezar la guerra
 
Harmonization of inter-cultural inter-religious and inter-ethnic relations: t...
Harmonization of inter-cultural inter-religious and inter-ethnic relations: t...Harmonization of inter-cultural inter-religious and inter-ethnic relations: t...
Harmonization of inter-cultural inter-religious and inter-ethnic relations: t...
 
FC Shakhtar: Digital marketing in Shakhtar (Yuriy Sviridov)
FC Shakhtar: Digital marketing in Shakhtar (Yuriy Sviridov)FC Shakhtar: Digital marketing in Shakhtar (Yuriy Sviridov)
FC Shakhtar: Digital marketing in Shakhtar (Yuriy Sviridov)
 
пожар
пожарпожар
пожар
 
Visualizing the Path of InteropNet and Beyond
Visualizing the Path of InteropNet and BeyondVisualizing the Path of InteropNet and Beyond
Visualizing the Path of InteropNet and Beyond
 
Managing Network Performance Within and Beyond Your Enterprise
Managing Network Performance Within and Beyond Your EnterpriseManaging Network Performance Within and Beyond Your Enterprise
Managing Network Performance Within and Beyond Your Enterprise
 

Mehr von ThousandEyes

Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
ThousandEyes
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
ThousandEyes
 

Mehr von ThousandEyes (20)

How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected WorkerHow To Troubleshoot Collaboration Apps for the Modern Connected Worker
How To Troubleshoot Collaboration Apps for the Modern Connected Worker
 
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for PartnersEnhancing Worker Digital Experience: A Hands-on Workshop for Partners
Enhancing Worker Digital Experience: A Hands-on Workshop for Partners
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyesAssure Ecommerce and Retail Operations Uptime with ThousandEyes
Assure Ecommerce and Retail Operations Uptime with ThousandEyes
 
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyesHow to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
How to Effectively Monitor SD-WAN and SASE Environments with ThousandEyes
 
New ThousandEyes Product Features and Release Highlights: March 2024
New ThousandEyes Product Features and Release Highlights: March 2024New ThousandEyes Product Features and Release Highlights: March 2024
New ThousandEyes Product Features and Release Highlights: March 2024
 
EMEA What is ThousandEyes? Webinar
EMEA What is ThousandEyes? WebinarEMEA What is ThousandEyes? Webinar
EMEA What is ThousandEyes? Webinar
 
Outage Analysis: March 5th/6th 2024 Meta, Comcast, and LinkedIn
Outage Analysis: March 5th/6th 2024 Meta, Comcast, and LinkedInOutage Analysis: March 5th/6th 2024 Meta, Comcast, and LinkedIn
Outage Analysis: March 5th/6th 2024 Meta, Comcast, and LinkedIn
 
Assure Patient and Clinician Digital Experiences with ThousandEyes for Health...
Assure Patient and Clinician Digital Experiences with ThousandEyes for Health...Assure Patient and Clinician Digital Experiences with ThousandEyes for Health...
Assure Patient and Clinician Digital Experiences with ThousandEyes for Health...
 
AMER Introduction to ThousandEyes Webinar
AMER Introduction to ThousandEyes WebinarAMER Introduction to ThousandEyes Webinar
AMER Introduction to ThousandEyes Webinar
 
New ThousandEyes Product Features and Release Highlights: February 2024
New ThousandEyes Product Features and Release Highlights: February 2024New ThousandEyes Product Features and Release Highlights: February 2024
New ThousandEyes Product Features and Release Highlights: February 2024
 
The Top Outages of 2023: Analyses and Takeaways
The Top Outages of 2023: Analyses and TakeawaysThe Top Outages of 2023: Analyses and Takeaways
The Top Outages of 2023: Analyses and Takeaways
 
Enhancing SaaS Performance: A Hands-on Workshop for Partners
Enhancing SaaS Performance: A Hands-on Workshop for PartnersEnhancing SaaS Performance: A Hands-on Workshop for Partners
Enhancing SaaS Performance: A Hands-on Workshop for Partners
 
The Top Outages of 2023: Analysis and Takeaways
The Top Outages of 2023: Analysis and TakeawaysThe Top Outages of 2023: Analysis and Takeaways
The Top Outages of 2023: Analysis and Takeaways
 
The Top Outages of 2023: Analysis and Takeaways
The Top Outages of 2023: Analysis and TakeawaysThe Top Outages of 2023: Analysis and Takeaways
The Top Outages of 2023: Analysis and Takeaways
 
ThousandEyes Enterprise Digital Workshop - Spanish
ThousandEyes Enterprise Digital Workshop - SpanishThousandEyes Enterprise Digital Workshop - Spanish
ThousandEyes Enterprise Digital Workshop - Spanish
 
ThousandEyes Enterprise Digital Workshop - German
ThousandEyes Enterprise Digital Workshop - GermanThousandEyes Enterprise Digital Workshop - German
ThousandEyes Enterprise Digital Workshop - German
 
ThousandEyes Enterprise Digital Workshop
ThousandEyes Enterprise Digital WorkshopThousandEyes Enterprise Digital Workshop
ThousandEyes Enterprise Digital Workshop
 

Kürzlich hochgeladen

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Kürzlich hochgeladen (20)

Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
Apidays New York 2024 - The Good, the Bad and the Governed by David O'Neill, ...
 
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu SubbuApidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
Apidays Singapore 2024 - Modernizing Securities Finance by Madhu Subbu
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
Strategies for Unlocking Knowledge Management in Microsoft 365 in the Copilot...
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot ModelNavi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Navi Mumbai Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Ransomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdfRansomware_Q4_2023. The report. [EN].pdf
Ransomware_Q4_2023. The report. [EN].pdf
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Corporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptxCorporate and higher education May webinar.pptx
Corporate and higher education May webinar.pptx
 
DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 

How to Monitor Your Network During a DDoS Attack

  • 1. Monitoring Your Network During a DDoS Attack Archana Kesavan, Product Marketing Manager
  • 2. 1 About ThousandEyes ThousandEyes delivers visibility into every network your organization relies on. Founded by network experts; strong investor backing Relied on for critical operations by leading enterprises Recognized as an innovative new approach 31 Fortune 500 5 top 5 SaaS Companies 4 top 6 US Banks
  • 3. 2 • Saturate bandwidth of the target. • Amplification attacks. • Easy to generate. • Examples: TCP Flood, NTP Amplification Distributed Denial of Service • Target Layer 7 of the protocol stack • Monopolize application transactions • Sophisticated & challenging • Examples: HTTP Flood, Attack on DNS Volumetric Application • Exploit a Layer 3 or Layer 4 weakness • Consume processing capacity of the target • Examples: Syn Flood, Ping of Death Protocol
  • 4. 3 Impact of DDoS Attacks • The target of the attack. – Attacking critical infrastructure can bring down the entire Internet – Load-balancer/firewalls • The type of attack. • Network architecture • Anycast networks are more resilient • Redundancy • Mitigation strategies Well, it depends!
  • 5. 4 Visibility Across Critical Services Enterprise Agents Branch Data Center Hosting / SaaS Provider ConsumersCloud Agents Internet Visibility across ISPs, DNS, online DDOS mitigation, and corporate networks
  • 6. 5 Mitigation Strategy 1:On-Premise Chicago, IL YourBank.comLondon Tokyo Atlanta Portland, OR Sydney Appliance at network edge monitors and mitigates application-layer attacks Internet EnterpriseOn-Premises DDoS Mitigation Appliance
  • 7. 6 Mitigation Strategy 2: ISP Collaboration Chicago, IL YourBank.comLondon Tokyo Atlanta Portland, OR Sydney Attack traffic is routed by ISPs to a remote-triggered black hole Internet EnterpriseRemote-Triggered Black Hole ISP 1 ISP 2
  • 8. 7 Mitigation Strategy 3: Cloud-based Chicago, IL London Tokyo Atlanta Portland, OR Sydney Traffic is rerouted, using DNS or BGP, to cloud-based scrubbing centers and ‘real’ traffic is routed back to your network Internet EnterpriseScrubbing Center
  • 9. 8 Monitor For DDoS Attacks Global Availability Layered Error Detection Identify Bottlenecks Mitigation Performance
  • 11. 10 Understand Global Availability and Faults Availability dip to 0% Global Availability Issues Problems at TCP connection and HTTP receive phases
  • 12. 11 Understand Network Connectivity Metrics Loss, latency & jitter Loss during the height of attack
  • 13. 12 Find Congested Nodes and Links Bank website under attackPacket loss in upstream ISPs High packet loss from all testing points
  • 14. 13 Monitor and Visualize Mitigation Performance Highlighted nodes indicate mitigation vendor networks Search for specific networks Quickly select interesting data points
  • 15. 14 Confirm Mitigation Handoff Using BGP New Autonomous System (Verisign) Prior autonomous system (HSBC) Mitigation vendor in the forefront of the attack by altering BGP routes to Bank’s prefix under attack
  • 16. 15 See what you’re missing. Watch the webinar www.thousandeyes.com/webinars/ddos

Hinweis der Redaktion

  1. H