High-performance, multi-use DDoS security for data center operators and co-location

happycorn(36)
Published in
#ddos
Words
1295
Reading
6 min
Listen
Play
9y

Businesses use data center operators for better predictability of operations, higher return on investment (ROI), and greater security than operating their own data centers. Data centers have the most valuable assets in the enterprise, so maintaining integrity and protecting businesses from service disruption is their top priority.

As reported in a recent report by the Ponemon Institute, an information security research institute, UPS system failures, human error, DDoS cybercrime, weather, climate control, generator failures and IT equipment failures are the data center downtime It is the main cause. Although two years ago, the DDoS attack was the last of the above list, but now it is in the third place, and if there are five outages, one of them is the cause.

DDoS attacks have increased in all industries, due to simple activation, low cost and significant impact. However, data center environments with multi-tenant rich resources and multi-tenant characteristics all include the risks of individual tenants, so data centers are the main focus of DDoS attacks. DDoS attacks affect not only the target customer, but also corrupt data centers and other tenants with incidental corruption. Data center downtime results in lost revenue and customer complaints, which translates into higher operating and marketing costs to attract new customers and retain existing customers. But the most important point is that there will be a devastating blow to the data center's brand and reputation.

problem

In a data center, each tenant's DDoS attack risks are summed together, leading to collateral damage, which in turn will cause the same damage to all tenants. DDoS protection is now the lifeblood of any data center, as DDoS attacks are the third leading cause of data center downtime and downtime.

solution

A10 Networks Thunder TPS is a high performance, versatile and simple configurable DDoS mitigation solution that provides automatic threat detection and mitigation and precise service protection policies.

result

Effective multi-vector attack defense with hardware acceleration

Automatic threat detection and mitigation with strategic traffic baseline settings

Elaborate attack detection and mitigation with scalability and simple configuration

flexible introduction; Simple integration with custom systems via standard and RESTful aXAPI

DDoS attacks that break down networks

DDoS attacks are becoming increasingly sophisticated as a combined large-scale and application-layer attack, attacking network bandwidth, server sockets, Web server threads, and CPU usage. Large-scale attacks saturate the primary carrier link to the data center and block access to all applications and services hosted in the data center. Application attacks are inherently excluded because they target specific hosts in a way that overloads application resources.

DDoS attacks are easy to attack and cost less, while size, speed, duration and complexity are evolving day by day. Internet service providers should be the first line of defense against large-scale attacks, but Internet service providers are less reliable. Firewalls, IPS, and load balancers, on the other hand, are effective tools for network integrity, but they are vulnerable to state-exhaustion attacks and are inadequate to detect and mitigate L7 attacks. As a data center operator, you should deploy a dedicated DDoS solution for self-defense to protect your network against large-scale and application-layer attacks targeting your network infrastructure.

Surprisingly, only a handful of data centers sell security services to customers over firewalls, SSL certificates, antivirus, VPN and alerts. However, data centers using dedicated DDoS solutions can differentiate their data centers and then increase revenue by managing the latest DDoS attack protection services for tenants.

A10 Networks Thunder TPS Solution

By introducing a scalable, high-performance solution at the edge of the data center, you can protect your customers' low-speed downstream links and servers and eliminate downtime. DDoS attacks will cost customers a significant loss and damage their brand and reputation. A10 Networks' Thunder TPS family provides high-performance DDoS security solutions with broad network security and mitigates these risks. It also ensures service availability for large and precise application attacks.

Thunder TPS is designed to provide the best performance in terms of bandwidth, packet throughput per second, connections per second, and black list capacity, and the infrastructure has enough headroom to handle other issues such as DDoS attacks and almost daily security deviations Is guaranteed. Due to the different nature of the network's design and policies, the introduction and integration of Thunder TPS is available in several options. With A10 Networks' aXAPI® REST-based API, third-party analytics systems can direct you to change the direction of specific traffic if needed. Likewise, an orchestration solution can provide a Thunder TPS system to the data center using individual policies for specific end users.

A10 Networks' aGalaxy (centralized management system) integrates management of multiple Thunder TPS devices to improve operational efficiency and cost. By consolidating all of your management tasks in one place, administrators can easily apply consistent policies across all devices. Administrators can check the status of a virtual server (in the case of Thunder TPS management, protected elements of the TPS) from the aGalaxy web user interface. Massive attacks that exceed network capacity can be handled by Verisign's DDoS protection services. Verisign's DDoS protection services are supported by 75 global branches and more than 2 Tbps of global capacity. Security-conscious and leading data center operators adopt Thunder TPS from A10 Networks to provide DDoS security solutions that can be managed directly to maintain service availability and increase revenues.

Feature Advantages of Thunder TPS Solution

Hardware-based mitigation of common infrastructure attack types
Thunder TPS can detect and mitigate up to 60 common attack vectors in hardware and has a powerful CPU for detecting and mitigating complex application layer attacks.

Intelligent threat detection and mitigation

The system has access to multiple Multi-Protocol Counter and behavior indicators, and can be used to detect abnormal conditions in the network by detecting the normal state of the network. Mitigation policies can gradually escalate suspicious traffic by gradually creating a strong countermeasure to minimize actual traffic degradation. DevOps can take advantage of scripts triggered by events to improve operational agility.

Apply granular bandwidth rate

Thunder TPS can track traffic speed per external connection. These traffic patterns are fairly predictable, so you can easily discover and mitigate unusual elements to ensure that they do not affect other customers.

Programmable policies

With access to system status and statistics, Thunder TPS simplifies the application of advanced applications and security policies. Regular expressions (regular expressions) and the Berkeley Packet Filter are the preferred tools for pattern matching.

Working with ThreatSTOP: A10 Networks' "Threat Intelligence Service"

This service combines and enhances trusted data from more than 30 security intelligence sources, allowing Thunder TPS to instantly recognize and block traffic flowing between well-known malicious sources.

A10 Networks' threat intelligence services offer the following benefits:

Protect your network from future threats

l> Block threats such as spam and phishing that are not related to DDoS attacks

l> Improved Thunder TPS efficiency

A threat intelligence network that continuously inspects and logs potential attackers allows customers to leverage global knowledge to block traffic from malicious Internet sites and offload Thunder TPS by identifying well-known bots and attack sources.

Programmable integration

Networks are very complex, requiring tight integration. There are multiple user-defined systems, and Thunder TPS can easily integrate the open network protocol standard and the aXAPI API.

Support for IPv6 functionality equally

With the rapid growth of IPv6 adoption, data center operators are confident that a secure security infrastructure is in place for all types of attacks that are performed over IPv4 or IPv6.

Summary: High-performance and versatile DDoS mitigation solutions for data center operators

A10 Networks provides DDoS mitigation solutions that are highly scalable and simple to configure for data center operators who need to address DDoS attacks that can cause incidental damage to the data center and maintain the integrity of the facility. The Thunder TPS family offers comprehensive tools to analyze traffic and minimize downtime with very low latency.

High-performance, multi-use DDoS security for data center operators... | Ecency