Top Banner
© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved. Prasad Kalyanaraman, VP AWS Andrew Thomas, Director AWS December 1, 2016 SAC322 NEW LAUNCH! AWS Shield Managed DDoS Protection
73

NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Jan 06, 2017

Download

Technology

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

© 2016, Amazon Web Services, Inc. or its Affiliates. All rights reserved.

Prasad Kalyanaraman, VP AWS

Andrew Thomas, Director AWS

December 1, 2016

SAC322

NEW LAUNCH!

AWS ShieldManaged DDoS Protection

Page 2: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

What to expect from this session

What is DDoS?

Challenges customers face mitigating DDoS attacks

AWS approach to DDoS Protection

Introducing AWS Shield, a managed DDoS protection service

Demo

Page 3: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

What is DDoS?

DDoS 101

Page 4: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

What is DDoS?

Distributed Denial Of Service

Page 5: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Types of DDoS attacks

Page 6: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Types of DDoS attacks

Volumetric DDoS attacks

Congest networks by flooding them with

more traffic than they are able to handle

(e.g., UDP reflection attacks)

Page 7: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Types of DDoS attacks

State-exhaustion DDoS attacks

Abuse protocols to stress systems like

firewalls, IPS, or load balancers (e.g., TCP

SYN flood)

Page 8: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Types of DDoS attacks

Application-layer DDoS attacks

Use well-formed but malicious requests to

circumvent mitigation and consume

application resources (e.g., HTTP GET, DNS

query floods)

Page 9: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

DDoS attack trends

Volumetric State exhaustion Application layer

65%Volumetric

17%State exhaustion

18%Application layer

Page 10: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Volumetric State exhaustion Application layer

65%Volumetric

17%State exhaustion

18%Application layer

DDoS attack trends

SSDP reflection attacks are very

common

Reflection attacks have clear signatures,

but can consume available bandwidth.

Page 11: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Volumetric State exhaustion Application layer

65%Volumetric

17%State exhaustion

18%Application layer

DDoS attack trends

Other common volumetric attacks:

NTP reflection, DNS reflection,

Chargen reflection, SNMP reflection

Page 12: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Volumetric State exhaustion Application layer

65%Volumetric

17%State exhaustion

18%Application layer

DDoS attack trends SYN floods can look like real

connection attempts

And on average, they are larger in

volume. They can prevent real users

from establishing connections.

Page 13: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Volumetric State exhaustion Application layer

65%Volumetric

17%State exhaustion

18%Application layer

DDoS attack trends

DNS query floods are real DNS requests

These can continue for hours and exhaust the

available resources of the DNS server.

Page 14: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Volumetric State exhaustion Application layer

65%Volumetric

17%State exhaustion

18%Application layer

DDoS attack trends

Other common application

layer attacks:

HTTP GET flood, Slowloris

Page 15: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Challenges in mitigating DDoS attacks

Page 16: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Challenges in mitigating DDoS attacks

Difficult to enable

Complex set-up Provision bandwidth capacity

Application re-architecture

Page 17: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Challenges in mitigating DDoS attacks

Manual involvement

Operator involvement to

initiate mitigation

Re-route traffic via distant

scrubbing location

Increased time to

mitigate

Traditional

Datacenter

Page 18: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Challenges in mitigating DDoS attacks

Traffic re-routing = Increased latency for usersTraditional

Datacenter

Page 19: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Challenges in mitigating DDoS attacks

Expensive to use

Page 20: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS approach to DDoS protection

Page 21: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

At AWS, our goal has always been to …

Remove undifferentiated

heavy lifting

Automatically protected

against common attacks

Ensure availability

AWS services are highly

available

Page 22: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

DDoS protections built into AWS

Integrated into the AWS global infrastructure

Always-on, fast mitigation without external routing

Redundant Internet connectivity in AWS data centers

Page 23: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

DDoS protections built into AWS

Protection against most common

infrastructure attacks

SYN/ACK Floods, UDP Floods,

Refection attacks etc.

No additional cost

DDoS mitigation

systems

DDoS Attack

Users

Page 24: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Customers keep asking …

Does AWS protect me

from DDoS attacks?

What about large

DDoS attacks?

How can I get visibility

when I get attacked?

Does AWS protect

me from application

layer attacks?

Scaling for

DDoS attacks

is expensive.

I want to talk to

DDoS experts.

Page 25: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS ShieldA Managed DDoS Protection Service

Page 26: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield

Standard Protection Advanced Protection

Available to ALL AWS customers at

No Additional CostPaid service that provides additional

protections, features and benefits.

Page 27: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield

AWS IntegrationDDoS protection

without infrastructure

changes

AffordableDon’t force unnecessary

trade-offs between cost and

availability

FlexibleCustomize protections

for your applications

Always-On Detection

and MitigationMinimize impact on application

latency

Four key pillars…

Page 28: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield Standard

Page 29: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield Standard

Layer 3/4 protection

Automatic detection & mitigation

Protection from most common

attacks (SYN/UDP Floods, Reflection

Attacks, etc.)

Built into AWS services

Layer 7 protection

AWS WAF for Layer 7 DDoS attack

mitigation

Self-service & pay-as-you-go

Page 30: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield Standard

Better protection than ever for your applications running on AWS

• Improved mitigations using proprietary BlackWatch systems

• Additional mitigation capacity

• Commitment to continuously improve detection and mitigation

• Still at no additional cost

Page 31: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield AdvancedManaged DDoS Protection

Page 32: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield Advanced

Application Load Balancer Classic Load Balancer Amazon CloudFront Amazon Route 53

Available today on …

Page 33: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield Advanced

Available today in …

US East (N. Virginia) us-east-1

US West (Oregon) us-west-2

EU (Ireland) eu-west-1

Asia Pacific (Tokyo) ap-northeast-1

Page 34: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield Advanced

Announcing AWS WAF for Application Load Balancer

Application Load BalancerAWS WAF

Valid users

Attackers

X

Page 35: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield Advanced

Always-on monitoring &

detection

Advanced L3/4 & L7 DDoS

protection

Attack notification and

reporting

24x7 access to DDoS

Response Team

AWS bill protection

Page 36: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield Advanced

Always-on monitoring &

detection

Advanced L3/4 & L7 DDoS

protection

Attack notification and

reporting

24x7 access to DDoS

Response Team

AWS bill protection

Page 37: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield Advanced

Always-on monitoring &

detection

Advanced L3/4 & L7 DDoS

protection

Attack notification and

reporting

24x7 access to DDoS

Response Team

AWS bill protection

Page 38: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield Advanced

Always-on monitoring &

detection

Advanced L3/4 & L7 DDoS

protection

Attack notification and

reporting

24x7 access to DDoS

Response Team

AWS bill protection

Page 39: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield Advanced

Always-on monitoring &

detection

Advanced L3/4 & L7 DDoS

protection

Attack notification and

reporting

24x7 access to DDoS

Response Team

AWS bill protection

Page 40: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield Advanced

Always-on monitoring &

detection

Advanced L3/4 & L7 DDoS

protection

Attack notification and

reporting

24x7 access to DDoS

Response Team

AWS bill protection

Page 41: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Always-on monitoring and detection

Network flow monitoring Application traffic monitoring

Page 42: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Always-on monitoring and detection

Signature based detectionHeuristics-based

anomaly detectionBaselining

Page 43: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Always-on monitoring and detection

Detects anomalies based on attributes such as:

• Source IP

• Source ASN

• Traffic levels

• Validated sources

Heuristics-based anomaly detection

Page 44: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Always-on monitoring and detection

Continuously baselining normal traffic patterns

• HTTP Requests per second

• Source IP Address

• URLs

• User-Agents

Baselining

Page 45: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield Advanced

Always-on monitoring &

detection

Advanced L3/4 & L7 DDoS

protection

Attack notification and

reporting

24x7 access to DDoS

Response Team

AWS bill protection

Page 46: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Advanced DDoS protection

Layer 7

application

protection

Layer 3/4

infrastructure

protection

Page 47: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Advanced DDoS protection

Layer 7

application

protection

Layer 3/4

infrastructure

protection

Page 48: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Layer 3/4 infrastructure protection

Advanced mitigation techniques

Deterministic

filtering

Traffic prioritization

based on scoring

Advanced routing policies

Page 49: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Layer 3/4 infrastructure protection

Automatically filters malformed TCP

packets

• IP checksum

• TCP valid flags

• UDP payload length

• DNS request validation

Deterministic filtering

Page 50: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Low suspicion attributes

Normal packet or request header

Traffic composition and volume is typical

given its source

Traffic valid for its destination

High suspicion attributes

• Suspicious packet or request headers

• Entropy in traffic by header attribute

• Entropy in traffic source and volume

• Traffic source has a poor reputation

• Traffic invalid for its destination

• Request with cache-busting attributes

Layer 3/4 infrastructure protection

Traffic prioritization based on scoring

Page 51: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Layer 3/4 infrastructure protection

• Inline inspection and scoring

• Preferentially discard lower priority (attack) traffic

• False positives are avoided and legitimate viewers are protected

Traffic prioritization based on scoring

High-suspicion

packets dropped

Low-suspicion

packets retained

Page 52: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Layer 3/4 infrastructure protection

• Distributed scrubbing and bandwidth

capacity

• Automated routing policies to absorb large

attacks

• Manual traffic engineering

Advanced routing policies

Page 53: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Layer 3/4 infrastructure protection

• Advanced routing capabilities

• Additional mitigation capacity

Additional protections against larger and more sophisticated attacks

Page 54: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Advanced DDoS protection

Layer 7

application

protection

Layer 3/4

infrastructure

protection

Page 55: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS WAF – Layer 7 application protection

Web traffic filtering

with custom rules

Malicious request

blocking

Active monitoring

and tuning

Page 56: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS WAF – Layer 7 application protection

Three modes of operation

Self-service Engage DDoS experts Proactive DRT engagement

Page 57: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS WAF – Layer 7 application protection

AWS WAF included at no additional

cost

Self-service

Page 58: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS WAF – Layer 7 application protection

1. You engage the AWS DDoS Response Team (DRT)

2. DRT triages attack

3. DRT assists you with creating AWS WAF rules

Engage DDoS experts

Page 59: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS WAF – Layer 7 application protection

1. Always-on monitoring engages the AWS DDoS

Response Team (DRT)

2. DRT proactively triages DDoS attack

3. DRT creates AWS WAF rules (prior

authorization required)

Proactive DRT engagement

Page 60: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield Advanced

Always-on monitoring &

detection

Advanced L3/4 & L7 DDoS

protection

Attack notification and

reporting

24x7 access to DDoS

Response Team

AWS bill protection

Page 61: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Attack notification and reporting

Attack monitoring

and detection

• Real-time notification of attacks via Amazon CloudWatch

• Near real-time metrics and packet captures for attack forensics

• Historical attack reports

Page 62: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield Advanced

Always-on monitoring &

detection

Advanced L3/4 & L7 DDoS

protection

Attack notification and

reporting

24x7 access to DDoS

Response Team

AWS bill protection

Page 63: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

24x7 access to DDoS Response Team

Critical and urgent priority cases are

answered quickly and routed directly

to DDoS experts

Complex cases can be escalated to

the AWS DDoS Response Team

(DRT), who have deep experience in

protecting AWS as well as

Amazon.com and its subsidiaries

Page 64: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

24x7 access to DDoS Response Team

Before Attack

Proactive consultation and

best practice guidance

During Attack

Attack mitigation

After Attack

Post-mortem

analysis

Page 65: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS Shield Advanced

Always-on monitoring &

detection

Advanced L3/4 & L7 DDoS

protection

Attack notification and

reporting

24x7 access to DDoS

Response Team

AWS bill protection

Page 66: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

AWS cost protection

AWS absorbs scaling cost due to DDoS attack

• Amazon CloudFront

• Elastic Load Balancer

• Application Load Balancer

• Amazon Route 53

Page 67: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Demo & Getting Started

Page 68: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

• No commitment

• No additional cost

AWS DDoS Shield: Pricing

• 1 year subscription commitment

• Monthly base fee: $3,000

• Data transfer fees

Data Transfer Price ($ per GB)

CloudFront ELB

First 100 TB $0.025 0.050

Next 400 TB $0.020 0.040

Next 500 TB $0.015 0.030

Next 4 PB $0.010 Contact Us

Above 5 PB Contact Us Contact Us

Standard Protection Advanced Protection

Page 69: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

For protection against most

common DDoS attacks, and

access to tools and best

practices to build a DDoS

resilient architecture on AWS.

AWS DDoS Shield: How to choose

For additional protection against

larger and more sophisticated

attacks, visibility into attacks,

AWS cost protection, Layer 7

mitigations, and 24X7 access to

DDoS experts for complex cases.

Standard Protection Advanced Protection

Page 70: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

You get it automatically

AWS Shield: Getting started

Enable via the AWS Console

Standard Protection Advanced Protection

Page 71: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Thank you!

Page 72: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Related sessions

SAC316

Security Automation: Spend Less Time Securing

Your Applications Thu 4:00pm

NET403Elastic Load Balancing Deep Dive and Best

PracticesThu 3:30pm

LD118AWS WAF Preconfigured Protections and Security

Automation (10-minute live demo)Thu 2:10pm

SEC310Mitigating DDoS Attacks on AWS: Five Vectors and

Four Use Cases[Video]

Page 73: NEW LAUNCH! AWS Shield—A Managed DDoS Protection Service

Remember to complete

your evaluations!