YOU ARE DOWNLOADING DOCUMENT

Please tick the box to continue:

Transcript
Page 1: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Trey Guinn Solution Engineer, CloudFlare

www.cloudflare.com

DDoS 101

Page 2: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Distributed Denial of Service

!

An attack coming from all many locations which overwhelms your resources and prevents you from serving legitimate

customers.

Page 3: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Fake Pizza Orders

Page 4: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Variety of Attacks

Volumetric

Protocol Attacks

Application Attacks

Page 5: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Real Life Example

Page 6: CloudFlare DDoS attacks 101: what are they and how to protect your site?
Page 7: CloudFlare DDoS attacks 101: what are they and how to protect your site?
Page 8: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Wednesday, March 20 ~75Gbps attack

Page 9: CloudFlare DDoS attacks 101: what are they and how to protect your site?

100Gbps Magic ceiling in DDoS attacks

Page 10: CloudFlare DDoS attacks 101: what are they and how to protect your site?

March 24 – March 25 Peaks of the attack reached at least 309Gbps

Page 11: CloudFlare DDoS attacks 101: what are they and how to protect your site?

dig ANY isc.org @63.217.84.76 +edns=0 +notcp +bufsize=4096

Page 12: CloudFlare DDoS attacks 101: what are they and how to protect your site?

64-byte query

Page 13: CloudFlare DDoS attacks 101: what are they and how to protect your site?

$ dig ANY isc.org @63.217.84.76 +edns=0 +notcp +bufsize=4096 !

Page 14: CloudFlare DDoS attacks 101: what are they and how to protect your site?

3,363-byte response

Page 15: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Amplification

Page 16: CloudFlare DDoS attacks 101: what are they and how to protect your site?

50x Amplification factor

Page 17: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Attack Amplification !

DNS - 50 x NTP - 200x

Coming: SNMP - 650x

Page 18: CloudFlare DDoS attacks 101: what are they and how to protect your site?

UDP = no handshake

Page 19: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Problem Ingredients: Networks that allows

source IP spoofing +

Servers that reply to “non-customers”

Page 20: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Good networks don’t let packets originate from IPs they don’t own (BCP38)

Page 21: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Not all networks are good

Page 22: CloudFlare DDoS attacks 101: what are they and how to protect your site?

How common are these ingredients?

Page 23: CloudFlare DDoS attacks 101: what are they and how to protect your site?

28 million open resolvers

Page 24: CloudFlare DDoS attacks 101: what are they and how to protect your site?

24.6% networks allow spoofing

Page 25: CloudFlare DDoS attacks 101: what are they and how to protect your site?

10s of Millions Open NTP DNS servers

Page 26: CloudFlare DDoS attacks 101: what are they and how to protect your site?

1 attacker’s laptop controlling 5–7 compromised servers on 3 networks that allowed spoofing of 9Gbps DNS requests to 0.1% of open resolvers resulted in 300Gbps+ of DDoS attack traffic.

+ + + +

Page 27: CloudFlare DDoS attacks 101: what are they and how to protect your site?

How did we stop it?

Page 28: CloudFlare DDoS attacks 101: what are they and how to protect your site?
Page 29: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Anycast

Page 30: CloudFlare DDoS attacks 101: what are they and how to protect your site?
Page 31: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Inherently “dilutes” the attack

Page 32: CloudFlare DDoS attacks 101: what are they and how to protect your site?

300Gbps 25 Anycasted PoPs 12 Gbps/PoP

÷

Page 33: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Make sure you’re not part of the problem…

Page 34: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Are you running open DNS resolvers?

Page 35: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Are you running open NTP servers?

Page 36: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Implement BCP38 (uRPF)

Page 37: CloudFlare DDoS attacks 101: what are they and how to protect your site?

Trey Guinn Solution Engineer

www.cloudflare.com


Related Documents