SlideShare a Scribd company logo
qrator.net 2016
qrator.net 2016
qrator.net 2016
Akamai: CDN vs DDoSM
aut-num: AS20940
as-name: AKAMAI-ASN1
org: ORG-AT1-RIPE
mnt-by: AKAM1-RIPE-MNT
mnt-routes: AKAM1-RIPE-MNT
qrator.net 2016
Akamai: CDN vs DDoSM
aut-num: AS20940
as-name: AKAMAI-ASN1
org: ORG-AT1-RIPE
mnt-by: AKAM1-RIPE-MNT
mnt-routes: AKAM1-RIPE-MNT
ASNumber: 32787
ASName: PROLEXIC-
TECHNOLOGIES-DDOS-
MITIGATION-NETWORK
Ref: https://whois.arin.net/
rest/asn/AS32787
qrator.net 2016
Akamai: CDN vs DDoSM
aut-num: AS20940
as-name: AKAMAI-ASN1
org: ORG-AT1-RIPE
mnt-by: AKAM1-RIPE-MNT
mnt-routes: AKAM1-RIPE-MNT
ASNumber: 32787
ASName: PROLEXIC-
TECHNOLOGIES-DDOS-
MITIGATION-NETWORK
Ref: https://whois.arin.net/
rest/asn/AS32787
https://www.peeringdb.com/asn/20940
qrator.net 2016
Akamai: CDN vs DDoSM
aut-num: AS20940
as-name: AKAMAI-ASN1
org: ORG-AT1-RIPE
mnt-by: AKAM1-RIPE-MNT
mnt-routes: AKAM1-RIPE-MNT
ASNumber: 32787
ASName: PROLEXIC-
TECHNOLOGIES-DDOS-
MITIGATION-NETWORK
Ref: https://whois.arin.net/
rest/asn/AS32787
https://www.peeringdb.com/asn/20940
qrator.net 2016
Akamai: CDN vs DDoSM
https://www.peeringdb.com/
asn/20940
qrator.net 2016
Akamai: CDN vs DDoSM
https://www.peeringdb.com/
asn/20940
qrator.net 2016
Akamai: CDN vs DDoSM
https://www.peeringdb.com/
asn/20940
https://www.peeringdb.com/
asn/32787
qrator.net 2016
Akamai: CDN vs DDoSM
https://www.peeringdb.com/
asn/20940
https://www.peeringdb.com/
asn/32787
qrator.net 2016
Akamai: CDN vs DDoSM
https://www.peeringdb.com/
asn/20940
https://www.peeringdb.com/
asn/32787
qrator.net 2016
Akamai: CDN vs DDoSM
https://radar.qrator.net/
as20940/
qrator.net 2016
Akamai: CDN vs DDoSM
https://radar.qrator.net/
as20940/
https://radar.qrator.net/
as32787/
qrator.net 2016
Akamai: CDN vs DDoSM
https://radar.qrator.net/
as20940/
https://radar.qrator.net/
as32787/
qrator.net 2016
15
CDN
qrator.net 2016
16
CDN
DDoS
DDoS
qrator.net 2016
17
CDN
DDoS
DDoS
qrator.net 2016
18
CDN
DDoS
DDoS
qrator.net 2016
19
DDoS
qrator.net 2016
20
qrator.net 2016
21
300 Mbps
30 Gbps
Amplification
qrator.net 2016
22
5 Gbps
500 Gbps
Amplification
qrator.net 2016
23
qrator.net 2016
• NTP
• DNS
• SNMP
• SSDP
• ICMP
24
• NetBIOS
• RIPv1
• PORTMAP
• CHARGEN
• QOTD
Vulnerable protocols
qrator.net 2016
• NTP
• DNS
• SNMP
• SSDP
• ICMP
25
• NetBIOS
• RIPv1
• PORTMAP
• CHARGEN
• QOTD
Amplification can be identified by source port
Vulnerable protocols
qrator.net 2016
BGP Flow Spec
qrator.net 2016
Wordpress Pingback
GET /whatever
User-Agent: WordPress/3.9.2;
http://example.com/;
verifying pingback
from 192.0.2.150
• 150 000 – 170 000
vulnerable servers
at once
• SSL/TLS-enabled
qrator.net 2016
Wordpress Pingback
GET /whatever
User-Agent: WordPress/3.9.2;
http://example.com/;
verifying pingback
from 192.0.2.150
• 150 000 – 170 000
vulnerable servers
at once
• SSL/TLS-enabled
Amplification can be identified by source port?
qrator.net 2016
Wordpress Pingback
GET /whatever
User-Agent: WordPress/3.9.2;
http://example.com/;
verifying pingback
from 192.0.2.150
• 150 000 – 170 000
vulnerable servers
at once
• SSL/TLS-enabled
Amplification can be identified by source port?
qrator.net 2016
BGP Flow Spec
qrator.net 2016
BGP Flow Spec
qrator.net 2016
Wordpress Pingback
• Millions of vulnerable servers
qrator.net 2016
Wordpress Pingback
• Millions of vulnerable servers
Drupal?
qrator.net 2016
Wordpress Pingback
• Millions of vulnerable servers
Joomla?
Drupal?
qrator.net 2016
Wordpress Pingback
• Millions of vulnerable servers
Joomla?
Drupal?
Mediawiki?
qrator.net 2016
Wordpress Pingback
• Millions of vulnerable servers
Joomla?
Drupal?
Sharepoint?
Mediawiki?
qrator.net 2016
Wordpress Pingback
• Millions of vulnerable servers
Joomla?
TinyCMS?
Drupal?
ModX?
Sharepoint?
Mediawiki?
qrator.net 2016
Wordpress Pingback
• Millions of vulnerable servers
Joomla?
TinyCMS?
Drupal?
ModX?
Sharepoint?
Mediawiki?
qrator.net 2016
Internet of Things
• Webcams, routers, smartphones, coffee makers
qrator.net 2016
Internet of Things
• Webcams, routers, smartphones, coffee makers
• Cheap hardware and software
qrator.net 2016
Internet of Things
• Webcams, routers, smartphones, coffee makers
• Cheap hardware and software
• (Little to) NO software updates
qrator.net 2016
Internet of Things
• Webcams, routers, smartphones, coffee makers
• Cheap hardware and software
• (Little to) NO software updates, including security fixes
qrator.net 2016
Internet of Things
• Webcams, routers, smartphones, coffee makers
• Cheap hardware and software
• (Little to) NO software updates,
•Default logins/passwords
including security fixes
qrator.net 2016
Internet of Things
• Webcams, routers, smartphones, coffee makers
• Cheap hardware and software
• (Little to) NO software updates,
•Default logins/passwords
•Full Internet access
including security fixes
qrator.net 2016
Internet of Things
• Webcams, routers, smartphones, coffee makers
• Cheap hardware and software
• (Little to) NO software updates,
•Default logins/passwords
•Full Internet access
including security fixes
qrator.net 2016
Internet of Things
• Network scanners are now powerful enough
to discover vulnerable IoT (good job, Flow Spec)
qrator.net 2016
Internet of Things
• Network scanners are now powerful enough
to discover vulnerable IoT (good job, Flow Spec)
=>
qrator.net 2016
Internet of Things
• Network scanners are now powerful enough
to discover vulnerable IoT (good job, Flow Spec)
=>
qrator.net 2016
Internet of Things
• Network scanners are now powerful enough
to discover vulnerable IoT (good job, Flow Spec)
=>
qrator.net 2016
Internet of Things
• Network scanners are now powerful enough
to discover vulnerable IoT (good job, Flow Spec)
=>
qrator.net 2016
qrator.net 2016
The Void
• To survive TCP- and HTTPS-based attacks,
one needs a session-capable and TLS-capable DPI
• To survive large botnets,
one needs a behavioral analysis and
correlation analysis built into that DPI
qrator.net 2016
The Void
• To survive TCP- and HTTPS-based attacks,
one needs a session-capable and TLS-capable DPI
• To survive large botnets,
one needs a behavioral analysis and
correlation analysis built into that DPI
• On the 1 Tbps bandwidth
qrator.net 2016
The Void
• Do not try to fix it yourself
• Reach out to your ISP ASAP
qrator.net 2016
The Cure
• ISP initiatives
qrator.net 2016
The Cure
• ISP initiatives
• Zero tolerance to vulnerable IoT
qrator.net 2016
The Cure
• ISP initiatives
• Zero tolerance to vulnerable IoT
• IPv6?
qrator.net 2016
Thank you, and good luck!
mailto: Artyom Gavrichenkov <ag@qrator.net>

More Related Content

PDF
Дмитрий Хоревич "Cloud native security with UAA \ Как защитить микросервисы с...
PPTX
Сергей Сверчков "Want to build a secure private cloud for IoT with high avail...
PDF
An approach for migrating enterprise apps into open stack
PDF
Orchestrating Shared Networks, Physical Load Balancer and DNS on CloudStack
PPTX
Reduce IT Spend with Software Load Balancing
PPTX
Improve App Performance & Reliability with NGINX Amplify
PPTX
What's new in NGINX Plus R9
PPTX
3 Ways to Automate App Deployments with NGINX
Дмитрий Хоревич "Cloud native security with UAA \ Как защитить микросервисы с...
Сергей Сверчков "Want to build a secure private cloud for IoT with high avail...
An approach for migrating enterprise apps into open stack
Orchestrating Shared Networks, Physical Load Balancer and DNS on CloudStack
Reduce IT Spend with Software Load Balancing
Improve App Performance & Reliability with NGINX Amplify
What's new in NGINX Plus R9
3 Ways to Automate App Deployments with NGINX

What's hot (20)

PPTX
Secure Your Apps with NGINX Plus and the ModSecurity WAF
PPTX
Nagios Conference 2014 - Scott Wilkerson - Log Monitoring and Log Management ...
PDF
Interop2018 contrail ContrailEnterpriseMulticloud
PDF
Practical tips and tricks for Apache Kafka messages integration | Francesco T...
PDF
NGINX Amplify: Monitoring NGINX with Advanced Filters and Custom Dashboards
PPTX
Simplify Microservices with the NGINX Application Platform
PPTX
MRA AMA Part 7: The Circuit Breaker Pattern
PDF
MRA AMA Part 8: Secure Inter-Service Communication
PPTX
How to Adopt Infrastructure as Code
PPTX
What's New in NGINX Plus R10?
PDF
Container network security
PPTX
Microservices and Container Management with NGINX Plus and Mesosphere DC/OS
PDF
Netflix Open Source Meetup Season 3 Episode 2
PPTX
ModSecurity and NGINX: Tuning the OWASP Core Rule Set - EMEA (Updated)
PDF
OSMC 2018 | Current State of Icinga by Bernd Erk
PDF
NGINX Microservices Reference Architecture: What’s in Store for 2019 – EMEA
PDF
Netflix Open Source Meetup Season 4 Episode 1
PDF
Orchestrating Shared Networks, Physical LB and DNS on Cloudstack
PPTX
NGINX, Istio, and the Move to Microservices and Service Mesh
PDF
Monitoring Highly Dynamic and Distributed Systems with NGINX Amplify
Secure Your Apps with NGINX Plus and the ModSecurity WAF
Nagios Conference 2014 - Scott Wilkerson - Log Monitoring and Log Management ...
Interop2018 contrail ContrailEnterpriseMulticloud
Practical tips and tricks for Apache Kafka messages integration | Francesco T...
NGINX Amplify: Monitoring NGINX with Advanced Filters and Custom Dashboards
Simplify Microservices with the NGINX Application Platform
MRA AMA Part 7: The Circuit Breaker Pattern
MRA AMA Part 8: Secure Inter-Service Communication
How to Adopt Infrastructure as Code
What's New in NGINX Plus R10?
Container network security
Microservices and Container Management with NGINX Plus and Mesosphere DC/OS
Netflix Open Source Meetup Season 3 Episode 2
ModSecurity and NGINX: Tuning the OWASP Core Rule Set - EMEA (Updated)
OSMC 2018 | Current State of Icinga by Bernd Erk
NGINX Microservices Reference Architecture: What’s in Store for 2019 – EMEA
Netflix Open Source Meetup Season 4 Episode 1
Orchestrating Shared Networks, Physical LB and DNS on Cloudstack
NGINX, Istio, and the Move to Microservices and Service Mesh
Monitoring Highly Dynamic and Distributed Systems with NGINX Amplify
Ad

Viewers also liked (15)

PDF
Алексей Залесов-«Управление контейнерами в облаках»
PDF
Алексей Лесовский "Тюнинг Linux для баз данных. "
PDF
Сергей Аверин "Распространенные ошибки применения баз данных"
PDF
Левон Авакян "Архитектура мета игры Wargaming. Глобальная карта 2.0"
PDF
Николай Сивко "Хорошо поддерживаемое в продакшне приложение"
PPTX
Александр Краковецкий "Разработка интеллектуальных ботов с помощью Microsoft ...
PDF
Артем Маринов "Сегментируем 600 млн. пользователей в режиме реального времени...
PDF
Вадим Мадисон "Опыт разработки через микросервисы"
PDF
Андрей Дроздов "Создание высокопроизводительных rest api на tarantool"
PDF
Артем Маринов "Сегментируем 600 млн. пользователей в режиме реального времени...
PDF
Максим Барышиков-«WoT: Geographically distributed cluster of clusters»
PDF
Андрей Светлов-«Делаем своё решение для оптимальной загрузки кластера»
PDF
Юрий Насретдинов-«Сбор логов в «облаке» в Badoo»
PDF
Левон Авакян-«Эволюция кланов в Wargaming. От веб страницы на танковом портал...
PDF
Александр Ломов-«Как перестать беспокоиться и начать использовать Cloud Foundry»
Алексей Залесов-«Управление контейнерами в облаках»
Алексей Лесовский "Тюнинг Linux для баз данных. "
Сергей Аверин "Распространенные ошибки применения баз данных"
Левон Авакян "Архитектура мета игры Wargaming. Глобальная карта 2.0"
Николай Сивко "Хорошо поддерживаемое в продакшне приложение"
Александр Краковецкий "Разработка интеллектуальных ботов с помощью Microsoft ...
Артем Маринов "Сегментируем 600 млн. пользователей в режиме реального времени...
Вадим Мадисон "Опыт разработки через микросервисы"
Андрей Дроздов "Создание высокопроизводительных rest api на tarantool"
Артем Маринов "Сегментируем 600 млн. пользователей в режиме реального времени...
Максим Барышиков-«WoT: Geographically distributed cluster of clusters»
Андрей Светлов-«Делаем своё решение для оптимальной загрузки кластера»
Юрий Насретдинов-«Сбор логов в «облаке» в Badoo»
Левон Авакян-«Эволюция кланов в Wargaming. От веб страницы на танковом портал...
Александр Ломов-«Как перестать беспокоиться и начать использовать Cloud Foundry»
Ad

Similar to Артем Гавриченков "The Dark Side of Things: Distributed Denial of Service Attacks after Mirai" (20)

PDF
DDoS Attacks in 2017: Beyond Packet Filtering
PDF
Addressing IPv6
PPTX
Where is Data Going? - RMDC Keynote
PDF
Latency Maps for Asia's mobile networks
PDF
DDoS Attacks - Scenery, Evolution and Mitigation
PDF
Fast Cars, Big Data - How Streaming Can Help Formula 1
PDF
Scala and ZeroMQ: Events beyond the JVM
PDF
Spoofing and Denial of Service: A risk to the decentralized Internet
PDF
DDoS And Spoofing, a risk to the decentralized internet
PDF
Enabling Smarter Cities and Connected Vehicles with an Event Streaming Platfo...
PDF
BREAKING HTTPS WITH BGP HIJACKING
PDF
IoT - the Next Wave of DDoS Threat Landscape
PDF
The Next Generation of Microservices
PDF
Virdata: lessons learned from the Internet of Things and M2M Cloud Services @...
PDF
Five Fabulous Sinks for Your Kafka Data. #3 will surprise you! (Rachel Pedres...
PPTX
Dear IT...I'd Like A Kubernetes Cluster
PDF
HKNOG 1.0 - DDoS attacks in an IPv6 World
PDF
Things I wish I had known about IPv6 before I started
PDF
Edge 2016 barbarians at the gateway
PPTX
Benefits of an Agile Data Fabric for Business Intelligence
DDoS Attacks in 2017: Beyond Packet Filtering
Addressing IPv6
Where is Data Going? - RMDC Keynote
Latency Maps for Asia's mobile networks
DDoS Attacks - Scenery, Evolution and Mitigation
Fast Cars, Big Data - How Streaming Can Help Formula 1
Scala and ZeroMQ: Events beyond the JVM
Spoofing and Denial of Service: A risk to the decentralized Internet
DDoS And Spoofing, a risk to the decentralized internet
Enabling Smarter Cities and Connected Vehicles with an Event Streaming Platfo...
BREAKING HTTPS WITH BGP HIJACKING
IoT - the Next Wave of DDoS Threat Landscape
The Next Generation of Microservices
Virdata: lessons learned from the Internet of Things and M2M Cloud Services @...
Five Fabulous Sinks for Your Kafka Data. #3 will surprise you! (Rachel Pedres...
Dear IT...I'd Like A Kubernetes Cluster
HKNOG 1.0 - DDoS attacks in an IPv6 World
Things I wish I had known about IPv6 before I started
Edge 2016 barbarians at the gateway
Benefits of an Agile Data Fabric for Business Intelligence

More from Tanya Denisyuk (13)

PPTX
Павел Вейник-«Программирование и лингвистика: как понять язык и как извлечь з...
PPTX
Михаил Серченя-«Построение отказоустойчивой масштабируемой среды для WEB и бе...
PPTX
Дмитрий Лазаренко-«Живая миграция и отказоустойчивость контейнеров в гибридно...
PDF
Андрей Федоренчик- «Высоконагруженная система с аналитикой на InfoBright»
PDF
Роман Иманкулов-«Быстрые и масштабируемые приложения с Sync API»
PPTX
Дмитрий Дурасов-«Технологии контейнеризации в Windows Server 2016»
PDF
Антон Щербаков, Отказоустойчивость на примере aviasales — почему даже если на...
PDF
Александр Тоболь, Кадры решают все, или стриминг видео в Одноклассниках
PDF
Денис Баталов, Принципы построения высоконагруженных сайтов на платформе АWS
PDF
Кирилл Алешин, Ламбда Архитектура на практике
PDF
Михаил Табунов, Аналитическая платформа на несколько миллиардов событий в месяц
PDF
Alvaro Videla, Building a Distributed Data Ingestion System with RabbitMQ
PDF
Антон Тюрин, Евгений Сафронов, Инфраструктура под Cocaine
Павел Вейник-«Программирование и лингвистика: как понять язык и как извлечь з...
Михаил Серченя-«Построение отказоустойчивой масштабируемой среды для WEB и бе...
Дмитрий Лазаренко-«Живая миграция и отказоустойчивость контейнеров в гибридно...
Андрей Федоренчик- «Высоконагруженная система с аналитикой на InfoBright»
Роман Иманкулов-«Быстрые и масштабируемые приложения с Sync API»
Дмитрий Дурасов-«Технологии контейнеризации в Windows Server 2016»
Антон Щербаков, Отказоустойчивость на примере aviasales — почему даже если на...
Александр Тоболь, Кадры решают все, или стриминг видео в Одноклассниках
Денис Баталов, Принципы построения высоконагруженных сайтов на платформе АWS
Кирилл Алешин, Ламбда Архитектура на практике
Михаил Табунов, Аналитическая платформа на несколько миллиардов событий в месяц
Alvaro Videla, Building a Distributed Data Ingestion System with RabbitMQ
Антон Тюрин, Евгений Сафронов, Инфраструктура под Cocaine

Recently uploaded (20)

PDF
Physiotherapy_for_Respiratory_and_Cardiac_Problems WEBBER.pdf
PDF
Anesthesia in Laparoscopic Surgery in India
PPTX
Cell Types and Its function , kingdom of life
PPTX
GDM (1) (1).pptx small presentation for students
PDF
3rd Neelam Sanjeevareddy Memorial Lecture.pdf
PPTX
Institutional Correction lecture only . . .
PDF
Sports Quiz easy sports quiz sports quiz
PPTX
Pharmacology of Heart Failure /Pharmacotherapy of CHF
PDF
O5-L3 Freight Transport Ops (International) V1.pdf
PPTX
Introduction_to_Human_Anatomy_and_Physiology_for_B.Pharm.pptx
PDF
FourierSeries-QuestionsWithAnswers(Part-A).pdf
PDF
Pre independence Education in Inndia.pdf
PPTX
Cell Structure & Organelles in detailed.
PDF
STATICS OF THE RIGID BODIES Hibbelers.pdf
PDF
grade 11-chemistry_fetena_net_5883.pdf teacher guide for all student
PPTX
1st Inaugural Professorial Lecture held on 19th February 2020 (Governance and...
PPTX
master seminar digital applications in india
PDF
102 student loan defaulters named and shamed – Is someone you know on the list?
PDF
Abdominal Access Techniques with Prof. Dr. R K Mishra
PDF
Complications of Minimal Access Surgery at WLH
Physiotherapy_for_Respiratory_and_Cardiac_Problems WEBBER.pdf
Anesthesia in Laparoscopic Surgery in India
Cell Types and Its function , kingdom of life
GDM (1) (1).pptx small presentation for students
3rd Neelam Sanjeevareddy Memorial Lecture.pdf
Institutional Correction lecture only . . .
Sports Quiz easy sports quiz sports quiz
Pharmacology of Heart Failure /Pharmacotherapy of CHF
O5-L3 Freight Transport Ops (International) V1.pdf
Introduction_to_Human_Anatomy_and_Physiology_for_B.Pharm.pptx
FourierSeries-QuestionsWithAnswers(Part-A).pdf
Pre independence Education in Inndia.pdf
Cell Structure & Organelles in detailed.
STATICS OF THE RIGID BODIES Hibbelers.pdf
grade 11-chemistry_fetena_net_5883.pdf teacher guide for all student
1st Inaugural Professorial Lecture held on 19th February 2020 (Governance and...
master seminar digital applications in india
102 student loan defaulters named and shamed – Is someone you know on the list?
Abdominal Access Techniques with Prof. Dr. R K Mishra
Complications of Minimal Access Surgery at WLH

Артем Гавриченков "The Dark Side of Things: Distributed Denial of Service Attacks after Mirai"