ddos mitigation at nordunet
play

DDoS Mitigation at NORDUnet Lars Fischer (w/ big thanks to Martin - PowerPoint PPT Presentation

NORDUnet Nordic Infrastructure for Research & Education DDoS Mitigation at NORDUnet Lars Fischer (w/ big thanks to Martin Aldrin) TF-MSP Meeting Malta, 27 November 2014 NORDUnet Basic Nordic infrastructure for Research & Education


  1. NORDUnet Nordic Infrastructure for Research & Education DDoS Mitigation at NORDUnet Lars Fischer (w/ big thanks to Martin Aldrin) TF-MSP Meeting Malta, 27 November 2014

  2. NORDUnet Basic Nordic infrastructure for Research & Education • DDoS is a major issue; every responsible network must be working on the best ways to counter it • So far NORDUnet is doing blackholing • It works • It kills an entire network • Creates ”Innocent bystander” problem • Creates reluctance to deploy

  3. NORDUnet DDoS structure Nordic infrastructure for Research & Education

  4. NORDUnet Options Nordic infrastructure for Research & Education • Scrubbing • Intelligence DDoS Mitigation Systems (IDMS) • Commercial products available (i.e., Arbor Networks) • Costly • Unlike carriers, we cannot sell it as a service • Enterprise-level solutions • IP rewrite, running traffic through filter or firewall • Does not scale to our needs • Flowspec • Promising • This is our bet for a future solution

  5. NORDUnet What is FlowSpec? Nordic infrastructure for Research & Education • Flow Specification (RFC 5575) • Designed for DDoS mitigation • Remote triggered ACLs • Extension to BGP • Can match in various events and traffic types • Can act to rate-limit, redirect, mark, etc • Bleeding edge technology, working it’s way through IETF • Per-interface capability only came this summer

  6. NORDUnet Trying FlowSpec Nordic infrastructure for Research & Education • Objective • Investigate what a FlowSpec-based solution might look like • Is there a good match for NREN environment? • DIY, since there’s nothing in the market • Can we create a controller to dynamically assign FlowSpec rules? • Student project • MSc student: Martin Aldrin • Controller design and development • Full implementation and test • Lab exercise

  7. NORDUnet DDoS Attack (w/ NTP) Nordic infrastructure for Research & Education

  8. NORDUnet Blackhole Nordic infrastructure for Research & Education Real traffic lost

  9. NORDUnet Flowspec – edge limit Nordic infrastructure for Research & Education Better, but still load on core

  10. NORDUnet Limit w/ FlowSpec controllers Nordic infrastructure for Research & Education Co-operating networks reduce core load

  11. NORDUnet Lab w/FlowSpec controllers Nordic infrastructure for Research & Education

  12. NORDUnet Attack traffic flow Nordic infrastructure for Research & Education 600 500 400 Mbit/s Multi weight 300 Multi Single 200 100 0 0 0,5 1 1,5 2 2,5 3 3,5 4 4,5 5 5,5 6 6,5 7 7,5 8 Time in minutes

  13. NORDUnet Real traffic flow Nordic infrastructure for Research & Education 100% 90% Survival rate 80% Multi weight Multi 70% Single 60% 50% 0 0,5 1 1,5 2 2,5 3 3,5 4 4,5 5 5,5 6 6,5 7 7,5 8 Time in minutes

  14. NORDUnet Status Nordic infrastructure for Research & Education • We have done the experiment • We have it working in the lab • Decision point: is this something we’re pushing towards production? • Live network trial? • We have not decided • We need a customer / border to try it on • Solution has network effect • Value go up with more deployments • There’s mutual benefit • (and there’s additional technical work we’d like to do)

  15. NORDUnet Joint Effort? Nordic infrastructure for Research & Education • Collaborative DDoS effort based on FlowSpec? • Are we solving a problem? • Is this something other networks see value in? • Community adopting the technology? • GÉANT Firewall-as-a-service based on FlowSpec • What next? • Is the idea liked? • How do we set up a collaboration? • What is the way forward?

  16. NORDUnet Conclusions Nordic infrastructure for Research & Education • We must have something better than blackhole • Right now that means FlowSpec • We have to go DIY • It works in the lab • We want to work with YOU • Real value comes if many are doing it

Download Presentation
Download Policy: The content available on the website is offered to you 'AS IS' for your personal information and use only. It cannot be commercialized, licensed, or distributed on other websites without prior consent from the author. To download a presentation, simply click this link. If you encounter any difficulties during the download process, it's possible that the publisher has removed the file from their server.

Recommend


More recommend