A denial-of-service (DoS) attack is an attempt to make a machine or network resource unavailable to its intended users, such as to temporarily or indefinitely interrupt or suspend services of a host connected to the Internet. A distributed denial-of-service (DDoS) is where the attack source is more than one–and often thousands–of unique IP addresses - see https://en.wikipedia.org/wiki/Denial-of-service_attack
We work with our hosting provide Rackspace (http://www.rackspace.com/managed_hosting/services/security/ddosmitigation) to mitigate the effects of a possible denial of service attack using a three layer program to ensure uptime in the event of such an attack.
Summary
Rackspace DDoS Mitigation Services is a unique DDoS hardware-based program that ensures uptime in the event of a DDoS attack Three distinct technologies have been layered to create an all-encompassing protection system. From network-wide packet scanning through granular traffic analysis right down to server-level anomaly detection, three layers of detection identify and filter hostile traffic 24x7x365.
How It Works
1. Network-Level Traffic Monitoring & Analysis
The service starts by monitoring all traffic entering the network. Sophisticated Intrusion
Detection technology, capable of handling over 30 million packets per second, examines each and every incoming packet for signs of malicious activity. Meanwhile, Cisco NetFlow statistics perform granular traffic analysis of source and destination IP addresses, protocol information, flow information, and traffic volume. This information is used to make
routing decisions for best performance and to provide information on the attack type, source, protocol, and duration in the event of any denial of service event.
2. Server-level Anomaly Detection
The service also searches for anomalies on a per-server basis. It does this two ways. Firstly analysis is done on server traffic patterns to learn about “normal” network behavior, combining the results with port usage information to create a profile of a server’s usual traffic. The service then monitors the traffic, constantly comparing it to this profile and looking for unusual behavior. If it detects an anomaly, the malicious traffic is immediately filtered and blocked.
3. Traffic Filtering & Re-Routing
Finally, if malicious activity is detected, the service acts quickly, routing suspicious traffic
through a “sanitation engine”, which uses multiple DDoS detection methods to filter out and divert malicious traffic. All legitimate traffic is then forwarded to the intended destination servers, which are able to serve clients entirely unaffected by the ongoing DDoS attack.
Response Policy Zone Filtering
In addition Rackspace has implemented RPZ (Response Policy Zone) filtering on their caching DNS servers. The purpose of RPZ is to match all queries to a list of domains known to be involved in malicious activity including DDoS, malware, phishing etc. and blocking these requests.