38
SOLVING DDOS ATTACKS FACILITATING BRIDGING SOLUTIONS AND STAKEHOLDERS DDOS CLEARING HOUSE IN THE NETHERLANDS 2019-05-21 , EUROPE, AND BEYOND

IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

  • Upload
    others

  • View
    9

  • Download
    0

Embed Size (px)

Citation preview

Page 1: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

SOLVING DDOS ATTACKS FACILITATING BRIDGING SOLUTIONS AND STAKEHOLDERS

DDOS CLEARING HOUSEIN THE NETHERLANDS

2019-05-21

, EUROPE, AND BEYOND

Page 2: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

SOLVING DDOS ATTACKSKoen van Hove

Researcher at the University of Twente

Page 3: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

THE PROBLEM AND OUR IDEA

Page 4: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

https://www.bus

iness.c

om/categ

ories/be

st-ddo

s-protec

tion-services/

Page 5: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

https://scho

lar.g

oogle.nl/sch

olar?h

l=en

&as_sdt=0

%2C

5&q=

ddos

+atta

ck&btnG

=

Page 6: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

?

WHY DOES DDOS STILL

EXIST?

??? ? ?? ?

Page 7: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

SOLVING DDOS

ATTACKS

Page 8: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

SOLVING DDOS

ATTACKS

ACADEMIADDOS

PROTECTIONPROVIDERS

Page 9: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

DDOSPROTECTIONPROVIDERS

VICTIMSNETWORK

OPERATORS+

CERT/CSIRTACADEMIA

LAWENFORCEMENT

AGENCIES

Page 10: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

DDOS CLEARING HOUSE

Page 11: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

DDOS CLEARING HOUSE

Page 12: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

NETWORK MEASUREMENT (PCAP, NET FLOW, IPFIX, SFLOW, LOGS, …)DDOS_DISSECTORINPUT: NETWORK MEASUREMENTOUTPUT: DDOS FINGERPRINT (+*NOTES)

FILTERED & ANONYMIZED NETWORK MEASUREMENTSDDOS_FINGERPRINT_CONVERTERSINPUT: DDOS FINGERPRINTOUTPUT: RULE/SIGNATURE FOR SPECIFIC HW/SW SOLUTION(S)(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …)DDOSDBSTORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO

Page 13: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

DDOSPROTECTIONPROVIDERS

VICTIMSNETWORK

OPERATORS+

CERT/CSIRTACADEMIA

LAWENFORCEMENT

AGENCIES

Page 14: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …
Page 15: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …
Page 16: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

DDOSPROTECTIONPROVIDERS

VICTIMSNETWORK

OPERATORS+

CERT/CSIRTACADEMIA

LAWENFORCEMENT

AGENCIES

Page 17: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …
Page 18: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

DDOSPROTECTIONPROVIDERS

VICTIMSNETWORK

OPERATORS+

CERT/CSIRTACADEMIA

LAWENFORCEMENT

AGENCIES

Page 19: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …
Page 20: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

DDOSPROTECTIONPROVIDERS

VICTIMSNETWORK

OPERATORS+

CERT/CSIRTACADEMIA

LAWENFORCEMENT

AGENCIES

Page 21: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …
Page 22: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

DDOSPROTECTIONPROVIDERS

VICTIMSNETWORK

OPERATORS+

CERT/CSIRTACADEMIA

LAWENFORCEMENT

AGENCIES

Page 23: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

ONE EXTRA ELEMENT…

Page 24: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

DDOS OPEN THREAT SIGNALING (DOTS) [IETF]

Page 25: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

DDOS OPEN THREAT SIGNALING (DOTS) [IETF]

Page 26: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

DEMO:USING THE DDOS DISSECTOR

Page 27: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

DEMO:QUERYING DDOSDB

Page 28: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

[THE CURRENT]DEPLOYMENT & GOVERNANCE

Page 29: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

TIMELIME

2019

2018

?2017

Page 30: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

https://github.com/ddos-clearing-house https://ddosdb.ORG https://ddosdb.NL

Page 31: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

CHALLENGES & FUTURE DIRECTIONS

Page 32: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

.org .nl

Page 33: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

.org.nl.it

Page 34: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

QUESTIONS?

SOLVING DDOS ATTACKSKoen van Hove

Researcher at the University of [email protected]

Page 35: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

BACKUP SLIDES

Page 36: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

NETWORK MEASUREMENT (PCAP, NET FLOW, IPFIX, SFLOW, LOGS, …)DDOS_DISSECTORINPUT: NETWORK MEASUREMENTOUTPUT: DDOS FINGERPRINT (+*NOTES)

FILTERED AND ANONYMIZED NETW. MEASU.DDOS_FINGERPRINT_CONVERTERSINPUT: DDOS FINGERPRINTOUTPUT: RULE/SIGNATURE FOR SPECIFIC HW/SW SOLUTION(S)(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …)DDOSDBSTORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO

Page 37: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

SOLVING DDOS ATTACKS FACILITATING BRIDGING SOLUTIONS AND STAKEHOLDERS

DDOS CLEARING HOUSEIN THE NETHERLANDS, EUROPE, AND BEYOND

3/03/2019

Page 38: IN THE NETHERLANDS, EUROPE, AND BEYOND(SNORT, SURICATA, BRO, IPTABLES, EBPF, BGP FLOWSPEC, …) DDOSDB STORE, ENRICH, AND DISTRIBUTE DDOS ATTACK RELATED INFO DDOS PROTECTION …

https://www.zdn

et.com

/article/the-av

erag

e-dd

os-atta

ck-cos

t-for-bus

inesses-ris

es-to

-ove

r

WHAT IS THE AVERAGE ECONOMIC LOSS PER DDOS ATTACK?A. $25.000 C. $2.500.000

D. $25.000.000B. $250.000