SlideShare une entreprise Scribd logo
1  sur  46
Session ID: HT-R33
Session Classification: Intermediate
►
►
►
►
►
►
►
►
►
►
►
►
Network Impact    Sever
Business Impact   Sever
Attack                   Confirmed Pipe     FW     Web
Vector                             Satur-
                         Measurement        CPU    Server
                                   ation    100%   Outage
UDP Flood                44 Mbps     X        X
HTTP Flood               40K Concurrent Con. X        X
Empty Connection Flood   5.2K PPS             X       X
FIN+ACK                  4 Mbps               X       X
“Stock exchange hit
                        by hackers”
 “Attack on stock
exchange triggers
  halt in trade”
Network Impact    Low
Business Impact   None
“Stock exchange IT
 have been working
intensively to resolve
     all issues”
                         “Experts successfully
                            implemented a
                         protection against the
                                attacks”
“Additional measures
were taken such as a
redundant New Site”
Network Impact    None
    Business Impact   None





Legitimate traffic monitoring




TCP connection flood detection
  and mitigated immediately
Network Impact    None
Business Impact   None
Attack begins but quickly
        mitigated
►
    ►
►
►
►
Psychological
   Impact
                 Static Content              HTTP Flood



   Trade        Trade/Financial
 Disruption     Announcements
                                  Firewall   L3 Router    Internet Pipe



                  Trading API
Psychological
   Impact
                 Static Content              UDP Flood



   Trade        Trade/Financial
 Disruption     Announcements
                                  Firewall   L3 Router   Internet Pipe



                  Trading API
Psychological
   Impact
                 Static Content               SYN Flood



   Trade        Trade/Financial
 Disruption     Announcements
                                  Firewall   L3 Router    Internet Pipe



                  Trading API
Protection


                              HTTP Flood

                                UDP Flood

                                   SYN Flood

Stock Exchange
Protection


                                   HTTP Flood

                              UDP Flood

                                    SYN Flood

Stock Exchange
Protection


                                      HTTP Flood
  Attackers will
                                       UDP Flood
 eventually find
the weakest link!                      SYN Flood

    Stock Exchange           Slow Rate Flood

                          Image Download Flood
Political/Hacktivist’s Bull’s Eye (Realistic)
Legitimate
                  Bypass CDN




Attack Directly
►
    ►
Pragma: no-cache
►
►
►
►
►
Attack
Heads Up      Reconnaissance          Test Fire
                                                    Begins

                                Service                         Service
                               Disruption                      Disruption
 Automatic     Manual                New Attack   Mitigation
 Mitigation   Mitigation              Vectors     Continued




Attack Ends    Forensic
Attack                                                    Attack
             Period                                                    Period
“Peace”                                   “Peace”
 Period                                    Period



                                                                                Time

Pre-attack            Post-attack Phase             Pre-attack Phase
  Phase
                               Automatic Mitigation
                         (no time for human interaction)
THE SECURITY GAP
                 Attacker has time to bypass automatic mitigation.
                   Defenders have no skill/capacity to sustain it.
“Peace” Period                                                        “Peace” Period


                                 Attack Period

 Pre-attack                                                          Post-attack
 Phase                                                               Phase
45%

                                                                               40%

                                                                               35%

                                                                               30%
                  Procedures                                                   25%

                                                                               20%
                  Human skills
                                                                               15%

                  Equipment                                                    10%

                                                                               5%

                                                                               0%




                                              Before          During   After



Radware 2012 Global Application and Network Security Report
Be prepared for prolonged attacks!

                                THE SECURITY GAP
                 Attacker has time to bypass automatic mitigation.
“Peace” Period     Defenders have no skill/capacity to sustain it.    “Peace” Period


                                 Attack Period

 Pre-attack                                                          Post-attack
 Phase                                                               Phase
Counterattack
    RT Intel
Active Mitigation




   24x7x365
    Trained
  Experienced
►
►
►
►
►
►

Contenu connexe

Plus de Radware

Mobile Web Stress: Understanding the Neurological Impact of Poor Performance
Mobile Web Stress:  Understanding the Neurological Impact of Poor PerformanceMobile Web Stress:  Understanding the Neurological Impact of Poor Performance
Mobile Web Stress: Understanding the Neurological Impact of Poor Performance
Radware
 

Plus de Radware (20)

What’s the Cost of a Cyber Attack (Infographic)
What’s the Cost of a Cyber Attack (Infographic)What’s the Cost of a Cyber Attack (Infographic)
What’s the Cost of a Cyber Attack (Infographic)
 
DDoS Threat Landscape - Ron Winward CHINOG16
DDoS Threat Landscape - Ron Winward CHINOG16DDoS Threat Landscape - Ron Winward CHINOG16
DDoS Threat Landscape - Ron Winward CHINOG16
 
Radware Cloud Security Services
Radware Cloud Security ServicesRadware Cloud Security Services
Radware Cloud Security Services
 
Radware 2016 State of the Union: Multi Industry Web Performance (Desktop)
Radware 2016 State of the Union: Multi Industry Web Performance (Desktop)Radware 2016 State of the Union: Multi Industry Web Performance (Desktop)
Radware 2016 State of the Union: Multi Industry Web Performance (Desktop)
 
Radware Hybrid Cloud WAF Service
Radware Hybrid Cloud WAF ServiceRadware Hybrid Cloud WAF Service
Radware Hybrid Cloud WAF Service
 
The Expanding Role and Importance of Application Delivery Controllers [Resear...
The Expanding Role and Importance of Application Delivery Controllers [Resear...The Expanding Role and Importance of Application Delivery Controllers [Resear...
The Expanding Role and Importance of Application Delivery Controllers [Resear...
 
The Art of Cyber War [From Black Hat Brazil 2014]
The Art of Cyber War [From Black Hat Brazil 2014]The Art of Cyber War [From Black Hat Brazil 2014]
The Art of Cyber War [From Black Hat Brazil 2014]
 
The Real Cost of Slow Time vs Downtime
The Real Cost of Slow Time vs DowntimeThe Real Cost of Slow Time vs Downtime
The Real Cost of Slow Time vs Downtime
 
Cyber Attack Survival: Are You Ready?
Cyber Attack Survival:  Are You Ready?Cyber Attack Survival:  Are You Ready?
Cyber Attack Survival: Are You Ready?
 
Radware ERT Threat Alert: Shellshock Bash
Radware ERT Threat Alert: Shellshock BashRadware ERT Threat Alert: Shellshock Bash
Radware ERT Threat Alert: Shellshock Bash
 
The Art of Cyber War: Cyber Security Strategies in a Rapidly Evolving Theatre
The Art of Cyber War:  Cyber Security Strategies in a Rapidly Evolving TheatreThe Art of Cyber War:  Cyber Security Strategies in a Rapidly Evolving Theatre
The Art of Cyber War: Cyber Security Strategies in a Rapidly Evolving Theatre
 
Mobile Web Stress: Understanding the Neurological Impact of Poor Performance
Mobile Web Stress:  Understanding the Neurological Impact of Poor PerformanceMobile Web Stress:  Understanding the Neurological Impact of Poor Performance
Mobile Web Stress: Understanding the Neurological Impact of Poor Performance
 
InfoSecurity Europe 2014: The Art Of Cyber War
InfoSecurity Europe 2014:  The Art Of Cyber WarInfoSecurity Europe 2014:  The Art Of Cyber War
InfoSecurity Europe 2014: The Art Of Cyber War
 
OpenStack Networking: Developing and Delivering a Commercial Solution for Lo...
OpenStack Networking:  Developing and Delivering a Commercial Solution for Lo...OpenStack Networking:  Developing and Delivering a Commercial Solution for Lo...
OpenStack Networking: Developing and Delivering a Commercial Solution for Lo...
 
SecureWorld St. Louis: Survival in an Evolving Threat Landscape
SecureWorld St. Louis:  Survival in an Evolving Threat LandscapeSecureWorld St. Louis:  Survival in an Evolving Threat Landscape
SecureWorld St. Louis: Survival in an Evolving Threat Landscape
 
In the Line of Fire - The Morphology of Cyber-Attacks
In the Line of Fire - The Morphology of Cyber-AttacksIn the Line of Fire - The Morphology of Cyber-Attacks
In the Line of Fire - The Morphology of Cyber-Attacks
 
Survival in an Evolving Threat Landscape
Survival in an Evolving Threat LandscapeSurvival in an Evolving Threat Landscape
Survival in an Evolving Threat Landscape
 
In the Line of Fire-the Morphology of Cyber Attacks
In the Line of Fire-the Morphology of Cyber AttacksIn the Line of Fire-the Morphology of Cyber Attacks
In the Line of Fire-the Morphology of Cyber Attacks
 
In the Line of Fire-the Morphology of Cyber Attacks
In the Line of Fire-the Morphology of Cyber AttacksIn the Line of Fire-the Morphology of Cyber Attacks
In the Line of Fire-the Morphology of Cyber Attacks
 
Radware DefenseFlow-The SDN Application That Programs Networks for DoS Security
Radware DefenseFlow-The SDN Application That Programs Networks for DoS Security Radware DefenseFlow-The SDN Application That Programs Networks for DoS Security
Radware DefenseFlow-The SDN Application That Programs Networks for DoS Security
 

Dernier

Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Victor Rentea
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Victor Rentea
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Safe Software
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
WSO2
 

Dernier (20)

Platformless Horizons for Digital Adaptability
Platformless Horizons for Digital AdaptabilityPlatformless Horizons for Digital Adaptability
Platformless Horizons for Digital Adaptability
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Vector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptxVector Search -An Introduction in Oracle Database 23ai.pptx
Vector Search -An Introduction in Oracle Database 23ai.pptx
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024Finding Java's Hidden Performance Traps @ DevoxxUK 2024
Finding Java's Hidden Performance Traps @ DevoxxUK 2024
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdfRising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
Rising Above_ Dubai Floods and the Fortitude of Dubai International Airport.pdf
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
MS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectorsMS Copilot expands with MS Graph connectors
MS Copilot expands with MS Graph connectors
 
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ..."I see eyes in my soup": How Delivery Hero implemented the safety system for ...
"I see eyes in my soup": How Delivery Hero implemented the safety system for ...
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 
ICT role in 21st century education and its challenges
ICT role in 21st century education and its challengesICT role in 21st century education and its challenges
ICT role in 21st century education and its challenges
 
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot ModelMcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
Mcleodganj Call Girls 🥰 8617370543 Service Offer VIP Hot Model
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)
 

Stock Exchanges in the Line of Fire-Morphology of Cyber Attacks

  • 1. Session ID: HT-R33 Session Classification: Intermediate
  • 4.
  • 5. Network Impact Sever Business Impact Sever
  • 6.
  • 7. Attack Confirmed Pipe FW Web Vector Satur- Measurement CPU Server ation 100% Outage UDP Flood 44 Mbps X X HTTP Flood 40K Concurrent Con. X X Empty Connection Flood 5.2K PPS X X FIN+ACK 4 Mbps X X
  • 8. “Stock exchange hit by hackers” “Attack on stock exchange triggers halt in trade”
  • 9.
  • 10.
  • 11. Network Impact Low Business Impact None
  • 12. “Stock exchange IT have been working intensively to resolve all issues” “Experts successfully implemented a protection against the attacks” “Additional measures were taken such as a redundant New Site”
  • 13.
  • 14. Network Impact None Business Impact None 
  • 15. Legitimate traffic monitoring TCP connection flood detection and mitigated immediately
  • 16. Network Impact None Business Impact None
  • 17. Attack begins but quickly mitigated
  • 18.
  • 19. ► ► ► ►
  • 20.
  • 21. Psychological Impact Static Content HTTP Flood Trade Trade/Financial Disruption Announcements Firewall L3 Router Internet Pipe Trading API
  • 22. Psychological Impact Static Content UDP Flood Trade Trade/Financial Disruption Announcements Firewall L3 Router Internet Pipe Trading API
  • 23. Psychological Impact Static Content SYN Flood Trade Trade/Financial Disruption Announcements Firewall L3 Router Internet Pipe Trading API
  • 24. Protection HTTP Flood UDP Flood SYN Flood Stock Exchange
  • 25. Protection HTTP Flood UDP Flood SYN Flood Stock Exchange
  • 26. Protection HTTP Flood Attackers will UDP Flood eventually find the weakest link! SYN Flood Stock Exchange Slow Rate Flood Image Download Flood
  • 27.
  • 29.
  • 30.
  • 31. Legitimate Bypass CDN Attack Directly
  • 32.
  • 35.
  • 36. Attack Heads Up Reconnaissance Test Fire Begins Service Service Disruption Disruption Automatic Manual New Attack Mitigation Mitigation Mitigation Vectors Continued Attack Ends Forensic
  • 37.
  • 38. Attack Attack Period Period “Peace” “Peace” Period Period Time Pre-attack Post-attack Phase Pre-attack Phase Phase Automatic Mitigation (no time for human interaction)
  • 39. THE SECURITY GAP Attacker has time to bypass automatic mitigation. Defenders have no skill/capacity to sustain it. “Peace” Period “Peace” Period Attack Period Pre-attack Post-attack Phase Phase
  • 40. 45% 40% 35% 30% Procedures 25% 20% Human skills 15% Equipment 10% 5% 0% Before During After Radware 2012 Global Application and Network Security Report
  • 41. Be prepared for prolonged attacks! THE SECURITY GAP Attacker has time to bypass automatic mitigation. “Peace” Period Defenders have no skill/capacity to sustain it. “Peace” Period Attack Period Pre-attack Post-attack Phase Phase
  • 42. Counterattack RT Intel Active Mitigation 24x7x365 Trained Experienced
  • 43.
  • 45.