Ddos Protection Architecture Solution Profile
Ddos Protection Architecture Solution Profile
scripting language.
A two-tier DDoS protection architecture provides greater effciency and fexibility in scaling security
components.
IPS
ISPa/b
Cloud
Scrubbing
Service
DDoS
Attacker
Legitimate
Users
Attackers Botnet Anonymous
Requests
Anonymous
Proxies
Scanner
Tier 1
Network attacks:
ICMP ood,
UDP ood,
SYN ood
DNS attacks:
DNS amplication,
query ood,
dictionary attack,
DNS poisoning
Tier 2
SSL attacks:
SSL renegotiation,
SSL ood
HTTP attacks:
Slowloris,
slow POST,
recursive POST/GET
Financial
Services
E-Commerce
Subscriber
Corporate Users
Next-Generation
Firewall
Threat Feed Intelligence
REFERENCE ARCHITECTURE: DDoS Protection
CONTENT TYPE: Architecture Diagram
AUDIENCE: IT Director/Security Engineer
CUSTOMER SCENARIO: Enterprise Data Center
Application Network
and DNS
Multiple ISP
strategy
Strategic Point of Control