1. 程式人生 > >Reduce DDoS Risks Using Amazon Route 53 and AWS Shield

Reduce DDoS Risks Using Amazon Route 53 and AWS Shield

In late October of 2016 a large-scale cyber attack consisting of multiple denial of service attacks targeted a well-known DNS provider. The attack, consisting of a flood of DNS lookups from tens of millions of IP addresses, made many Internet sites and services unavailable to users in North America and Europe. This

Distributed Denial of Service (DDoS) attack was believe to have been executed using a botnet consisting of a multitude of Internet-connected devices such as printers, camera, residential network gateways, and even baby monitors. These devices had been infected with the Mirai malware and generated several hundreds of gigabytes of traffic per second. Many corporate and educational networks simply do not have the capacity to absorb a volumetric attack of this size.

In the wake of this attack and others that have preceded it, our customers have been asking us for recommendations and best practices that will allow them to build systems that are more resilient to various types of DDoS attacks. The short-form answer involves a combination of scale, fault tolerance, and mitigation (the AWS Best Practices for DDoS Resiliency white paper, linked below, goes in to far more detail) and makes use of

Amazon Route 53 and AWS Shield (read AWS Shield – Protect Your Applications from DDoS Attacks to learn more).

Scale – Route 53 is hosted at numerous AWS edge locations, creating a global surface area capable of absorbing large amounts of DNS traffic. Other edge-based services, including Amazon CloudFront and AWS WAF, also have a global surface area and are also able to handle large amounts of traffic.

Fault Tolerance – Each edge location has many connections to the Internet. This allows for diverse paths and helps to isolate and contain faults. Route 53 also uses shuffle sharding and anycast striping to increase availability. With shuffle sharding, each name server in your delegation set corresponds to a unique set of edge locations. This arrangement increases fault tolerance and minimizes overlap between AWS customers. If one name server in the delegation set is not available, the client system or application will simply retry and receive a response from a name server at a different edge location. Anycast striping is used to direct DNS requests to an optimal location. This has the effect of spreading load and reducing DNS latency.

Mitigation – AWS Shield Standard protects you from 96% of today’s most common attacks. This includes SYN/ACK floods, Reflection attacks, and HTTP slow reads. As I noted in my post above, this protection is applied automatically and transparently to your Elastic Load Balancers, CloudFront distributions, and Route 53 resources at no extra cost. Protection (including deterministic packet filtering and priority based traffic shaping) is deployed to all AWS edge locations and inspects all traffic with just microseconds of overhead, all in a totally transparent fashion. AWS Shield Advanced includes additional DDoS mitigation capability, 24×7 access to our DDoS Response Team, real time metrics and reports, and DDoS cost protection.

To learn more, read the DDoS Resiliency white paper and learn about Route 53 anycast.

Jeff;

相關推薦

Reduce DDoS Risks Using Amazon Route 53 and AWS Shield

In late October of 2016 a large-scale cyber attack consisting of multiple denial of service attacks targeted a well-known DNS provider. The attack

Create a Simple Resource Record Set in Amazon Route 53 Using the AWS CLI

{ "Comment": "CREATE/DELETE/UPDATE", "Changes": [ { "Action": "CREATE",

Troubleshoot Errors with Creating Amazon Route 53 Resource Record Sets Using the AWS CLI

An error occurred (InvalidChangeBatch) when calling the ChangeResourceRecordSets operation: RRSet of type CNAME with DNS name domain.com. is no

Amazon Route 53 Amazon Registrar Policies

When you register or transfer in a Registered Name to Amazon Registrar, you will have the option to enable or disable the services describe

Amazon Route 53 Domain Name Registration End User Agreement

13.11 Limitation of Liability. WE AND OUR AFFILIATES AND BUSINESS ASSOCIATES, INCLUDING ANY REGISTRY OPERATORS, REGISTRARS, OR LICENSORS, WIL

Transfer Amazon Route 53 Resources

Amazon Web Services is Hiring. Amazon Web Services (AWS) is a dynamic, growing business unit within Amazon.com. We are currently hiring So

Amazon Route 53 pricing

The monthly health check prices listed above are prorated for partial months. Need more than 200 health checks? Please contact us.

Amazon Route 53

Amazon Web Services is Hiring. Amazon Web Services (AWS) is a dynamic, growing business unit within Amazon.com. We are currently hiring So

하이브리드 환경을 위한 Amazon Route 53 DNS Resolver 신규 기능

제가 AWS 고객으로서 처음 Virtual Private Cloud(VPC)를 생성했을 때의 감동을 잊을 수가 없습니다. 비슷한 데이터 센터 내 환경을 구축하느라 몇 개월을 보내고, 진짜 복잡한 설정 방식에 힘들어 하고 있을 때였습니다. VPC가 제공하는 즉각적

新增功能 – Amazon Route 53 混合雲解析器

我異常清晰地記得我作為一名客戶建立第一個 Virtual Private Cloud (VPC) 時的興奮。我最近幾個月一直在構建一個類似的本地環境,但對其中複雜的設定感到很苦惱。VPC 提供的一個直接優勢是 EC2 例項傳送域名服務 (DNS) 查詢的神奇地址 10.0.0.2。它非常可靠

Управляемый облачный сервис DNS – Система доменных имен – Amazon Route 53 

Система DNS в Интернете напоминает телефонную книгу – она также управляет соответствиями между именами и цифрами. Если говорить про сервис DNS,

Amazon Route 53 雲域名系統(DNS服務)_DNS解析

Internet 上的 DNS 系統與電話簿非常相似,它管理著名稱和數字之間的對映關係。在 DNS 中,名稱就是方便使用者記憶的域名 (www.example.com)。但是,DNS 中的名稱不是對映到電話號碼,而是對映到 IP 地址 (192.0.2.1),它指定了計算機在 Inte

Amazon Route 53 FAQs

Q. What is DNS Failover? DNS Failover consists of two components: health checks and failover. Health checks are automated requests sent

Amazon Route 53

En cas d'utilisation des vérifications de l'état de santé pendant une partie du mois seulement, les tarifs mensuels annoncés ci-dessus sont cal

Système de noms de domaine Amazon Route 53

Tout comme un annuaire téléphonique, le système de noms de domaine d'internet gère la mise en correspondance entre les noms et les nombres. Dan

Amazon Route 53雲域名系統(DNS)開發人員資源

Amazon Web Services 誠聘精英。 Amazon Web Services (AWS) 是 Amazon.com 的一個充滿活力、不斷壯大的業務部門。我們現誠聘軟體開發工程師、產品經理、客戶經理、解決方案架構師、支援工程師、系統工程師以及設計師等人才。請訪問我

Amazon Route 53雲域名系統(DNS)價格_DNS解析

對於未滿一個月的部分,上述執行狀況檢查月度價格按比例收取。 需要執行超過 200 次執行狀況檢查?請聯絡我們。 * 對於新客戶及現有客戶,其 AWS 賬戶中的(或與其賬戶關聯的)可免費享受執行狀況檢查的 AWS 終端節點(如下所述)數目最多可

Analyze and visualize your VPC network traffic using Amazon Kinesis and Amazon Athena

Network log analysis is a common practice in many organizations.  By capturing and analyzing network logs, you can learn how devices on your netwo

Segmenting brain tissue using Apache MXNet with Amazon SageMaker and AWS Greengrass ML Inference

In Part 1 of this blog post, we demonstrated how to train and deploy neural networks to automatically segment brain tissue from an MRI scan in a s