DDoS Radware Mitigation on Cisco Firewalls

 What is Radware’s DDoS Mitigation Solution?

Radware’s DDoS Mitigation solution for Cisco Firepower NGFW appliance detects all DDoS attacks and mitigates them in seconds – all without blocking legitimate user traffic. It protects network infrastructure and data centers against network and application downtime (or slow time), network anomalies and network and application scanning. Radware DDoS Mitigation helps service providers win the ongoing security battle against availability attacks by detecting and mitigating known and zero-day DoS/DDoS attacks in real-time. It protects against other security threats that go undetected by traditional DDoS mitigation tools that rely on rate-based threshold for detection. Radware’s DDoS Mitigation provides full protection against the DoS/DDoS threat with the shortest mitigation time and broadest possible attack coverage. Radware provides a hybrid solution that combines on premise and cloud-based mitigation tools in a single integrated solution that is designed to mitigate multiple attack vectors occurring in parallel.

Why Radware DDoS Mitigation?

The Radware DDoS Mitigation solution includes a comprehensive set of three essential security modules –anti-DDoS, network behavioral analysis (NBA) and a signature detection engine - to protect the application infrastructure against known and emerging network security attacks. It employs multiple detection and mitigation modules including adaptive behavioral analysis, challenge response technologies and signature detection.Compared to stand-alone solutions, the synergy of multiple security modules on a single platform enables more effective protection against attackers attempting to compromise business assets while providing unified reporting, forensics and compliance.Radware DDoS Mitigation consists of patent protected, adaptive, behavioral-based, real-time signature technology that detects and mitigates emerging network attacks, zero-minute, DoS/DDoS, application misuse attacks, network scanning and malware spread. It eliminates the need for human intervention and does not block legitimate user traffic.

Always On Deployment for Service Providers

Radware DDoS Mitigation can be deployed as an Always On solution where a Firepower NGFW appliance with a DDoS Mitigation module is deployed at the customer perimeter (on-premises appliance) and at the service provider’s peering points or core network.The on-premise Firepower appliance ensures that the customer network is constantly protected by providing accurate real-time detection and mitigation of multi-vector DDoS attacks that wouldn’t be possible using only a cloud-based DDoS mitigation solution. Only volumetric attacks, where the customer’s Internet pipe is saturated, is when service providers may decide to move mitigation either to the core network Firepower appliances or Radware’s cloud-based scrubbing center (DefensePipe), thereby clearing attack traffic before it reaches the customer’s Internet pipe. This enables a smooth transition between mitigation options assuring immediate protection with no disruption gaps and without adding the scrubbing center latency.


Defense Messaging enables sharing of attack information between the on premise solution and scrubbing center appliances. This allows the solution to maintain continual and accurate mitigation even when diverting the traffic to the cloud for scrubbing.

Summary

DDoS attacks cause organizations to lose revenue and increase operational costs. Attackers are more sophisticated and leveraging multi-vector attack campaigns. Radware’s DDoS Protection solution offers a hybrid, multi-layered mitigation solution with industry-leading network and application DDoS attack mitigation. Radware’s hybrid solution provides the shortest time to mitigation, providing across-the-board detection and mitigation to stop multi-vector DDoS attacks instantaneously.

Solution Benefits:

• Full Coverage - able to detect and mitigate all types of DoS/ DDoS flood attacks

 o Network DDoS attacks

 o Application DDoS attacks

 o Known attack tools

• High Accuracy

 o Minimal false positives with patent-protected behavioral analysis technology

 o Real-time signatures and selective challenge-response mechanism for high mitigation accuracy

• Shortest Time

 o All attacks are detected on premise and in real-time

 o Protection starts in seconds


I.Z

Comments

Popular posts from this blog

CISA and ENISA enhance their Cooperation

Top Five Most Exploited Vulnerabilities in January 2024

SmartScreen Vulnerability: CVE-2024-21412 Facts and Fixes