Customers: Loyalty Partners East Moscow; Advertizing, PR and marketing Contractors: Jet Infosystems Product: Jet Security Operation Center (JSOC)Project date: 2013/06 - 2013/07
|
The Loyalty Partners East management company and Jet Infosystems company reported on July 9, 2013 some details of reflection of DDoS attack which purpose were resources of the program of Malines.
Start
The attack is carried out in several steps and was guided by Web servers, a number of infrastructure services of the program of Malines. Attack duration - more than two days, and the flow of the illegitimate traffic directed by malefactors to resources of Malines exceeded 40 Gbit per second.
Opposition
For effective reflection of attack and recovery of work of all services of Malines, in a short time created task force which specialists of the Service center and Information Security Center of Jet Infosystems company entered.
The nature of traffic underwent the analysis, created and sent to "black lists" provider of the IP addresses with which the attack, for the subsequent blocking was conducted. Having beaten off the first wave of DDoS, the data center of Loyalty Partners East company installed the firewall (Cisco ASA) and unrolled a software package of monitoring. Carried out repeated diagnostics of network traffic and established that malefactors began to use the dummy IP addresses. It demanded operational connection of external service of protection against DDoS attacks of Kaspersky DDoS Prevention (KDP) using which provided the maximum filtering of the arriving requests.
The taken measures, in total, allowed to reflect quickly DDoS attack and to completely recover operability of all services and the websites of the company.
"This case can be considered some kind of demonstrative, visually shown direct dependence between the productive solution of business challenges and the IB effective organization, - Evgeny Akimov, the associate director of Information Security Center of Jet Infosystems company noted. – According to the results of the performed works we suggested Loyalty Partners East company to correct a comprehensive plan of further development of information security taking into account such tasks as protection of public and internal services, the organization of effective monitoring and 24/7 information security management based on Jet Security Operation Center".
"Jet Infosystems company" performs complex outsourcing of IT infrastructure of the RASPBERRY Program since 2006. At the time of commission of the attack of the monitor of operability of the equipment began to signal about excessive loading, experts of the Service center of the company took operational measures and involved in further work of specialists of Information Security Center. The vector and methods of the attack constantly changed that required operational measures of protection, at the same time especially there is a wish to note the high level of professionalism of our partners in DDoS attack reflection, efficiency, aiming at result and really team work – it allowed to reflect successfully through joint efforts the attack", - Denis Kruchinin, the operating officer of Loyalty Partners East company emphasized.