DDos Attacks and Web Threats: How to Protect Your Site & Information

61
© 2013 Imperva, Inc. All rights reserved. DDos Attacks and Web Threats: How to Protect Your Site & Information Tina Shaw Account Executive 650-832-6087 [email protected]

description

Hacking and data theft use to belong to expert hackers. Today, anybody can go online, download free hacking tools, and launch sophisticated Web attacks within minutes. Join InterDev as we host this webinar presented by Imperva to see these tools in action and learn how to protect your Website from these attacks. Imperva's Web application cloud based security solution, specifically designed for small and mid-sized organizations, can secure your Website against attacks from free hacking tools such as Havij.

Transcript of DDos Attacks and Web Threats: How to Protect Your Site & Information

Page 1: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

DDos Attacks and Web Threats: How to Protect Your Site & Information

Tina ShawAccount [email protected]

Page 2: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. - CONFIDENTIAL -2

Page 3: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. - CONFIDENTIAL -3

Page 4: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. - CONFIDENTIAL -4

Page 5: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. - CONFIDENTIAL -5

Page 6: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. - CONFIDENTIAL -6

Page 7: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. - CONFIDENTIAL -7

Page 8: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. - CONFIDENTIAL -8

Page 9: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. - CONFIDENTIAL -9

Page 10: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. - CONFIDENTIAL -10

Page 11: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. - CONFIDENTIAL -11

Page 12: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. - CONFIDENTIAL -12

Page 13: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. - CONFIDENTIAL -13

Page 14: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. - CONFIDENTIAL -14

Page 15: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. - CONFIDENTIAL -15

Page 16: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. - CONFIDENTIAL -16

Page 17: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. - CONFIDENTIAL -17

Page 18: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

Low-Orbit Ion Canon (LOIC) Purpose - DDoS Windows desktop application, coded in C# UDP/TCP/HTTP flooding

Hacking Tools

Page 19: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

Hacker Forum Discussion Topics

DoS is Another Tool in the Hacker Toolbox

16%

22%

19%10%

12%

12% 9%

spamdos/ddosSQL Injectionzero-dayshell codebrute-forceHTML Injection

Source: Imperva. Covers July 2010 -July 2011 across 600,000 discussions

Page 20: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

A 100GB attack (Sept 24th)

• Featured in eWeek on October 1, 2013• The attack's load was distributed across our +350Gbps network.

(each color represents a different data center)

Page 21: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. Confidential

Imperva Incapsula Overview

21

Incapsula helps Website owners…

Page 22: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

Imperva Incapsula

Simplicity

Flexibility

Versatility

Imperva Incapsula Overview

Page 23: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

Versatility “The idea of recognizing your strengths and using them in as versatile a way as you can is cool to me.” - Frank Ocean

Imperva’s

Tina^

Page 24: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. Confidential24

Imperva Incapsula Versatility

By routing Website traffic through Incapsula, bad traffic is removed and good traffic is accelerated

Web Application Firewall (WAF)Distributed Denial of Service (DDOS)Distributed Denial of Service (DDOS)Load BalancingLoad BalancingContent Delivery Network (CDN)

Page 25: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

Imperva Incapsula is Deployed as a Reverse Proxy Network

360° Global Threat Detection & Analysis:

Enables early detection of threats and attack vectors and instant application of protection rules across the entire proxy network

Page 26: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved. Confidential26

Incapsula’s Global Content Delivery Network

Datacenters• Currently 15 Datacenters

USA (Ashville NC, Ashburn VA, Los Angles CA, San Jose CA, Chicago IL, Miami FL, Dallas TX, New York NY), London, Singapore, Israel, Amsterdam, Tokyo, Frankfurt, Sydney

• Plans for another 4 Datacenters Toronto, Hong Kong, Sao Paulo, and Milan

Data Across Borders• Customer data can be locked into (or out of) specific countries

Page 27: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

Simplicity

“Life is really simple, but we insist on making it complicated.” - ConfusiusSecurity Tina Shaw!

Page 28: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

The Activation Email

20 sec

Elapsed time

Page 29: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

Creating a User Account

40 sec

Elapsed time

Page 30: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential30 © 2013 Imperva, Inc. All rights reserved.

Logging into Incapsula and adding a website

60 sec

Elapsed time

Page 31: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential31 © 2013 Imperva, Inc. All rights reserved.

Incapsula Automatically Gathers Site Data

1 min 5 sec

Elapsed time

Page 32: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

Changing DNS Settings

1 min 15 sec

Elapsed time

Page 33: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

Getting Lost in Go Daddy’s Horrible UI

6 min 15 sec

Elapsed time

Page 34: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

Updating DNS Records

8 min 15 sec

Elapsed time

Page 35: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

Completing Incapsula’s Setup

8 min 45 sec

Elapsed time

Page 36: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential36 © 2013 Imperva, Inc. All rights reserved.

The Website is Protected

9 Minutes- 5 Minutes4~5 Minutes

Elapsed time

Page 37: DDos Attacks and Web Threats: How to Protect Your Site & Information

37 © 2013 Imperva, Inc. All rights reserved.

Dashboard - Traffic

Confidential

Page 38: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential38 © 2013 Imperva, Inc. All rights reserved.

Dashboard - Traffic

Page 39: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential39 © 2013 Imperva, Inc. All rights reserved.

Dashboard - Security

Page 40: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential40 © 2013 Imperva, Inc. All rights reserved.

Dashboard - Performance

Page 41: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential41 © 2013 Imperva, Inc. All rights reserved.

Dashboard – Datacenter Response Time

Page 42: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential42 © 2013 Imperva, Inc. All rights reserved.

Dashboard – Recent Updates

Page 43: DDos Attacks and Web Threats: How to Protect Your Site & Information

- CONFIDENTIAL -43 © 2013 Imperva, Inc. All rights reserved.

Visits

Page 44: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential44 © 2013 Imperva, Inc. All rights reserved.

Visits - More

Page 45: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential45 © 2013 Imperva, Inc. All rights reserved.

Visits – Add to Whitelist

Page 46: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential46 © 2013 Imperva, Inc. All rights reserved.

Settings - General

Page 47: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential47 © 2013 Imperva, Inc. All rights reserved.

Settings – Login Protect

Page 48: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential48 © 2013 Imperva, Inc. All rights reserved.

Settings - Performance

Page 49: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential49 © 2013 Imperva, Inc. All rights reserved.

Settings - Performance

Page 50: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential50 © 2013 Imperva, Inc. All rights reserved.

Settings - Notifications

Page 51: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential51 © 2013 Imperva, Inc. All rights reserved.

Settings - Security

Page 52: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential52 © 2013 Imperva, Inc. All rights reserved.

Settings - Security

Page 53: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential53 © 2013 Imperva, Inc. All rights reserved.

Settings - WAF

Page 54: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential54 © 2013 Imperva, Inc. All rights reserved.

Settings - WAF

Page 55: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential55 © 2013 Imperva, Inc. All rights reserved.

Settings – WAF Whitelist

Page 56: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential56 © 2013 Imperva, Inc. All rights reserved.

Settings – WAF Whitelist

Page 57: DDos Attacks and Web Threats: How to Protect Your Site & Information

Confidential57 © 2013 Imperva, Inc. All rights reserved.

Settings - Permissions

Page 58: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

Flexible

“I like forms that are flexible, that can let you feel creative.” -John Scofield

Security Products

Tina Shaw!

^

Page 60: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

Incapsula Makes Security Simple

Imperva Incapsula

Simplicity

Flexibility

Versatility

Page 61: DDos Attacks and Web Threats: How to Protect Your Site & Information

© 2013 Imperva, Inc. All rights reserved.

Questions?