Hosting with full DDoS protection - myth or reality

THUMB



In the first two quarters of 2020, the number of DDoS attacks almost tripled, with 65% of them attributable to primitive ā€œload testingā€ attempts that easily ā€œdisableā€ defenseless sites of small online stores, forums, blogs, and the media.



How to choose a DDoS-protected hosting? What to look for and what to prepare for so as not to be in an unpleasant situation?



( Ā«Ā» )



DDoS- - . DDoS , , ( -).



DDoS- , , (OSI):



  • (L2),
  • (L3),
  • (L4),
  • (L7).


, : (L2-L4) (L7). : IP-, .



, ā€“ . , , ( ).



3 DDoS



DDoS- (Service Level Agreement, SLA) -. :



  • ?
  • , ?
  • - DDoS- (, , )?


, , DDoS (L3-4) . , .



! Reverse Proxy, - : , ( 1).



image



1.



, IP- , ā€” . IP- -, Ā«Ā» .



IP-



ā€” IP- ( ).



1:

- Intelligence X: , , Whois, .



image



- (HTTP-, Whois .) , Cloudflare, IP , 3 IP- , Cloudflare.



image



SSL- Censys , IP- . , Certificates :



_parsed.names: AND tags.raw: trusted



image



IP- , SSL-, ( Ā«ExploreĀ», Ā«IPv4 HostsĀ»).



2: DNS

DNS- ā€” , . IP- , ( -) . - ViewDNS SecurityTrails.



IP- CDN, . , - IP- .



image



, DNS- , (dig, host nslookup) IP- , :



_dig @__dns_



3: email

, / ( , ) , Ā«ReceivedĀ».



image



IP- MX- ( ), .



IP Cloudflare :



  • DNS, DNSDumpster.com;
  • Crimeflare.com;
  • .


ā€” , . CloudFail.



, , , : Sublist3r dnsrecon.



seo.com, Cloudflare, builtwith ( / / CMS, , ā€“ ).



Ā«IPv4 HostsĀ» . , IP- 443. , , Ā«HostĀ» HTTP- (, *curl -H "Host: _" *https://IP_).



image



Censys , .



DNS https://securitytrails.com/dns-trails.



image



DNS CloudFail, . .



image



, IP -. ā€” .



-. , DDoS-.



-



  1. ( 2).

    :

    1.1. ;

    1.2. ;

    1.3. , ;

    1.4. Ā«Ā» .

    image

    2.

    DDoS Gbps, . - ? Ā«Ā» ? , , .
  2. Reverse Proxy ( ). , DDoS- (. 1). - , .
  3. ( ) DDoS OSI ( 3).

    image

    3. DDoS

    . - .


! , .



, . , , , ( , .).



, - , . DDoS- Ā« Ā».




All Articles