DDoS_Protection_
DDoS_Protection_
DDoS Protection
DDoS
Integrated analytics correlates DDoS
and related events to focus on what
DNS Websites really matters
DDoS
Imperva DDoS Protection options are designed to meet your specific needs, whether you want protection
for websites, networks, DNS or individual IPs.
Centralized management
Imperva DDoS protection is part of a consolidated dashboard of cloud application
security services for the ultimate in ease of use. An optional connector integrates with
your SIEM (security information and event management) solution, whether it be HP
ArcSight, Splunk, McAfee Enterprise Security Manager, IBM QRadar, GrayLog, Sumo
Logic, or AlienVault USM Anywhere.
Unlike other solutions, our multi-layer approach to DDoS mitigation does not rely on
CAPTCHA challenges and we don’t reject legitimate users as attackers, even when
you are under heavy attack. Imperva transparent mitigation ensures your web visitors,
and your business, will never suffer during an attack.
DDoS
TCP FIN
TCP RESET
Legit Traffic
TCP ACK + PSH
Customer Customer
Imperva Network Router Infrastructure TCP Fragment
GRE Tunnel
DDoS
UDP
ICMP
On-demand
IGMP
Based on BGP (Border Gateway Protocol) routing, the Imperva on-demand service is
Sloloris
ideal for organizations that are particularly sensitive to any latency and want DDoS
protection only when needed. Even in the case of on-demand deployments, there is Spoofing
no need for a trigger call from your team to Imperva. In the event of an attack, traffic is
DNS flood
rerouted through Imperva data centers using Imperva-initiated BGP announcements.
All incoming network traffic is then directed to Imperva’s global network of full-stack Smurf
data centers where it is inspected and filtered. Only legitimate traffic is forwarded to
Ping of Death
your network via single or redundant GRE tunneling. We offer expertise in the areas of
BGP setup and ongoing configuration management and can offer full BGP switchover Mixed SYN + UDP or ICMP +
management via the Imperva services organization, so you can offload the responsibility UDP flood
for attack monitoring and switchover.
Attacks targeting Apache, Windows
or OpenBSD vulnerabilities
Always-on
Zero-day DDoS attacks
For organizations that need to react to DDoS attacks instantly and continuously, always-
Brute Force
on affords protection without the need to monitor for attacks or implement BGP routing.
With always-on protection, Imperva advertises your C Class subnet and routes all traffic Connection Flood
to our global network of DDoS mitigation data centers. Similar to on-demand we route
legitimate traffic to you via GRE tunneling. Unlike other always-on services, Imperva Teardrop
offers a 99.999% network uptime SLA and our industry-first 3-second mitigation SLA -
Reflected ICMP and UDP
critical requirements if you are considering an always-on solution.
HTTP Flood
Zero-day attacks
And more...
DDoS
CNAME Resolving
Legit
Legit Traffic
Traffic
Hybrid environments
Imperva DDoS protection for IPs is critical if you are migrating critical workloads
to the cloud but still need to run applications on-premises. Not just for websites,
this solution protects any service exposed to the Internet. Best of all, it is easy to
implement and manage.
Implementation of the service takes just minutes, and activation follows the TTL
settings of your name server. Once enabled, the Imperva proxy becomes your
authoritative DNS server, while you continue to manage your DNS zone files outside
of the Imperva proxy network.
Underlying our network and software are the Imperva Security Operations Center
engineers and security experts at Imperva Research Labs. These groups work
unremittingly, leveraging crowdsourcing techniques to uncover the most devious
emerging threats and attacks as they are happening. Because we control all of our
technology, we can quickly apply rules to stop threats—often in a matter of minutes
around the globe.
DDoS attack sizes in terms of Mbps and Mpps are growing unabated. We’ve already
seen 500Mbps attacks become common, but we can’t predict when and where attacks
of an even larger size and complexity will occur. So we built a software-defined network
that condenses our global network of DDoS Super PoPs into a single, massive 6+
Tbps DDoS mitigation engine that we can direct to an attack anywhere in the world,
on-demand. Most other services are only as large as the DDoS-enabled PoP nearest
you, and some rely on legacy, on-premises architectures which attackers can easily
overwhelm. Imperva has successfully mitigated, in less than 3 seconds, the largest
DDoS attacks in history, like a Layer 7 attack over 290,000 RPS (requests per second)
and Layer 3 attack over 650 million PPS (packets per second).
Defense in depth