Business Challenge |
There are varieties of DoS/DDoS attacks, including DoS attacks against system (e.g. Ping of Death) and against application layer (e.g. Http Get Flood, Connection Flood, CC etc.) as well as DDoS attacks against traffic (e.g. SYN Flood, UDP Flood, ACK Flood.) Judging from the previous attack instances, DoS/DDoS attacks pose a great impact on IDC business, and cause great damages:
- Compromise of important user severs: lose core clients
- Occupation of IDC line bandwidth resources: decrease service quality
- Varied and complicated application layer attack: lose profitable clients
|
Solutions NSFOCUS has been focusing on how to defend DDoS traffic flow in the MAN environment all the time. Taking advantage of the COLLAPSAR Anti-DoS system, which enjoys favorable fame in the security industry, NSFOCUS has implemented the solution of NC2M, NSFOCUS Collapsar CleanMatrix. The NC solution could guarantee the smooth operation of a core network by adopting multi-layered attack flow detection, protection and sanitization mechanism, with which COLLAPSAR could detect all varieties of attack flow in the background flows timely, and sanitize malicious flow from the network by means of the traffic diversion technique in a bypass deployment.
With the development of network utility construction and the advent of new IDC businesses, IDC sees its new period of development. The participation of telecom service providers into the IDC market promotes the construction of grade-1 IDC network utility, from the previous single link stack connection to the present 1000M dual link, and even 2.5G POS link. In the IDC deployment, the core layer comprises of two core switches, which are connected with the access router on the upper, and user server layer through the access switch on the lower. The whole IDC network and business is under the administration of operation and maintenance management network. As one part of the telecom operator MAN, the upper access router is the MAN backbone of the border router.
We specially recommend the COLLAPSAR bypass deployment to typical IDC dual link:
Fig. NSFOCUS Collapsar CleanMatrix: Large Data Center Traffic Sanitization
Advantages NC2M(NSFOCUS Collapsar CleanMatrix) has the following advantages for the traffic sanitization in a MAN core network.
- Special anti-DDoS device: Wide range of customers and complicated businesses of MAN access clients, commercial competition and other factors make multiple kinds of large traffic DDoS attack easy to launch.NSFOCUS Collapsar, anti-DoS attack system could fully protect against the attacks.
- New value-added service business for IDC operators with centralized protection and anti-DDoS device renting: NSFOCUS Collapsar CleanMatrix could guarantee the IDC network traffic sanitization, and at the same time provide operators with value-added services. This can solve the DoS attack problem for most clients concentratively, promote the overall service quality and competition capability of IDC and increase profits for IDC.
- Comprehensive event handling and emergency response mechanism enables timely and efficient protection against DDoS attacks: NSFOCUS could provide comprehensive and easy-to-use anti-DDoS system for MAN operators taking advantage of its perfect solution, powerful technical support, timely emergency response and in-depth network security research.
Why Choose NSFOCUS
Founded in April 2000, NSFOCUS Information Technology Co., Ltd.(NSFOCUS) is one of the earliest hi-tech enterprises in China that is dedicated to network security.
Powered by its years of security vulnerability research and security product development capacity, NSFOCUS provides security research reports for those internationally well-known vendors including Microsoft, Sun, Cisco, HP, etc., as well as top-level security products and comprehensive security solutions for government agencies, telecom, financial, energy and other industries, in an attempt to help the customers build a reliable and peaceful network environment. NSFOCUS has powerful security service capability and develops abundant long term customers.
We have put forward the NSPS security service system early in 2000, and taken the lead in passing the ISO 9001 certifications in the network security industry.
The security products and solutions of NSFOCUS cover Network Intrusion Detection/Prevention System, Remote Security Assessment System, Anti-DoS System, Security Audit System, Intranet Security Management System, Network Behavior Anomaly Detection System, and security solutions for various applications in the government, army and enterprises network, as well as in MAN telecom network. |