automated traffic and your aws environment_b

20
Automated Traffic And Your AWS Environment David Dowling June 2015 – AWS User Group Melbourne

Upload: david-dowling

Post on 14-Apr-2017

206 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Automated Traffic And Your AWS Environment_B

Automated Traffic And Your AWS Environment David Dowling June 2015 – AWS User Group Melbourne

Page 2: Automated Traffic And Your AWS Environment_B

Don’t Worry! This Is Not A Sales Pitch

Page 3: Automated Traffic And Your AWS Environment_B

Amazon Web Services

Page 4: Automated Traffic And Your AWS Environment_B

Bot Report 2014

Page 5: Automated Traffic And Your AWS Environment_B

Types of Automation

• Good Automation = CloudFormation, Auto Scaling Elastic Load Balancing and Googlebots

• Bad Automation = Site scraping, SQL Injection, fake Googlebots, DDoS bots

Page 6: Automated Traffic And Your AWS Environment_B

AWS Address Space Is Frequently Scanned

Page 7: Automated Traffic And Your AWS Environment_B

Googlebot Or DDoS Impersonator?

Page 8: Automated Traffic And Your AWS Environment_B

So, Like, What Does This Have To Do With AWS?

• If you can reduce malicious automated traffic hitting web servers you can control expenditure and reduce noise for the Security and DevOps teams

Amazon ELB

AmazonELB

Web servers

Amazon ELB

Web servers

Scaling Group

Availability Zone 1

Availability Zone 2

Page 9: Automated Traffic And Your AWS Environment_B

Quiz Time – Which Country Has The Largest Amount of Attack Traffic?

1. People’s Republic of China

2. Russia

3. One of the Stans

4. United States of America

Page 10: Automated Traffic And Your AWS Environment_B

The US And Alaska?

Page 11: Automated Traffic And Your AWS Environment_B

Application Denial of Service (DoS)

Page 12: Automated Traffic And Your AWS Environment_B

Torshammer script

Page 13: Automated Traffic And Your AWS Environment_B

Torshammer result

Page 14: Automated Traffic And Your AWS Environment_B

DDoS Attacks On Sites In AWS

• GreatFire.Org gets DDoS by a Nation-state

• “Because of the number of requests we are receiving, our bandwidth costs have shot up to USD $30,000 per day”

Page 15: Automated Traffic And Your AWS Environment_B

Do You Really Want A 253 Gig DDoS Attack On Your AWS Instance?

Page 16: Automated Traffic And Your AWS Environment_B

Site Scraping – Why?

Media – Steal page views

E-Business – Steal ad revenue

Insurance – rate harvesting and then undercutting

Social Media – Stealing user data to create fake accounts

Transportation – systematically undercutting pricing

Government Agencies – List harvesting

Page 17: Automated Traffic And Your AWS Environment_B

Lovely Faces – Aka your Facebook profile photo scraped from Facebook

Page 18: Automated Traffic And Your AWS Environment_B

AWS Test Drive

https://www.imperva.com/ld/aws_testdrive.asp

Page 19: Automated Traffic And Your AWS Environment_B

More Information?

[email protected] or 0403 803 804 • AWS share a lot of great stuff on SlideShare

• www.Blog.Imperva.com

• http://www.botopedia.org/

• Verizon Data Breach Report

Page 20: Automated Traffic And Your AWS Environment_B