Forum Discussion

Mogens_Bluhme_N's avatar
Mogens_Bluhme_N
Icon for Nimbostratus rankNimbostratus
Jun 28, 2015

The Business value of IP Reflection in Silverline DDOS Protection

Does IP Reflection mean that you can hide for an attacker that you are protećted by a scrubbing center?

 

What would a traceroute reveal?

 

If he knows that he would probably change strategy - run heavy SSL-attack and by observing response times could guess whether or not the scrubbing center has the private key.

 

He could also try to look for the real IP adresses or generate randomized strings in get/post-requests to bypass the center.

 

  • With Silverline DDOS, F5 scrubbing network do not have your private keys (that's for Silverline WAF). Layer7 attack are still to be mitigated by the customer. But there is a communication API between BIG-IP (by the customer) and the SOC which will enable blocking of source IPs performing those L7 attacks at the scrubbing network level.

     

  • http://www.google.com/patents/US20140245421

     

    double static-NAT. public <-> private at Scrubbing Center facing to Customer. private <-> public at Customer facing Scrubbing Center. due to same public IP between first and second translation, it could be seen as reflection

     

    public <-> private <-> public same IP same IP