百家乐怎么玩-澳门百家乐官网娱乐城网址_网上百家乐是不是真的_全讯网888 (中国)·官方网站

DDoS Protection of JUCC

by Wilson Wong, S K Tsui, Alex Lam
 
A Distributed Denial-of-Service (DDoS) attack is a cyber-attack, which an attacker tries to overload the targeted server/system with a huge volume of traffic from multiple, distributed sources (usually zombie computers), making the server/system unavailable to its intended users. As the attacks come from a large number of PCs in different areas, it is impossible to stop these attacks simply by blocking accesses from an area. To mitigate the damage from a DDoS attack, a pool of devices that scrutinises inbound traffic before it hits the targeted system is required.
 
According to the published by Deloitte, the number of DDoS attacks in 2017 will become large in scale, harder to mitigate, and more frequent. They expect that there will be over 10 million DDoS attacks in total globally. In view of the increase in the number of DDoS attacks against Hong Kong's local universities, the Joint Universities Computer Centre (JUCC) has decided to employ the DDoS protection services from Nexusguard with an aim to ensure uninterrupted services in the local institutions of higher education.
 
Starting from the second half of 2016, the Computing Services Centre (CSC, CityU) has been working with Nexusguard to implement the DDoS protection for the university’s IT services. Technically, there are several types of DDoS attacks, such as SYN, TCP, HTTP floods and Domain Name System (DNS) attacks, which attack different parts/layers of the IT infrastructure. The protection platform of Nexusguard is thus comprised of three pillars, namely Application Protection, DNS Protection and Origin Protection, to block attacks on different components of the IT infrastructure. We shall briefly discuss them in turn below.
 
Application Protection

Application Protection provides DDoS protection for web servers by scrutinising traffic in the Nexusguard’s Scrubbing Centres. 
 
By changing the DNS record, all traffic to the web servers will be redirected to the scrubbing centre first. If in case there is a DDoS attack against the protected web servers, the scrubbing centre, which is equipped to handle huge volume of traffic, will filter all the attacks and pass only the legitimate traffic to the protected web servers by means of reverse proxy. Thus, the protected web servers can continue to provide services to users without any interruption.
 
Currently, the CityU Announcement Portal (CAP) is protected via the Application protection service. We will put other central web servers under the same DDoS protection in the near future.
 
DNS Protection

The DNS is a hierarchical decentralized naming system to translate a host name into IP address(es) connected to the Internet.
 
We utilise Nexusguard’s DNS protection service to protect CityU from DNS attacks by transferring the zone file of the “cityu.edu.hk” domain to the Nexusguard’s DNS cluster and including Nexusguard’s DNS cluster in the authoritative name server list of the “cityu.edu.hk” domain.  
 
By leveraging anycast technology and redundant caching, Nexusguard’s solution performs load balancing across their high-performance, global DDoS Mitigation Network to filter out and absorb all DNS attacks and malicious traffic, including:
  • DNS Amplification
  • NXDomain
  • Phantom Domain
  • Random Sub-domain
  • Look-up Domain

Origin Protection

In addition to launching web application and DNS attacks, attackers may perform a volumetric attack that aims to consume all the available Internet bandwidth and resources of the University.  The latter is a typical example of a volumetric DoS or DDoS attack that will effectively block the network connectivity between the Internet and all campus users. 
 
“Origin Protection” is a solution that aims to protect against volumetric DoS or DDoS attacks by making use of the BGP routing protocol to redirect all CityU’s Incoming Internet network, including both legitimate traffic and attack traffic, to the Nexusguard’s worldwide scrubbing centres. 
 
These worldwide scrubbing centres, which collectively equipped with over 1.44Tbps of mitigation capacity, have significant capability and intelligence to “clean out” the attack traffic.  The resulting legitimate traffic will then be routed back to CityU via the dedicated GRE tunnels.   Thus,  the University will be protected from DoS and DDoS attacks that are becoming more common in the Internet environment.
 
Conclusion
 
The implementation of the above three pillars of protection is still in the process of fine tuning. It is expected to be completed in the third quarter of 2017. If staff or students experience any issues, especially when using the CityU Announcement Portal (CAP), please contact the CSC by sending an email to csc@cityu.edu.hk.
 
 
百家乐官网任你博娱乐场开户注册 | 百家乐官网游戏机价格| 网上百家乐赌场娱乐网规则| 老钱庄百家乐的玩法技巧和规则| 大发888在线投注| 五湖四海娱乐| 百家乐官网baccarat| 北京太阳城医院怎么样| 百家乐官网赌的技巧| 菲律宾百家乐官网赌场娱乐网规则| 大发888出纳柜台 在线| 景泰县| 最好的百家乐官网好评平台都有哪些 | 永康百家乐官网赌博| 赌场百家乐官网图片| 大发888国际娱乐bet| 百家乐投注方式| 百家乐赚水方法| 网上百家乐官网骗人不| 百家乐博彩通网| 博彩技巧| 闲和庄百家乐赌场娱乐网规则| 百家乐官网园36bol在线| K7百家乐的玩法技巧和规则 | 百家乐五湖四海赌场娱乐网规则| 百家乐官网一邱大师打法| 百家乐是娱乐场最不公平的游戏 | 百家乐赌场程序| 乐百家百家乐官网游戏| 百家乐7scs娱乐网| 真人百家乐官网什么平台| 大发888线上娱乐加盟合作| 博彩百家乐官网五2013124预测| 大发888 下载| 百家乐网址哪里有| 交口县| 百家乐公式软件| 百家乐官网玩法皇冠现金网| 太子百家乐的玩法技巧和规则| 风水24山代表什么| 博彩百家乐官网画谜网|