Skip to Content.
Sympa Menu

netsec-sig - Re: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?

Subject: Internet2 Network Security SIG

List archive

Re: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?


Chronological Thread 
  • From: Brad Fleming <>
  • To:
  • Subject: Re: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?
  • Date: Tue, 20 Nov 2018 14:20:03 -0600
  • Ironport-phdr: 9a23:LiYriRGSgtV/Iz2OxK3UDZ1GYnF86YWxBRYc798ds5kLTJ78rs2wAkXT6L1XgUPTWs2DsrQY07qQ6/iocFdDyK7JiGoFfp1IWk1NouQttCtkPvS4D1bmJuXhdS0wEZcKflZk+3amLRodQ56mNBXdrXKo8DEdBAj0OxZrKeTpAI7SiNm82/yv95HJbAhEmDmwbaluIBmqsA7cqtQYjYx+J6gr1xDHuGFIe+NYxWNpIVKcgRPx7dqu8ZBg7ipdpesv+9ZPXqvmcas4S6dYDCk9PGAu+MLrrxjDQhCR6XYaT24bjwBHAwnB7BH9Q5fxri73vfdz1SWGIcH7S60/VDK/5KlpVRDokj8KOT4l/27Yl8J+gqxbrgyjqBJ8xIDZe46VOOZ7fq7HfdMWWWhMU8BMXCJBGIO8aI4PAvIcMOZCtYbyukYFoxu6BQayAePvyzlIhnDr1qA9yOsuDA/G3Ag+ENILsXTUqtr1ObwRUe+vyqnI1yvMb/VM1Tf79ofIbgksrPeRVrxzacrc0VcjGgLZgliSrIHlMTCY2f8Rv2We4OdtVuOihmEipg1vvjSiw8IhhpfXio8R0lzI6CR0zYkvKdGlVUJ2b8SoHIZUuiyZLYd6X90uT31utS0n0LMJo4S7czIPyJk/xx7QdfiHc4+Q7xLmTumRIDN4iGtieLK+mhq+6EehxvPiWsSwylpKoS1Fkt7DtnAJyRPf8NSISvx4/ku52DaP0R7c6v1cLEwqlKfXN5wsz7s+lpcQqkvPAir7lUr1gaKXeUgp//ak5/jib7jjuJOQKYt5hhn7Mqs0m8y/Beo4MhIJX2ie4emzz6Ds/UP9QLpUi/02k6/ZsJ/BKMQYvKG5BRVV3Zgl6xqlCTepzsgYkWEdLF1ZYBKHk5TpO1bWLfDjE/iwn0mskC1qx/DaPrztG5vMLnfYnbflfLZ98FJcyBEtwdxF5pJUDK0BL+zpWk/3qtPYEgE1PxaqzOn6FdUunr8ZDHmCCbKDMb/D9ECHzuMpP+SWYoIJ4nDwJ+V2yeTpiCoTg1YRNYet0J4Wbn/wSv5qLUGUZHvqjf8CGGEQswx4SuH23g7RGQVPbmq/CvpvrgowD5irWN/O

Here’s the general flow for KanREN..

1) We dump IPFIX from our routers to Kentik.
2) Build rules in Kentik which identify traffic patterns we find suspicious.
3) Kentik fires an event to an on-network application we wrote.
a) It does some basic triage and presents the alarm in a KanREN staff portal.
4) If a human agrees with the alarm we can trigger a scrub route from the web interface.
5) Application does a netconf push to a Juniper vMX trigger box we use for RTBHR, flowspec, sBHR, and scrubbing which then signals to the core network.

Releasing the scrub route is currently a manual process. We have to watch the event in the Zenedge dashboard or simply guess when we think the event has passed. Releasing the scrub route is also done via the web interface. We can also add an event via the web interface if a Kentik rule didn’t catch something.

All of this could be automated; we’re just worried about false positives in the Kentik ruleset we created. We’re also not 100% we have the API calls correct to get status from the ZE portal. Having a human check it (or communicate with their SOC) provides some degree of final check.

We have a few members with /24 assignments from ARIN. For that reason we have to do some routing table tricks to keep those /24s in our internal route table but remove them from all the upstream transit carriers. The attached diagram kinda shows the problem; it was drawn mainly for the internal technical group at KanREN so you might see references to some communities that don’t make sense.

And of course we allow BGP-speaking members to signal scrub routes to us directly via community string which makes all the routing messes simpler by a country mile. 

If anyone is interested I can share some screenshots of our web interface.
--
Brad Fleming
Assistant Director for Technology
Kansas Research and Education Network
Office: 785-856-9805
Mobile: 785-865-7231
NOC: 785-856-9820

Attachment: zenedge routing design.graffle.pdf
Description: Adobe PDF document


On Nov 20, 2018, at 12:41 PM, Magorian, Daniel F. <> wrote:

Hello Security WG folks!

We are having issues with ZenEdge/Oracle Dyn's RapidBGP triggering of their scrubbing, and while they're figuring that out, I thought I would ask people what tools they use to trigger scrubbing of subsets of your prefixes.  

Yes, I know several folks have Arbox Peakflow boxes for on-prem scrubbing, and use these to signal Zenedge's as well.  

So does anyone have a netflow-based tool that seems to work well?

Thanks,  Dan

-----Original Message-----
From: Magorian, Daniel F.
Sent: Wednesday, October 3, 2018 10:34 AM
To:
Subject: RE: [Security-WG] What are folks' experience using Zenedge's scrubbing service....

We have the RapidBGP alerting service, and the main issue is false positives from stuff like big user downloads and high volume of inbound traffic to our Forcepoint/Websense http proxies.  They're supposed to trigger on multiple criteria not just volume, but when we complain to their tech support, they respond a few days later saying they'll adjust something or other, all very non-transparent.  They have also promised more useful stuff in the portal; right now it doesn't even know about the alerts they've sent you email about, basically broken.  Still a work in progress...  

Dan

-----Original Message-----
From: <> On Behalf Of Steven Wallace
Sent: Wednesday, October 3, 2018 10:25 AM
To:
Subject: [Security-WG] What are folks' experience using Zenedge's scrubbing service....

Greeting all,

Grateful if folks could share their experience using Zenedge’s scrubbing service. Specifically, how does engaging, and removing, the scrubbing service affect access to the hosts being scrubbed.

Is there a hit? Do users notice?

Thanks,

Steve


Attachment: smime.p7s
Description: S/MIME cryptographic signature




Archive powered by MHonArc 2.6.19.

Top of Page