netsec-sig - Re: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?
Subject: Internet2 Network Security SIG
List archive
Re: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?
Chronological Thread
- From: Brad Fleming <>
- To:
- Subject: Re: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?
- Date: Tue, 20 Nov 2018 14:20:03 -0600
- Ironport-phdr: 9a23:LiYriRGSgtV/Iz2OxK3UDZ1GYnF86YWxBRYc798ds5kLTJ78rs2wAkXT6L1XgUPTWs2DsrQY07qQ6/iocFdDyK7JiGoFfp1IWk1NouQttCtkPvS4D1bmJuXhdS0wEZcKflZk+3amLRodQ56mNBXdrXKo8DEdBAj0OxZrKeTpAI7SiNm82/yv95HJbAhEmDmwbaluIBmqsA7cqtQYjYx+J6gr1xDHuGFIe+NYxWNpIVKcgRPx7dqu8ZBg7ipdpesv+9ZPXqvmcas4S6dYDCk9PGAu+MLrrxjDQhCR6XYaT24bjwBHAwnB7BH9Q5fxri73vfdz1SWGIcH7S60/VDK/5KlpVRDokj8KOT4l/27Yl8J+gqxbrgyjqBJ8xIDZe46VOOZ7fq7HfdMWWWhMU8BMXCJBGIO8aI4PAvIcMOZCtYbyukYFoxu6BQayAePvyzlIhnDr1qA9yOsuDA/G3Ag+ENILsXTUqtr1ObwRUe+vyqnI1yvMb/VM1Tf79ofIbgksrPeRVrxzacrc0VcjGgLZgliSrIHlMTCY2f8Rv2We4OdtVuOihmEipg1vvjSiw8IhhpfXio8R0lzI6CR0zYkvKdGlVUJ2b8SoHIZUuiyZLYd6X90uT31utS0n0LMJo4S7czIPyJk/xx7QdfiHc4+Q7xLmTumRIDN4iGtieLK+mhq+6EehxvPiWsSwylpKoS1Fkt7DtnAJyRPf8NSISvx4/ku52DaP0R7c6v1cLEwqlKfXN5wsz7s+lpcQqkvPAir7lUr1gaKXeUgp//ak5/jib7jjuJOQKYt5hhn7Mqs0m8y/Beo4MhIJX2ie4emzz6Ds/UP9QLpUi/02k6/ZsJ/BKMQYvKG5BRVV3Zgl6xqlCTepzsgYkWEdLF1ZYBKHk5TpO1bWLfDjE/iwn0mskC1qx/DaPrztG5vMLnfYnbflfLZ98FJcyBEtwdxF5pJUDK0BL+zpWk/3qtPYEgE1PxaqzOn6FdUunr8ZDHmCCbKDMb/D9ECHzuMpP+SWYoIJ4nDwJ+V2yeTpiCoTg1YRNYet0J4Wbn/wSv5qLUGUZHvqjf8CGGEQswx4SuH23g7RGQVPbmq/CvpvrgowD5irWN/O
Here’s the general flow for KanREN.. 1) We dump IPFIX from our routers to Kentik. 2) Build rules in Kentik which identify traffic patterns we find suspicious. 3) Kentik fires an event to an on-network application we wrote. a) It does some basic triage and presents the alarm in a KanREN staff portal. 4) If a human agrees with the alarm we can trigger a scrub route from the web interface. 5) Application does a netconf push to a Juniper vMX trigger box we use for RTBHR, flowspec, sBHR, and scrubbing which then signals to the core network. Releasing the scrub route is currently a manual process. We have to watch the event in the Zenedge dashboard or simply guess when we think the event has passed. Releasing the scrub route is also done via the web interface. We can also add an event via the web interface if a Kentik rule didn’t catch something. All of this could be automated; we’re just worried about false positives in the Kentik ruleset we created. We’re also not 100% we have the API calls correct to get status from the ZE portal. Having a human check it (or communicate with their SOC) provides some degree of final check. We have a few members with /24 assignments from ARIN. For that reason we have to do some routing table tricks to keep those /24s in our internal route table but remove them from all the upstream transit carriers. The attached diagram kinda shows the problem; it was drawn mainly for the internal technical group at KanREN so you might see references to some communities that don’t make sense. And of course we allow BGP-speaking members to signal scrub routes to us directly via community string which makes all the routing messes simpler by a country mile. If anyone is interested I can share some screenshots of our web interface. -- Brad Fleming Assistant Director for Technology Kansas Research and Education Network Office: 785-856-9805 Mobile: 785-865-7231 NOC: 785-856-9820 |
Attachment:
zenedge routing design.graffle.pdf
Description: Adobe PDF document
|
Attachment:
smime.p7s
Description: S/MIME cryptographic signature
- [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?, Magorian, Daniel F., 11/20/2018
- Re: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?, James Deaton, 11/20/2018
- Re: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?, Sullivan, Jason W - (jsullivan), 11/20/2018
- RE: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?, Magorian, Daniel F., 11/20/2018
- Re: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?, Mark Montalto, 11/20/2018
- Re: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?, Sullivan, Jason W - (jsullivan), 11/20/2018
- RE: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?, Magorian, Daniel F., 11/20/2018
- Re: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?, Sullivan, Jason W - (jsullivan), 11/20/2018
- Re: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?, Brad Fleming, 11/20/2018
- RE: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?, Magorian, Daniel F., 11/20/2018
- Re: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?, David Farmer, 11/20/2018
- Re: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?, Brad Fleming, 11/20/2018
- RE: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?, Magorian, Daniel F., 11/20/2018
- [Security-WG] Re: What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?, Beals, Damon G, 11/21/2018
- Re: [Security-WG] What tools do people use to trigger Zenedge/Oracle Dyn's scrubbing service?, James Deaton, 11/20/2018
Archive powered by MHonArc 2.6.19.