下载PDF
Manufacturer Improves Network Perimeter Defense and DDoS Prevention With Arbor Edge Defense
技术
- 网络安全和隐私 - 入侵检测
- 网络安全和隐私 - 网络安全
适用功能
- 离散制造
- 质量保证
用例
- 网络安全
- 入侵检测系统
- 周边安全与访问控制
服务
- 网络安全服务
- 系统集成
挑战
该公司的安全运营 (SecOps) 团队在保护网络边界方面面临挑战。该过程主要是手动的,包括在防火墙级别维护 IP 地址的滚动列表(即黑名单)。任何可能被视为恶意行为者的新 IP 地址都会由 SecOps 资源手动添加到“列表底部”。由于 IP 地址列表规模庞大、维护所需的手动工作量以及准确性和时效性问题,这种方法被证明是低效的。随着公司网络和数据中心运营的增长以及随之而来的威胁形势的扩大,SecOps 需要下一代边界安全解决方案,以更好地保护业务并补充 nGeniusONE 和智能可视性解决方案已经为跨 IT 资源提供的功能。
关于客户
客户是一家美国制造商,生产多个品牌的重型设备。该公司在十几个国家设有生产工厂,并努力遵守高质量的工业标准,这有助于该公司保持其世界级制造商的地位。该公司的信息技术 (IT) 团队长期使用其 NETSCOUT nGeniusONE® 服务保障解决方案,该解决方案采用 InfiniStreamNG® (ISNG) 和数据包流交换机 (PFS) 技术,在其数据中心和总部位置进行实时数据包监控。与网络运营 (NetOps) 协调后,安全运营 (SecOps) 团队通过访问 nGeniusONE 分析和智能数据可视性源,进行基于数据包的取证,以进行与事件相关的故障排除,从而从公司对 NETSCOUT 的投资中获得了额外的价值。
解决方案
该公司通过部署 NETSCOUT Arbor Edge Defense (AED) 解决方案,改变了其网络边界防御策略,并自动实施 DDoS 攻击防护。借助 AED,SecOps 实现了与在其防火墙上定义“拒绝”和“允许”列表相关的流程的自动化,从而增强了网络边界安全性,并更好地保护了公司的制造业务。AED 以内联方式(即在互联网路由器和防火墙之间)部署在 NETSCOUT 已利用的相同链路上,以将网络数据包流量传送到长期部署的 ISNG 和 PFS 智能可视性源,这些源负责实时生成 nGeniusONE 分析使用的智能数据。除了提高网络边界安全性和防火墙效率外,AED 还为 SecOps 配备了阻止高达 40 Gbps 的 DDoS 攻击的功能。使用 NETSCOUT 的无状态数据包处理技术,SecOps 还可以使用 AED 阻止针对和影响有状态设备(如下一代防火墙)的 TCP 状态耗尽攻击。
运营影响
相关案例.
Case Study
Protecting a Stadium from Hazardous Materials Using IoT2cell's Mobility Platform
There was a need for higher security at the AT&T Stadium during the NFL draft. There was a need to ensure that nuclear radiation material was not smuggled inside the stadium. Hazmat materials could often be missed in a standard checkpoint when gaining entry into a stadium.
Case Study
Enel Secures Italian Power Generation Network
Electric energy operators around the world are working to increase the reliability and cyber resiliency of their systems. This includes Enel, a global power company that manages and monitors the Italian power grid. This grid:• Serves 31 million customers• Has a net installed energy capacity exceeding 31 gigawatts• Includes more than 500 power generation plants,including hydroelectric, thermoelectric, and wind• Is managed and monitored by Enel 24/7/365• Is operated by Terna, the Italian Transmission System Operator (TSO)Enel is responsible for the availability of the grid’s underlying ICS and industrial network. It also manages Regional Control Centers and Interconnection Centers which connect with the TSO. The TSO manages the flow of energy to the grid plus controls and remotely regulates the power generation of power plants, increasing and decreasing power production as required. The complex system of interaction and cooperation between Enel and the TSO has strong security implications as well as operational and business challenges.
Case Study
Securing the Connected Car Ecosystem
In-vehicle communications and entertainment system hosts high-value or sensitive applications. API libraries facilitate communication and sharing of vehicle data. These API libraries are vulnerable to reverse engineering and tampering attacks and may even result in loss of passenger safety. Attackers can inject malware that may be able to migrate to other in-car networks such as the controller-area-network (CAN) bus which links to the vehicle’s critical systems. Software provided for dealers to interface with cars through the OBD2 port is vulnerable to reverse engineering and tampering attacks. Hackers may be able to abuse these tools to inject malicious code into the ECUs and CAN bus. Attackers can lift the cryptographic keys used, and use that to build their own rogue apps/software. Their cloned version of the original app/software may have altered functionality, and may intend to gain access to other in-car networks.
Case Study
Secure and Cloud-based Data Marketplace
The great promise of new connected concepts of industry like 'Industry 4.0' is their ability to deliver a historically unparalleled level of responsiveness and flexibility. While modern supply chains are already heavily integrated and designed to be fluid and fast moving, a large swathe of manufacturing still remains beholden to economies of scale, large production runs, and careful preplanning.The Industrial Internet of Things (IIoT) is set to change this by allowing small-batch or even custom manufacturing on a truly industrial scale. With machines whose functions are not set in stone, but flexible and determined by their operating software and with a new form of connectivity bringing industrial engineers, product manufacturers, and end users closer together than ever before. Ad-hoc adjustments to automotive parts, for example, during active product runs or the bespoke manufacturing of custom sneakers become very viable options indeed.Much of this remains a theoretical vision, but IUNO, the German national reference project for IT security in Industry 4.0 demonstrates the new capabilities in action with a secure technology data marketplace running a smart drinks mixer.
Case Study
Expedia Hosted by 2lemetry Through AWS
Expedia is committed to continuous innovation, technology, and platform improvements to create a great experience for its customers. The Expedia Worldwide Engineering (EWE) organization supports all websites under the Expedia brand. Expedia began using Amazon Web Services (AWS) in 2010 to launch Expedia Suggest Service (ESS), a typeahead suggestion service that helps customers enter travel, search, and location information correctly. According to the company’s metrics, an error page is the main reason for site abandonment. Expedia wanted global users to find what they were looking for quickly and without errors. At the time, Expedia operated all its services from data centers in Chandler, AZ. The engineering team realized that they had to run ESS in locations physically close to customers to enable a quick and responsive service with minimal network latency.