Solution Brief | Protector Cyber Controller for Service Providers | Check Point Software
Solution Brief | Protector Cyber Controller for Service Providers
To provide best-in-class cyber security protection to multiple tenants with multiple services and networks while still maintaining a reasonable cost structure, an operator requires tools that will provide advanced attack detection, comprehensive visibility combined with robust automation and orchestration for provisioning new services, applying mitigation activations, orchestrating traffic diversions, and providing reports and forensics to be used for in-depth investigations.
QUANTUM PROTECTOR CYBER CONTROLLER
Protector Cyber Controller provides service providers with a security management, orchestration, and automation solution. The solution offers the flexibility of deployment (inline, out-of-path (OOP), 1-tier and 2-tier mitigation) with a great degree of automation, orchestration, and visibility to accommodate for each service provider's specific needs and constraints, while considerably reducing operational overhead and overall costs.
Protector Cyber Controller is a central component in Check Point's DDoS infrastructure protection solution and enables a holistic solution for distributed infrastructure protection.
INFRASTRUCTURE PROTECTION FOR DISTRIBUTED NETWORKS
Check Point’s approach to addressing the challenges facing service providers involves three main components:
Distributed Detection
The ability to detect a single threat across the entire network by utilizing dedicated security and network elements placed strategically across the network. The detection component can detect both infrastructure and application DDoS threats by utilizing the Layer 4–7 in-line/Smart Tap solution.
Distributed Mitigation
The ability to mitigate attacks by utilizing several mitigation components, one after the other, typically located the furthest away from the protected infrastructure with the least disruption of traffic flow and effect on user experience. Mitigation components include usage of the network as the mitigation tier followed by Cloud as a second tier. Mitigation using the network tier is done by the enforcement of black hole policies by border gateway protocol (BGP) flow specification (flowspec).
Centralized Control
The overarching facilitator of the distributed network. It collects input from distributed detection elements and aggregates, correlates, and analyzes those inputs in the context of the protected service. It also implements security, availability, and scale logic and applies the optimal mitigation action based on the available distributed mitigation components.
ENSURING HIGH AVAILABILITY
Protector Cyber Controller can be deployed in high availability. This ensures service and business continuity. Cyber Controller’s high-availability architecture comprises two identical Cyber Controller nodes: active and standby. Both nodes communicate with each other and maintain full synchronization for both component state and configuration.
Cyber Controller creates a peer from each active/standby node to each router, resulting in two peer connections for each network element. If one node fails, the other node keeps the peer connections and the related announcements active. When the primary Cyber Controller node fails, the secondary node continues to communicate with all registered routers and third-party detectors with zero downtime.
SECURITY OPERATIONS (SECOPS) DASHBOARD - HEART OF CYBER CONTROLLER
At the heart of Protector Cyber Controller is SecOps – a comprehensive security and operations dashboard that provides a single pane of glass with top-notch visibility and analytics that includes details of all the incoming attacks and ongoing active protections, and a complete history of all the attacks and protections handled by the system. It enables the user to take swift and immediate actions, at the click of a button, such as the ability to manually activate/deactivate single or multiple protections, or to manually add/remove networks/classless interdomain routing from an ongoing protection.
NETWORK TRAFFIC ANALYTICS
Protector Cyber Controller introduces additional levels of analytics, comprising attack-time detailed analytics and peacetime traffic analytics. Both peacetime and attack-time analytics offer Top-N parameters such as top source and destination IPs, top applications being accessed, top protocols being used, and top ASNs (locations) from where services are being accessed. Attack-time data also includes top source and destination ports, TCP flags, packet size distribution, and more. In addition, weekly traffic trends and traffic anomaly analysis are also available. These new network visibility capabilities greatly contribute to an administrator's abilities to characterize and understand the traffic flows in the network, identify anomalies as they occur, and tie those into an ongoing attack. Network traffic analysis directly enhances the administrator's abilities to refine detection thresholds to perfection and set the proper actions and mitigations to block attacks.
CUSTOM THRESHOLDS SETTING
Custom threshold settings allow administrators to create detection thresholds for virtually any application or service they deploy, even if it is proprietary. This is done by setting the protocols and ports used for these services and setting the proper threshold values. Custom threshold setting provides great flexibility for Cyber Controller users to protect any and every service and application that they wish to deploy. In addition to this, Protector Cyber Controller adds a "weekly top talkers" trend table which allows administrators to set any threshold (standard or custom) in accordance with the actual traffic trends which their network experiences. This greatly enhances the administrators' ability to set detection thresholds to perfection.
FLEXIBILITY WITH CUSTOMIZED OPERATIONS
Protector Cyber Controller is able to activate and deactivate various types of predefined operations after a workflow rule entry and exit criteria are matched. As part of the predefined operations, Cyber Controller can divert, and block traffic based on a BGP or a flow Spec rule. Cyber Controller also enables the customer to define and program its own customized operations to match the unique needs of its network, ensuring that new customized operations are activated whenever protection is required in accordance with a rule criteria match within its workflow engine.
PROTECTOR CYBER CONTROLLER USE CASES
Cyber Controller supports four main deployment use cases:
Use Case 1: Out-of-path detection using Cyber Controller and Flow Detector.
Mitigation is accomplished using Check Point DDoS Protector installed in a local scrubbing center.
Use Case 2: Cyber Controller and third-party flow telemetry detector
This use case is essentially the same as use case 1, but detection is done using a third-party flow telemetry device (such as Nokia, Arbor, and Genie).
Use Case 3: Out-of-path detection via Flow Detector and mitigation by Cyber Controller on the peering edge router.
Use Case 4: Two-tier detection and mitigation.
This use case demonstrates detection and mitigation using a multi-tier solution, tailored to defend against sophisticated application-level (L7 / TLS) attacks.
PROTECTOR CYBER CONTROLLER FOR SERVICE PROVIDERS USE CASE BENEFITS
| Use Case | Attack Detection Method | Operation | Benefits |
|---|---|---|---|
| 1 | Flow Detector | Traffic diversion to scrubbing center using BGP / BGP Flowspec | Best quality-of-mitigation solution in the industry; wide attack coverage, mitigating all types of DoS/DDoS attacks; highest mitigation accuracy, blocks attack traffic without blocking legitimate user traffic; single pane of glass; single vendor solution |
| 2 | Third-party NetFlow-based detector | Traffic diversion to scrubbing center using BGP / BGP Flowspec | Best mitigation solution in the industry; wide attack coverage for all types of DoS/DDoS attacks; highest mitigation accuracy to block attack traffic without impacting legitimate user traffic |
| 3 | Flow Detector | BGP Flowspec Rate-limit / blocking anomaly traffic on router | Fast detection and mitigation (min –2sec); rich visibility - anomaly analytics, router dropping statistics. Non-intrusive – fully Out-of-path solution, no need to install machines in data path. |
| 4 | DDoS Protector | Local mitigation with DDoS Protector | Traffic diversion to scrubbing center using BGP; inject mitigation policy to peering DDoS Protector; shared mitigation policy between mitigation devices; set blackholing rule on peering router; on-premises attack mitigation by DDoS Protector; flexible operations per incident to resolve any service provider use case; application-layer protection; low and slow attack protection. |
SUMMARY
Protector Cyber Controller allows service providers to easily automate security incident response operations, even in the most complex and highly distributed environments. The cyber command and control application maximizes security effectiveness with minimal operational effort and overhead. Cyber Controller extends Check Point’s DDoS infrastructure protection solution by adding always-on/Smart Tap and hosted customer protection use cases, for service providers to provide the widest attack detection coverage coupled with immediate attack mitigation.