Multi-Layer DDoS Defense: Integrated on-premise and cloud-based mitigation for “always on” protection

 

Modern attackers are now combining traditional volumetric attacks designed to overwhelm network bandwidth with stealthy application-layer attacks designed to slowly exhaust network resources over time. This blended approach to DDoS is growing in popularity because it is highly effective and difficult to defend. To combat today’s full spectrum of DDoS attacks, security experts recommend a hybrid solution that integrates cloud-based mitigation and on-premise protection.

RioRey provides a scalable, multi-layer DDoS defense solution by combining powerful on-premise protection for infrastructure and application-layer attacks with an on-demand cloud-based scrubbing service for volumetric attacks that otherwise overwhelm the network. 


How It Works

RioRey’s comprehensive line of on-premise equipment is placed at the networks edge for “always on” protection against 25 classes of DDoS attacks. Our on-premise equipment quickly and automatically detects and mitigates attack traffic. This is the best mode of protection for most DDoS attacks.

 
  Traffic routed to cleaning center using BGP announcements. Good traffic returned via GRE tunnels.     
  
 
  
    
  
 Normal 
 0 
 
 
 
 
 false 
 false 
 false 
 
 EN-US 
 JA 
 X-NONE 
 
  
  
  
  
  
  
  
  
  
  
 
 
  
  
  
  
  
  
  
  
  
  
  
  
    
  
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
  
   
 
 /* Style Definitions */
table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-parent:"";
	mso-padding-alt:0in 5.4pt 0in 5.4pt;
	mso-para-margin:0in;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:12.0pt;
	font-family:Cambria;
	mso-ascii-font-family:Cambria;
	mso-ascii-theme-font:minor-latin;
	mso-hansi-font-family:Cambria;
	mso-hansi-theme-font:minor-latin;}

Traffic routed to cleaning center using BGP announcements. Good traffic returned via GRE tunnels.

 

Only in the case of a high volumetric attack will traffic be rerouted to RioRey’s cloud-based scrubbing center before it reaches your network. At the scrubbing center, attack traffic is mitigated and legitimate traffic is redirected back to your network. When the DDoS attack has subsided, mitigation operations will revert back to on-premise protection.  


Central Management and Reporting on rWeb

rWeb is RioRey’s premier management and reporting system that provides browser-based management for all RioRey on-premise protection. In addition, the management and reporting capabilities provided by the customer portal at the scrubbing center will be consistent with the operator’s experience with rWeb on the customer’s premise.

                                                                  Scrubbing Center Portal

                                                                Scrubbing Center Portal

rWeb gives network operators complete visibility into the traffic passing through their network and a comprehensive range of tools to quickly analyze attack traffic. This makes the decision-making process of transferring traffic between on-premise and cloud-based scrubbing straightforward. In addition, rWeb has a robust API that makes all functions available for integration into external systems and provides almost unlimited reporting flexibility.

RioRey’s layered approach to DDoS attacks enables businesses to deploy and manage best-practices defense with a single solution that integrates on-site and in-cloud DDoS protection.