Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
Microsoft details 'Windows on ARM' program
March debut of 'iPad 3' a sure bet, says analyst
FBI unbolts Steve Jobs 1991 investigation file
Cisco boosted profit, sales in Q2 while cutting costs
Macs take on the enterprise
Four crazy tech ideas from Google's Solve for X project
Obama 2012 campaign playlist revealed courtesy of Spotify
Oracle buying Taleo for US$1.9 billion in direct hit at SAP
Amazon attacks Apple: You get 3 Kindle products for price of iPad 2
Pre-rendered pages highlight latest Google Chrome release
Microsoft exec: Lync-Skype integration a 'compelling opportunity'
The future of hypervisors
/

Canadian carrier TELUS adds DoS security protection to backbone net

Today's breaking news
Send to a friendFeedback


TELUS, the second largest telecomunications carrier in Canada, said it is deploying Arbor Networks' denial-of-service product Peakflow DoS to protect its Internet backbone from attacks on TELUS and its customers.

With its announcement this week, TELUS becomes the first known telecom carrier to make a major commitment to installing equipment for combating the wide variety of denial-of-service attacks, including the type called distributed denial-of-service attacks in which IP floods directed from hundreds of sources by a single attacker can quickly overwhelm servers and routers. Arbor competes against a handful of other vendors, including Mazu Networks, which specializes in distributed denial-of-service network defense.

TELUS, which said Arbor was selected in a competition that included two other vendors it declined to name, has initially deployed Arbor's Peakflow denial-of-service equipment on multiple OC-3 links at four major hubs on its Internet backbone.

There, the Arbor antidenial-of-service equipment will detect and analyze traffic transversing high-speed Cisco routers, said Leonard Hendricks, director of marketing at TELUS. These four hubs, in the Canadian provinces of British Columbia, Alberta as well as two in Ontario, will be able to collect data from across the larger Canadian cities in order to recommend appropriate action should a denial-of-service attack be detected. Until now, TELUS engineers had been forced to do this type of analysis in a more manual fashion, Hendricks said.

"A denial-of-service attack can be difficult to nail down," Hendricks said. "In the past, we had a reactive approach."

A customer might phone in to ask for help in fending off what was suspected of being a denial-of-service attack on a Web site, and TELUS would have its engineers look at the routers and try to block it. In the case of such attacks, "It could take some time to either find out if it's an actual attack or just a hardware failure," Hendricks said.

In the few months since TELUS deployed the Arbor equipment, the carrier has been able to get a far better picture of what's happening in terms of the denial-of-service threat. "We discovered we can see a lot more attacks than we had been able to in the past," Hendricks said.

TELUS uses the Remedy trouble-ticketing system, and it has integrated use of Arbor Peakflow DoS into Remedy so that the Arbor reporting console can issue a trouble-ticket that can be shared with the Remedy.

Although Arbor Peakflow DoS, which works by analyzing traffic through routers, can be configured to automatically take action against perceived attack by blocking traffic streams, TELUS said it prefers that any blocking "be done by humans," Hendricks said. "The big fear is that an automated system could block out legitimate traffic."

TELUS is deploying the antidenial-of-service equipment initially to protect its own core backbone, and in the next few months will be deploying additional Arbor gear at the edge of customer networks and in its Web-hosting centers. This is costing TELUS less than $2 million, according to Hendricks.

Canadian ISPs are counted among TELUS customers. And TELUS hopes that its ability to analyze denial-of-service attacks more efficiently will be a "differentiation for selling to ISPS," Hendricks said. TELUS has no specific plans that would call for marketing denial-of-service protection as a value-added service. That's a topic that's gotten a lot of discussion from U.S. ISPs, though none have made a public commitment to purchase antidistributed denial-of-service gear yet as TELUS just did.

RELATED LINKS

Contact Senior Editor Ellen Messmer

Other recent articles by Messmer

Error 404--Not Found

Error 404--Not Found

From RFC 2068 Hypertext Transfer Protocol -- HTTP/1.1:

10.4.5 404 Not Found

The server has not found anything matching the Request-URI. No indication is given of whether the condition is temporary or permanent.

If the server does not wish to make this information available to the client, the status code 403 (Forbidden) can be used instead. The 410 (Gone) status code SHOULD be used if the server knows, through some internally configurable mechanism, that an old resource is permanently unavailable and has no forwarding address.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.