Rootconf 2014

On devops and cloud infrastructure

Sameer Garg

@sameerg

DDOS mitigation @flipkart

Submitted May 12, 2014

In this talk we explore various types of attacks and what flipkart does for mitigation.

Outline

DDOS Attacks have been on the rise all over the world. This include Volumetric i.e. Layer 4 TCP / UDP and Application i.e. Layer 7 HTTP, MySQL.Volumetric attacks are all about muscling out the attacker at the upstream / scrubbing farms. The same cannot be done for Layer 7 attacks.

Traditional DDoS systems cannot catch Layer7 attacks as they all work on layer 4. There are inline solutions such as WAF, etc which looks at traffic and make profiles like IDP. But at scale all that becomes resource intensive and affects latencies. At flipkart we devised a solution that looks at logs from various layers, detects patterns and automatically blocks the attacker at the perimeter.

In this talk we explore various types of attacks and what Flipkart does for mitigation.

Requirements

Basic understanding of TCP/IP and Internet Routing protocols

Speaker bio

Sameer is a Senior Operations Engineer at Flipkart, India’s largest e-commerce website with multiple data centers and thousands of servers, where he works on website reliability, scalability and network performance. Before fipkart he handled gigs at Yahoo! and Naukri.

Comments

{{ gettext('Login to leave a comment') }}

{{ gettext('Post a comment…') }}
{{ gettext('New comment') }}
{{ formTitle }}

{{ errorMsg }}

{{ gettext('No comments posted yet') }}

Hosted by

We care about site reliability, cloud costs, security and data privacy