Team Cymru Community Services,Overview of all public services

bdnog 71 views 18 slides Jul 15, 2024
Slide 1
Slide 1 of 18
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18

About This Presentation

Team Cymru Community Services


Slide Content

1 Free Community Services Overview of all public services Tarek Sendi – Security Evangelist https://team- cymru.com /community-services/

2 2 Team Cymru’s Other Free Service Solutions Nimbus Threat Monitor BOGON Reference Unwanted Traffic Removal Service (UTRS) Free Community Services for ASN Owners

3 Nimbus-TM https://team- cymru.com /community-services/

4 What is NimbusTM ? A cloud based netflow aggregation collector that provides enhanced visibility into your own flow data while also enriching your flow traffic by creating specific Alarms based off our Threat Intelligence Feed. Based on Elastic / Kibana. https://team- cymru.com /community-services/nimbus-threat-monitor/

5 Netflow ? Flow Record Defines the criteria for what is collected from a tcp / udp conversation traversing that router/switch Flow Exporter Specifies where and how the flow record will be sent to the FlowCollector or aggregator Monitor Combines the Flow Record and Exporter to associate to the interface or vlan you want to monitor or generate netflow from. https://team- cymru.com /community-services/

6 What does NimbusTM give you Ability to manipulate traffic data by either ASN or Proto Ability to track traffic anomaly related events visually, outages, total throughput, etc Ability to take our Threat Intelligence data association and see what hosts communicating with your network are: victims, targets, or the source of malicious behavior https://team- cymru.com /community-services/nimbus-threat-monitor/

7 7

8 8

9 BOGON Reference https://team- cymru.com /community-services/

10 What are Bogons? Bogons are defined as Martians (private and reserved addresses defined by RFC 1918, RFC 5735, and RFC 6598) and netblocks that have not been allocated to a regional internet registry (RIR) by the Internet Assigned Numbers Authority. https://team- cymru.com /community-services/ https://team- cymru.com /community-services/bogon-reference/

11 How are the lists managed? We try to break up the lists into more specific types to allow for more flexibility based on your use case needs. Bogons Full Bogons IPv4 IPv6 https://team- cymru.com /community-services/

12 How can I access the Bogon list? Supported list of formats and methods by which you can receive these updates: HTTP BGP Peering (Bogon Route Service Project) Routing Registries ( RADb and RIPE NCC Partnerships) DNS All formats are updated at the same intervals Our data is based on relevant RFCs, IANA IPV4 allocation list (IPv4 summary page) and RIR data We constantly monitor for changes and update quickly when changes occur https://team- cymru.com /community-services/

13 UTRS 2.0 https://team- cymru.com /community-services/

14 What is DDOS? DDOS = Distributed Denial of Service. It is an attack against one or more network resources designed to deny that resource from providing normal services. DDOS can be via an amplification attack. Malicious actor sends a small flow of special packets towards a service that has a large response. Examples: Recursive DNS servers, NTP, CHARGEN and others. https://team- cymru.com /community-services/

15 History of UTRS The need for a coordinated, automated, rapid community response exists. In 2014, Team Cymru launched UTRS 1.0 In 2022 we currently have 1,600+ peering sessions currently configured with our Partners. https://team- cymru.com /community-services/

16 What is UTRS 2.0 (Unwanted Traffic Removal Service)? A FREE Community Driven Free DDOS mitigation service Similar to Remote Trigger Black Hole (RTBH) except: Upstream and Global Team Cymru validates the request then forwards out to the 1600+ participating networks Thanks to our participating partner networks, we effectively reduce the impact of threat actors A single BGP announcement to rule them all https://team- cymru.com /community-services/

17 Questions? https://team- cymru.com /community-services/

18