ANT1003

Anti-DDoS Scrubbing Center

Duration of training: 3 days

sign up for a course

description
course

This course provides participants with an understanding of the architectures, technologies, and mechanisms used to design and build a Scrubbing Center for protection against DDoS attacks.

course audience

Engineers responsible for cybersecurity of corporate network infrastructure and enterprise application infrastructure, as well as corporate cybersecurity architects.

prerequisites

Participants should have knowledge of TCP/IP network operations at the level of the ANT-N101 course, general cybersecurity fundamentals at the level of the ANT0000 course, and an understanding of DoS and DDoS attack protection concepts at the level of the ANT0013 course.

how it works
education

online course

The online course involves group classes with an instructor via video conferencing, in addition, homework and an exam.

for corporate clients

training for corporate clients includes online and self-study courses, as well as additional services required by corporate clients: organizing training plans for client departments, assessing the effectiveness of training, etc.

program
course

• DoS and DDoS attacks within the threat model.
• Classification of DoS attacks.
• Classification DDoS attacks.
• Modeling of DoS and DDoS attacks.
• Prevention of DoS and DDoS attacks.
• What is a Scrubbing Center.
• The role of a Scrubbing Center in an enterprise infrastructure.
• Scrubbing Center components.
• Single-site и geo-distributed scrubbing.
• Inline and redirect traffic cleaning scenarios.
• Out-of-path scrubbing and GRE/IPIP tunneling.
• High availability and fault tolerance.
• Bandwidth, oversubscription, and link redundancy.
• Scrubbing Center capacity planning and calculation.
• Capacity planning: bandwidth, packets per second, session tables.
• BGP for scrubbing scenarios.
• Prefix advertisement and more specific routes.
• RTBH as part of the incident response strategy.
• FlowSpec as a targeted traffic filtering mechanism.
• Anycast as a load distribution method.
• Route leak and asymmetric routing issues.
• Telemetry sources: NetFlow, sFlow, IPFIX, SNMP.
• Baseline and anomaly detection methods.
• Traffic behavior analysis.
• Signature-based and heuristic approaches.
• Detection of L3/L4 and L7 attacks.
• Building detection thresholds and service profiles.
• Telemetry sources: NetFlow, sFlow, IPFIX, SNMP.
• ACL-based and stateless filtering.
• Stateful protection and connection tracking.
• SYN proxy, rate limiting, and challenge mechanisms.
• Spoofed traffic filtering.
• Blocking amplification attack vectors.
• HTTP/HTTPS attack mitigation using reverse proxy / WAF technologies.
• TLS termination in protected service scenarios.
• Integration with upstream providers.
• Integration into data center infrastructure.
• Integration with SOC components.
• Incident response automation.
• SLA and SLO requirements for protected services.
• Customer connectivity models.
• Service models: always-on, on-demand, and hybrid.
• DDoS incident response playbooks.
• Scrubbing Center metrics: TTD, TTM, accuracy, false positive rate.
• Operational management of traffic scrubbing policies.

Сourse purchase
options

individual

Cost — $1,549.15

Group online classes

Unlimited access to all the materials

Live webinars with teachers

Homework

Exam with certificate

To confirm course dates fill out the form.

SUBMIT YOUR APPLICATION

* By clicking “send”, you agree to the Terms of Service And Privacy Policy

corporate

Cost from $1,549.15

To obtain information about the final cost and clarify the date of the course, please fill out the form.

SUBMIT YOUR APPLICATION

* By clicking “send”, you agree to the Terms of Service And Privacy Policy