《阿里云安全产品重磅发布&演讲(23页).pdf》由会员分享,可在线阅读,更多相关《阿里云安全产品重磅发布&演讲(23页).pdf(23页珍藏版)》请在三个皮匠报告上搜索。
1、Grand Launch of Cloud Security ProductsHanqing WuChief Security Researcher of Alibaba CloudPart 1Cyber Security Analysis of Todays Alibaba CloudCurrent Situation of Alibaba Cloud SecurityProtect over 35%of Chinas WebsitesBlock 200 Million Brute ForceAttacks Every DayBlock 20 Million Web ApplicationA
2、ttacks Every dayMitigate Over 2,000 Times of DDoS Attack35%200Million20Million2,000Cloud computing aggregates data.Latest threat intelligence is acquired by analyzing and computing PB-level data every day,which builds the core competitiveness of Alibaba Cloud Security.Security big data covering all
3、IT LayersSecurity big data covering all IT LayersContentApplicationHostSystemNetworkContinuous monitor and analyzeReal threat intelligence is generated by integrating values of different data types.Big Data and Threat Intelligence Ability of Entire NetworkGlobal botnet C&C servers info,80%of whichar
4、e effectively monitoredMonitor over 2.5 million active malicious IPs globallyOver 10 million samplesof backdoor files recorded,as well as their usages 1000+2.5 Million10 MillionGlobal Defense AbilityIn November of 2015,Alibaba Cloud Security successfully mitigated the worlds largest HTTPS(SSL)flood
5、attack ever in history,with 950,000 QPS as maximum concurrent requests.Over 140 self-developed patches,helped our users fix more than 1 million vulnerabilities this year.Alibaba Cloud WAF helps customers block nearly 10 million web application attacks every day,most of which are SQL injections and a
6、utomatic scans.Among those launched by humans,over 30%hackers performed continuous attacks.Over 50,000 backdoor files are detected and eliminated every day,the self-developed next generation backdoor detection engine is able to identify backdoor mutations.Traceback AbilityAmong cyber attacks such as
7、 database compromises,DDoS attacks,brute force attacks,over 95%of them can be traced to identify a hacker.Customers under these attacks are most distributed in gaming,e-commerce and finance industries.Security Ecology and White HatsMore than 200 ecologicalproducts and servicesOver 1,500 white hats j
8、oined Crowdsourced Security TestingOver 100 security vendors in China2001500100Part 2What Makes Alibaba Cloud Different?Products of Alibaba Cloud SecurityCloud Security Shared Responsibility MatrixCustomerResponsibleData SecurityAccount Authentication and Authorization SystemSecurity EcologyAuthenti
9、catedAccountAuthorizationApplication SecurityHost Security(Virtual Security)Network Security(Virtual Network)Resource Abstraction and ControlRDSECSOSSMaxComputerPhysical DeviceComputeNetworkStorageInfrastructureRegionsZonesBackbone NetworkAlibaba CloudResponsibleWhat makes Alibaba Cloud different fr
10、om AWS/Azure is Alibaba Cloud Security.Build A“Red N Blue Army Competition”Security SystemNetwork:Layer 4&7 DDoS Mitigation Application:Web Intrusion Protection Business:Scraper/Bots/DB Brute-forcePenetration Test System&Crowdsourced Security TestingSecurity Big Data Analyze Situation AwarenessPenet
11、rationAwarenessDefenseSecurityManagementBusiness SecurityDataSecurityCA CertificateHSMKMSAnti-DDoSExpress ConnectServer GuardApplication SecuritySystemNetwork SecuritySituation AwarenessAccess ControlOperation AuditContent Security(Porn Detection)Antifraud ServiceWAFCrowdsourced Security TestingMobi
12、le SecurityData EncryptionSecurity Products FamilySecurity Products FamilySecurityManagementDataSecurityCA CertificateOversea ETA Dec.HSMOversea ETA Mar.KMSAvailable overseasAnti-DDoSAvailable overseasExpress ConnectServer GuardOversea ETA Dec.Application SecuritySystemNetwork SecuritySituation Awar
13、enessOversea ETA Dec.Access ControlAvailable overseasOperation AuditAvailable overseasWAFOversea ETA Nov.Crowdsourced Security TestingMobile SecurityAvailable overseasPart 3Alibaba Cloud Security Products Grandly Launched OverseaAnti-DDoS Pro now available in HKComing soon in USHKU.S.AMore than just
14、 high-volume DDoS attack mitigationHigh PerformancePrecise DetectionFast ResponseFalse PositivesGaming Empty ConnectionsHTTP(S)FloodBotnet ProtectionIntegrated WAFMore than just high-volume DDoS attackmitigationFull CoverageTCP/UDP/HTTP/HTTPS/DNS protection supported,one IP covers 20 origins.Great E
15、xperienceLatency less than 30ms in Southeast Asia,meeting requirements of sensitive business like gaming.Complex ScenariosCombination with CDN/WAF.Support Chinese business outside China or global business inside China.Largest Scrubbing Center in Eastern HemisphereLarge ProtectionBandwidthMobile Secu
16、rity Products Officially Launched OverseaCovering 0.8 billion mobile devices,with vulnerability scanner covering Over 95%known vulnerabilities.Web Application Firewall coming soon in Southeast Asia.Fast and stable:withstood the extremely massive requests during the“11.11”shopping festival.Integrated
17、 with the latest threat Intelligence from Alibaba Cloud Security.Situation Awareness coming soon in Singapore.The ONLY security product able to trace the hackers identity.The ONLY security product able to automatically analyze the paths of intrusions.The ONLY security product able to automatically analyze behaviors following intrusions.