Imperva: Protecting the Data that Drives Business Blog|Login|Chinese German Japanese|Follow @imperva
Cloud DDoS Protection

Stop DDoS Attacks

Distributed Denial of Service (DDoS) attacks are a critical threat for any organization that conducts business online. Hackers, criminals, and political “Hacktivists” increasingly rely on DDoS attacks because they are inexpensive to execute and difficult to stop. Underground chat rooms advertise DDoS attack services starting from as low as $50, making it easy for malevolent users to disrupt and even disable a victim’s Website. Current DDoS attacks have become more sophisticated than ever—advanced attacks can evade firewall detection by exploiting application vulnerabilities.

To protect against DDoS attacks, organizations need a solution that protects against all types of DDoS attacks and scales to manage massive bursts of traffic. Imperva Cloud DDoS Protection is a simple, secure cloud-based service that safeguards businesses from the most debilitating and protracted DDoS attacks. As a service, Cloud DDoS Protection can be deployed quickly and can scale on demand to mitigate malicious traffic. Imperva’s experienced security professionals provide on-call, expert assistance and policy tuning in the event of a DDoS attack, providing businesses assurance that their applications will always be available.


Key Capabilities
Stops application and network DDoS attacks
Avoids application outages and brand damage
Protects in minutes with effortless deployment
Scales to absorb DDoS attacks that exceed Internet bandwidth limits
Leverages real-time assistance from Imperva’s DDoS experts
Lowers costs by eliminating need to over-provision bandwidth


Imperva Cloud DDoS Protection Plans

Imperva offers flexible 1, 2 and 3-year standby and automatic service plans to meet specific business needs. The standby plan can be enabled when under attack. The automatic plan is a continuous service that can be purchased in conjunction with the Imperva Cloud WAF service.

 Standby Plan
1 Gbps
Standby Plan
2 Gbps
Automatic Plan
1 Gbps
Automatic Plan
2 Gbps
Bandwidth: 1 Gbps 2 Gbps 1 Gbps 2 Gbps
Burstable Bandwidth Limit: 2 Gbps 4 Gbps 2 Gbps 4 Gbps
Managed DDoS Service: Included Included Included Included
Additional 100 Mbps
Bandwidth, per Month:
Optional Optional Optional Optional
Websites Included
with Service:
1 1 All All
Additional Websites: Optional Optional Included Included


To learn more, click on the Capabilities tab.

Fast, Accurate DDoS Security from Imperva

The Imperva Cloud DDoS Protection Service offers a complete defense against all types of DDoS threats, including network-based attacks, like SYN or UDP floods, and application attacks that attempt to overwhelm server resources. The service also blocks advanced attacks that exploit application and Web server vulnerabilities, like Slowloris, and it caches Web content to ensure optimum performance, even when under attack. Unique bot-detection technology differentiates real users from automated clients to stop attack sources.

Cloud DDoS Protection scales on demand to stop multi-gigabit denial of service attacks. With Imperva’s powerful defense against DDoS attacks, customers can be assured that their applications are always accessible.

Fast, Easy Deployment

Cloud DDoS Protection can be rolled out without any hardware, software or Web application code changes. Customers can provision this service simply by changing their Website’s DNS setting. This effortless deployment allows customers to be protected in a matter of minutes while maintaining their existing hosting provider and application infrastructure.

Centralized Attack Analysis

The Imperva Security Operations Center (SOC) protects Web applications using collective knowledge about DDoS threats, including new and emerging attack methods. The Imperva SOC aggregates information across the entire service network to identify new attacks as they happen and to detect known malicious users. Based on this aggregated information, mitigation rules can be applied in real-time across all protected Websites.

Affordable DDoS Protection

While every organization wants to ensure maximum application uptime, remediating DDoS risks on-premise—by over-provisioning bandwidth and deploying additional servers and load balancers—can be cost-prohibitive for many. Cloud DDoS Protection offers an economical insurance plan against DDoS attacks. As a managed service, it avoids expensive hardware and overhead costs. Businesses can avoid purchasing multi-gigabit Internet connections and eliminate additional capital and operational costs. Cloud DDoS Protection is the smart choice to avoid the disruptive downtime, lost revenue, and brand damage associated with DDoS attacks.

World-class DDoS and Security Expertise

The Imperva Cloud DDoS Protection Service provides organizations with continuous monitoring by knowledgeable and adept Security Operations Center (SOC) engineers. By subscribing to this service, organizations can leverage a dedicated team of DDoS security experts. Cloud DDoS Protection provides the following services when a DDoS attack occurs:

  • Proactive security event management and response
  • Continuous, real-time monitoring
  • Adept policy tuning
  • Summary attack reports
  • Around-the-clock support

Extending Imperva SecureSphere and Imperva Cloud WAF

The Imperva Cloud DDoS Protection Service complements the capabilities of the market-leading SecureSphere Web Application Firewall. While SecureSphere prevents application DDoS attacks, attacks designed to overwhelm an organization’s Internet connection are best dealt with before they reach the organization’s network. Cloud DDoS Protection, as a cloud-based service, can scale on demand to filter up to 4 Gbps of DDoS traffic—much greater than most enterprises’ network connections. This service also includes real-time, hands-on management and monitoring from the Imperva SOC.

For Imperva Cloud WAF customers, Cloud DDoS Protection includes specific policies designed to stop DDoS attacks. Because DDoS attacks can consume inordinate amounts of traffic, this service also provides a cost-effective way to secure critical Web applications without incurring Cloud WAF overage charges—DDoS traffic will be excluded from Cloud WAF bandwidth calculations.

Imperva Cloud DDoS Protection Specifications


Specification Description
Security
  • Network and application DDoS attack protection
  • Bad bot blocking
  • Access control by country
  • Access control by visitor type
  • Advanced security actions
  • Security rule fine tuning
  • Support for HTTPS Sites
  • Threat Control dashboard
Performance
  • Globally distributed network
  • Static and dynamic content caching
  • Connection optimization
  • Dynamic content compression
  • Content minification1
Managed Security Service
  • Around-the-clock health monitoring
  • Threat alert email notifications
  • Performance notifications
  • Server outage notifications
  • Application response time analysis
  • Proactive security event management and response
  • Proactive policy tuning
  • Weekly reporting
  • Around-the-clock support
DDoS Attack Protection2
  • TCP SYN+ACK
  • TCP FIN
  • TCP RESET
  • TCP ACK
  • TCP ACK+PSH
  • TCP Fragment
  • UDP
  • ICMP
  • IGMP
  • HTTP Flood
  • Brute Force
  • Connection Flood
  • Slowloris
  • Spoofing
  • DNS flood
  • Mixed SYN+UDP or ICMP+UDP flood
  • Ping of Death
  • Smurf
  • Reflected ICMP and UDP
  • Teardrop
  • Zero-day DDoS attacks
  • DDoS attacks targeting Apache, Windows or OpenBSD vulnerabilities
  • As well as other attacks...

1 Eliminating unnecessary application code such as white spaces and comments.

2 The Imperva Cloud DDoS Protection Service can detect and block the following DDoS threats. Note that Cloud DDoS Protection proxies Web requests, so any network layer DDoS attacks would target the cloud infrastructure and would never be relayed to the client network. Therefore, Cloud DDoS Protection will prevent all network DDoS attacks.