Glossary
| Element | Description |
|---|---|
| Scrubbing | Scrubbing refers to the process of filtering Internet traffic, particularly at OSI layers ¾, in such a way that valid clean traffic is distinguished from harmful attack traffic. |
| Scrubbing Center | A scrubbing center is a high-performance Internet node (point of presence/PoP) consisting of hardware, software, and broadband connectivity that is capable of performing scrubbing efficiently using Myra technology. |
| Myra Partner | An ISP is a Myra customer that uses the Myra product Network DDoS Protection (on-prem) and has implemented it within its own network. |
| End customer | An end customer is the customer of a Myra partner that uses the volumetric DDoS protection service for OSI layers ¾ powered by Myra. |
| Network DDoS Protection (cloud) | Cloud scrubbing is a service provided by Myra in the form of Security-as-a-Service (SaaS) that protects the network of the Myra partner from volumetric DDoS attacks on OSI layers ¾. Functionality: As soon as parameters defined in advance are exceeded, the (attack) traffic is briefly rerouted into a cloud scrubbing center by means of Border Gateway Protocol (BGP) rerouting and washed clean of unwanted traffic there, so that only clean traffic is forwarded to the recipient over a secured connection. Advantages: Network DDoS Protection (cloud) can reliably defend against DDoS attacks with a bandwidth of several Tbit/s. This defence bandwidth is always available to the Myra partner, even if it exceeds the total line capacity (bandwidth) of the Myra partner's own physical connection. It is irrelevant whether the entire line capacity of the Myra partner is physically implemented by one line provider or by several (multi-vendor strategy). This DDoS protection is also retained if the Myra partner changes line provider in the future or adds further ones. Restriction: For technical reasons, protection through Network DDoS Protection (cloud) is only possible for individual /24 prefixes with IPv4 and /48 prefixes with IPv6. Because of the restriction to exactly these sizes that generally applies on the public internet, networks smaller than /24 or /48 cannot be protected through cloud scrubbing. |
| Network DDoS Protection (on-premises) | Myra provides its partner with one or more physical scrubbing centers, which are integrated into the network infrastructure of the Myra partner. This ensures that all routers involved in routing relevant to scrubbing are controlled by Myra or the Myra partner. This also makes it possible to define valid routes for smaller prefixes (that is, networks smaller than /24 or /48) without causing problems for public routing. |
| Network DDoS Protection (hybrid) | Network DDoS Protection (hybrid) is a combination of the OnPrem and Cloud network DDoS protection solutions. If the bandwidth of a DDoS attack exceeds the line capacity (of one or of several physical connections) of the Myra partner, the resources of Myra can be used as a second line of defence and a switch can be made from Network DDoS Protection (on-prem) to Network DDoS Protection (cloud), in order to reliably defend against volumetric DDoS attacks on OSI layers ¾ with bandwidths of several Tbit/s as well. This enables Myra partners to ensure that their own servers and networks, as well as those of their end customers, remain accessible even during DDoS attacks with extremely high bandwidths. |
| Myra Flow-Application | The Myra Flow Application is an application that detects DDoS attacks on the basis of the data supplied by the edge routers of the Myra partner and thresholds defined beforehand. The Flow-Monitoring reports detected attacks to downstream instances to automatically initiate countermeasures. The application is operated in the network infrastructure of the Myra partner, usually on a virtual machine. |
| Uplink | An uplink is a dedicated channel for returning the cleaned traffic to the Myra partner after scrubbing has been completed. This channel is necessary to avoid a routing loop. Uplinks can be set up redundantly as direct connect (physical) or as VLAN, IPsec, GRE (virtual). |
| On Demand | On demand means that traffic filtering is only activated once an attack exceeds the specified thresholds. Normally, traffic does not flow through the scrubbing center. With automatic attack detection, routing is changed and data traffic is processed there. After 24 hours, regular routing is restored – a period recommended by Myra to prevent unnecessary route flapping. |
| Route flapping | Route flapping refers to the state of different announced routes on the internet at the same time. This is dangerous and has far-reaching negative consequences for routing on the public Internet. |
| Myra App | The Myra App is a web-based user interface for controlling and configuring the protection systems. |
| Myra DataHub | The Myra DataHub is a web-based user interface (WebGUI) for Myra partners to view an overview of end customers. This shows the end customers with the connected networks and their created accounts. Within this WebGUI, end customers have an overview of traffic history, the networks that have been activated, and the mitigation reports that have been collected. Within the traffic history view, it is possible to filter between bandwidth and packet rate, sorted by destination IP, overview of source countries, ASN, and packet rates by port. In addition, various viewing periods of up to 24 hours can be defined. The set thresholds can also be viewed via the WebGUI. In addition, the functionality of the Myra DataHub includes the option of initiating manual mitigation and configuring the defined companies, networks, and users by the Myra partner. |