Free Newsletter
Register for our Free Newsletters
Newsletter
Zones
Access Control
LeftNav
Alarms
LeftNav
Biometrics
LeftNav
Detection
LeftNav
Deutsche Zone (German Zone)
LeftNav
Education, Training and Professional Services
LeftNav
Government Programmes
LeftNav
Guarding, Equipment and Enforcement
LeftNav
Industrial Computing Security
LeftNav
IT Security
LeftNav
Physical Security
LeftNav
Surveillance
LeftNav
View All
Other Carouselweb publications
Carousel Web
Defense File
New Materials
Pro Health Zone
Pro Manufacturing Zone
Pro Security Zone
Web Lec
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
ProSecurityZone Sponsor
 
 
News

DDoS Attack on Virtual Payment Card Provider Mitigated

Prolexic Technologies : 13 September, 2012  (Application Story)
Virtual payment card service provider EntroPay is breathing a sigh of relief after a high volume DDoS attack on its site was mitigated by Prolexic without loss of data
DDoS Attack on Virtual Payment Card Provider Mitigated

Prolexic has recently mitigated a high volume Layer 4 DDoS attack on EntroPay, a virtual credit card web site owned and operated by Ixaris Systems.

At Entropay, anyone can open and fund an account to obtain a virtual prepaid Visa card that is accepted by millions of merchants worldwide. As the first and now most successful virtual prepaid card introduced in Europe, EntroPay provides consumers with a safe, flexible and instantaneous way of making and receiving online payments.

As awareness and popularity of the web site increased, it became a target for DDoS denial of service attacks. Although no user data was ever compromised, the DDoS attacks brought down the EntroPay site, sometimes for a considerable length of time.  In response, the company increased network protection with a hardware mitigation appliance from its Internet Service Provider. However, this solution failed when EntroPay was hit with an attack that had traffic volume exceeding the appliance’s limit of 100Mbps.

EntroPay then decided to engage Prolexic for DDoS detection and DDoS protection. Ixaris now uses Prolexic’s PLXrouted service to provide DDoS protection for the EntroPay wen site. With this service, DDoS attacks are detected by monitoring on-premise equipment. In the event of an attack, the traffic-routing service is activated using Border Gateway Protocol (BGP) to on-ramp network traffic to Prolexic's 500 Gbps cloud-based denial of service DDoS mitigation infrastructure.

Recently, the EntroPay web site has been hit by a wide range of attack types – SYN Flood, ICMP Flood, UDP Flood – in various durations including a Layer 4 DDoS attack peaking at 700 Mbps.  EntroPay has also experienced attacks characterized by high CPU usage on its routers and several UDP drops on the router’s Access Control Lists (ACLs). In each case, Prolexic technicians were able to defeat the attacks in minutes.  With the assistance of PLXsert (Prolexic’s Security Engineering and Response Team), post-attack forensic information helped Ixaris identify where the attacks originated.

“The first half of 2012 has seen an increase in the number and size of DDoS attacks on financial industry web sites,” said Stuart Scholly, president of Prolexic. "The recent attacks against EntroPay.com is no surprise in light of the escalating activity against the financial industry.”

“As a Level 1 PCI compliant financial services provider, the security of our service is of the utmost importance so any attack is something we take very seriously,” said Tim Murfet, chief information officer at Ixaris Systems. “Once our traffic is routed through Prolexic’s network, we’re immediately back in business.”

With DDoS attacks against financial web sites on the rise, Murfet recommends that DDoS protection be treated like a disaster recovery plan that should be regularly tested to ensure that everyone in IT knows how to respond during an attack.

“It’s important to have good communication with your DDoS mitigation provider even in non-attack situations and to test the service regularly so you’ll know it will work when you need it,” Murfet advised. “For a financial services company like ours that requires 100 percent uptime, we need the peace of mind that Prolexic mitigation services provide.”

Bookmark and Share
 
Home I Editor's Blog I News by Zone I News by Date I News by Category I Special Reports I Directory I Events I Advertise I Submit Your News I About Us I Guides
 
   © 2012 ProSecurityZone.com
Netgains Logo