Protección Anti-DDoSAnti-DDoS Protection
Absorción y filtrado de ataques de denegación de servicio antes de que lleguen.Absorption and filtering of denial of service attacks before they land.
¿Qué es este servicio?What is this service?
Es la capacidad de absorber y filtrar tráfico de denegación de servicio antes de que alcance la infraestructura de la organización. Se implementa desviando el tráfico hacia una red de limpieza con mucha más capacidad que el enlace del cliente, donde se descarta lo malicioso y se reenvía lo legítimo. Los ataques se separan en tres familias que se mitigan de forma distinta: volumétricos, de protocolo y de capa de aplicación.
The capability to absorb and filter denial of service traffic before it reaches the infrastructure of the organisation. It works by diverting traffic into a scrubbing network with far more capacity than the client link, where the malicious portion is dropped and the legitimate portion forwarded. Attacks fall into three families that are mitigated differently: volumetric, protocol and application layer.
¿Para qué se usa?What is it used for?
Mantiene el servicio en pie cuando alguien decide tirarlo, y conviene ser honesto sobre cómo funciona de verdad: contra un ataque volumétrico grande no hay aparato en el borde del cliente que valga, porque si el volumen recibido supera lo que cabe en el enlace, el enlace ya se saturó antes de que el aparato pueda opinar. La mitigación real de ese tipo exige capacidad de red aguas arriba, la del proveedor. Los ataques de protocolo agotan tablas de estado en cortafuegos y balanceadores con relativamente poco tráfico, y los de capa de aplicación imitan usuarios reales y se detienen con lógica, no con ancho de banda.
It keeps the service standing when somebody decides to take it down, and it is worth being honest about how that actually works: against a large volumetric attack no appliance at the customer edge helps, because once the incoming volume exceeds what the link can carry, the link is already saturated before the appliance gets a say. Real mitigation of that type demands upstream network capacity, that of the provider. Protocol attacks exhaust state tables in firewalls and load balancers with relatively little traffic, and application layer attacks imitate real users and are stopped with logic, not bandwidth.
Qué beneficios traeBenefits it delivers
- Mantiene el servicio disponible durante el ataque, que en comercio electrónico o banca es directamente facturación que no se pierde.
- Protege también lo que está detrás: un ataque absorbido en el borde no consume los cortafuegos, los balanceadores ni el enlace de la organización.
- La protección siempre activa mitiga en segundos, mientras que la bajo demanda necesita que alguien detecte, decida y desvíe el tráfico.
- Elimina el uso del ataque como distracción, una táctica frecuente para ocupar al equipo de operaciones mientras ocurre otra cosa.
- It keeps the service available during the attack, which in e-commerce or banking is revenue not lost.
- It also protects what sits behind: an attack absorbed at the edge does not consume the firewalls, load balancers or link of the organisation.
- Always-on protection mitigates in seconds, whereas on-demand requires somebody to detect, decide and divert traffic.
- It removes the attack as a distraction tactic, frequently used to tie up the operations team while something else happens.
¿En qué momentos es obligatorio?When is it mandatory?
Costa RicaCosta Rica
- No existe obligación legal de contratar protección anti-DDoS en Costa Rica.
- En entidades supervisadas por SUGEF, SUGEVAL, SUPEN y SUGESE, el Acuerdo CONASSIF 5-24 gobierna la gestión de la tecnología de información y la disponibilidad de los servicios entra dentro de esa gestión de riesgo; además, el perfil tecnológico se remite cada año y ahora incluye tablas de funciones de ciberseguridad y de servicios en nube donde estas protecciones se declaran.
- Se pide con frecuencia en contratos con clientes corporativos y en licitaciones donde hay compromiso de disponibilidad.
- There is no legal obligation to contract anti-DDoS protection in Costa Rica.
- For entities supervised by SUGEF, SUGEVAL, SUPEN and SUGESE, CONASSIF Agreement 5-24 governs information technology management and service availability falls within that risk management; the technology profile is also filed annually and now includes cybersecurity function and cloud service tables where these protections are disclosed.
- It is frequently required in corporate client contracts and in tenders carrying availability commitments.
InternacionalInternational
- Ningún marco obliga a contratar un servicio anti-DDoS concreto.
- ISO 27001 trata la disponibilidad como una de las tres propiedades a proteger y exige preparar la continuidad de la seguridad ante interrupciones.
- NIS2 y DORA empujan hacia la resiliencia operativa de los servicios esenciales, y un servicio que se cae ante una saturación de tráfico no es resiliente por mucha política escrita que haya.
- No framework mandates a specific anti-DDoS service.
- ISO 27001 treats availability as one of the three properties to protect and requires preparing continuity of security through disruption.
- NIS2 and DORA push towards operational resilience of essential services, and a service that falls over under a traffic flood is not resilient however much written policy exists.
Requisitos mínimosMinimum requirements
- Control sobre el DNS o sobre el anuncio BGP de los rangos propios, según se proteja una aplicación concreta o una red completa.
- Un perfil de tráfico normal medido antes del ataque. Sin línea base, el filtrado no distingue una campaña de marketing exitosa de una inundación.
- Contrato con tiempo de mitigación comprometido y modalidad explícita: siempre activa o bajo demanda. Es la diferencia comercial que de verdad importa.
- Que la IP de origen no siga siendo alcanzable de forma directa, porque si lo es el atacante ignora toda la protección y va al servidor.
- Control over DNS or over the BGP announcement of the ranges, depending on whether a single application or a whole network is protected.
- A normal traffic profile measured before the attack. Without a baseline, filtering cannot tell a successful marketing campaign from a flood.
- A contract with a committed mitigation time and an explicit mode: always-on or on-demand. That is the commercial difference that genuinely matters.
- That the origin IP is no longer directly reachable, because if it is the attacker bypasses the entire protection and goes straight to the server.
Plazo típico de entregaTypical delivery time
La activación va de una a cuatro semanas. Una semana basta para proteger una aplicación web cambiando registros DNS hacia el proveedor. Se estira a cuatro cuando hay que proteger rangos completos con desvío BGP, coordinar con el operador de telecomunicaciones y ejecutar pruebas de conmutación fuera de horario. Una vez arriba es un servicio continuo, y conviene ensayar la mitigación al menos una vez al año en lugar de descubrir cómo funciona el día del ataque.
Activation runs from one to four weeks. A week is enough to protect a web application by pointing DNS records at the provider. It stretches to four when whole ranges need BGP diversion, coordination with the telecoms carrier and out-of-hours failover testing. Once live it is a continuous service, and it pays to rehearse mitigation at least annually rather than learning how it works on the day of the attack.
NomenclaturaTerminology
Las siglas y estándares que aparecen en esta ficha, explicados. The acronyms and standards used on this page, explained.