Fast-growing Cloud Service Providers must safeguard customer trust and project a reliable brand image. Issues impacting service reliability and service level agreements (SLAs) are a major concern to guarantee growth, and DDoS protection and DNS infrastructure availability are critical to cloud operations. The Cloud Service Provider required a superior mitigation solution, which would integrate with their own internal detection and management control centre while providing a high performance, flexible and cost-effective DDoS protection solution.
A10 worked with the Cloud Service Provider to create an innovative Non-stop DNS solution to prevent anticipated DNS meltdowns due to DDoS attacks on their DNS infrastructure. The solution, utilizing Thunder TPS, was first deployed in 2017 to provide Non-stop DNS services for the Cloud Service Provider.
At the heart of the new solution is a ground-breaking authoritative DNS cache from A10 that achieves unprecedented levels of scale and performance while protecting the backend DNS servers. This new capability complements the industry-leading DNS service protection available on the Thunder TPS Mitigator platform to further fortify DDoS defences. The overall solution provides multi-vector protection which is highly accurate, granular, and provides scalable enforcement, ultimately reducing CAPEX and OPEX.
A10 Thunder TPS Non-stop DNS enables the following key benefits:
· Highly scalable authoritative DNS cache server to eliminate the impact of DNS DDoS attacks
· 150x DNS performance vs a typical DNS server
· Up to 35M queries per second (QPS)
· Impedes attacker reconnaissance by responding in a manner that is indistinguishable from the backend authoritative DNS servers
· Absorbs massive attacks while limiting the volume of queries to the backend DNS servers
· Enhances the experience of legitimate users by reducing DNS response time especially when placed at the network edge in global service provider networks
· Ease of integration with detection and management systems via OpenAPI (aXAPI) to automate tasks
“High profile outages caused by attacks on critical infrastructure have demanded the creation of new solutions,” said Raj Jalan, CTO, A10 Networks. “The A10 Networks Non-stop DNS solution enables any service provider to avoid costly downtime by keeping DNS infrastructure operational despite the largest targeted attacks.”
When DNS servers are targeted by attackers, Thunder TPS Authoritative DNS Cache can provide Non-stop DNS service with unmatched capability and performance.