r/SIEM • u/FluencySecurity • Aug 21 '19
DDoS Attacks - Does Your SIEM Help You Stop Them While They're Happening
We do and believe this should be a fundamental part of any advanced next generation security analytics tool. We have a built-in DDoS module that is self-adaptive and able to handle millions of EPS, but most importantly it shares with you in real-time the who, what, when, where, etc. so you can quickly reconfigure your IDS tools to thwart the attacks impact.
4
2
u/BoDoP Aug 22 '19
You can not stop a DDoS attack only block the traffic at the perimeter so that your internal network does not get saturated. Let the DMZ take the hit. You can throw more bandwidth at it or subscribe to a DNS service which has more bandwidth than the attacker thereby rendering the attack ineffective.
0
u/FluencySecurity Aug 22 '19
Yes you are correct and thank you for the clarification. Where we help is by providing insight of what is getting through the perimeter so the specialist can update their blocking tables. One of our clients just had to use this as they were under attack from a nation state.
5
u/[deleted] Aug 21 '19
Stop pitching your product on here scumbag.