Solution Brief | Protector Cyber Controller for Service Providers
This solution brief highlights the Protector Cyber Controller, an advanced security management and automation solution designed for service providers. It enhances distributed infrastructure protection by offering flexible deployment options, automated attack detection and mitigation, and comprehensive analytics to improve operational efficiency and reduce overhead.

©2023 Check Point Software Technologies Ltd. All rights reserved. | April 2023 | Page 1
©2023 Check Point Software Technologies Ltd. All rights reserved. | April 2023 | Page 2
To provide best-in-class cyber security protection to multiple tenants with multiple services and networks while still maintaining a reasonable cost structure, an operator requires tools that will provide advanced attack detection, comprehensive visibility combined with robust automation and orchestration for provisioning new services, applying mitigation activations, orchestrating traffic diversions, and providing reports and forensics to be used for in-depth investigations.
QUANTUM PROTECTOR CYBER CONTROLLER Protector Cyber Controller provides service providers with a security management, orchestration, and automation solution. The solution offers the flexibility of deployment (inline, out-of-path (OOP), 1-tier and 2- tier mitigation) with a great degree of automation, orchestration, and visibility to accommodate for each service provider's specific needs and constraints, while considerably reducing operational overhead and overall costs. Protector Cyber Controller is a central component in Check Point's DDoS infrastructure protection solution and enables a holistic solution for distributed infrastructure protection. INFRASTRUCTURE PROTECTION FOR DISTRIBUTED NETWORKS Check Point’s approach to addressing the challenges facing service providers involves three main components: Distributed Detection is the ability to detect a single threat across the entire network by utilizing dedicated security and network elements placed strategically across the network. The detection component can detect both infrastructure and application DDoS threats by utilizing the Layer 4–7 in-line/Smart Tap solution. Distributed Mitigation is the ability to mitigate attacks by utilizing several mitigation components, one after the other, typically located the furthest away from the protected infrastructure with the least disruption of traffic flow and effect on user experience. Mitigation components include usage of the network as the mitigation tier followed by Cloud as a second tier. Mitigation using the network tier is done by the enforcement of black hole policies by border gateway protocol (BGP) flow specification (flowspec). Centralized Control is the overarching facilitator of the distributed network. It collects input from distributed detection elements and then aggregates, correlates, and analyzes those inputs in the context of the protected
Organizations are increasingly relying on service providers to provide the infrastructure for their mission-critical applications. For the provider, this business model requires an infrastructure that is shared between different locations and across multiple tenants, thereby increasing its complexity to meet the needs of the customer. This architecture also leads to increased network security threats — threats that have evolved in volume, complexity, and duration, and that now present challenges to organizations trying to protect their infrastructure and customers.
©2023 Check Point Software Technologies Ltd. All rights reserved. | April 2023 | Page 3
service. It also implements security, availability and scale logic and applies the optimal mitigation action based on the available distributed mitigation components. ENSURING HIGH AVAILABILITY Protector Cyber Controller can be deployed in high availability. This ensures service and business continuity. Cyber Controller’s high-availability architecture comprises two identical Cyber Controller nodes: active and standby. Both nodes communicate with each other and maintain full synchronization for both component state and configuration. Cyber Controller creates a peer from each active/standby node to each router, resulting in two peer connections for each network element. If one node fails, the other node keeps the peer connections and the related announcements active.
When the primary Cyber Controller node fails, the secondary node continues to communicate with all registered routers and third-party detectors with zero downtime. SECURITY OPERATIONS (SECOPS) DASHBOARD - HEART OF CYBER CONTROLLER At the heart of Protector Cyber Controller is SecOps – a comprehensive security and operations dashboard that provides a single pane of glass with top notch visibility and analytics that includes details of all the incoming attacks and ongoing active protections, and a complete history of all the attacks and protections handled by the system. It enables the user to take swift and immediate actions, at the click of a button, such as the ability to manually activate/deactivate single or multiple protections, or to manually add/remove networks/classless interdomain routing from an ongoing protection.
©2023 Check Point Software Technologies Ltd. All rights reserved. | April 2023 | Page 4
NETWORK TRAFFIC ANALYTICS Protector Cyber Controller introduces additional levels of analytics, comprising of both attack-time detailed analytics and peacetime traffic analytics. Both peacetime and attack-time analytics offer Top-N parameters such as top source and destination IPs, top applications being accessed, top protocols being used and top ASNs (locations) from where services are being accessed. Attack-time data also includes top source and destination ports, TCP flags, packet size distribution and more. In addition, weekly traffic trends and traffic anomaly analysis are also available. These new network visibility capabilities greatly contribute to an administrator's abilities to characterize and understand the traffic flows in the network, identify anomalies as they occur and tie those into an ongoing attack. Network traffic analysis directly enhances the administrator's abilities to refine detection thresholds to perfection and set the proper actions and mitigations to block
attacks.
Cyber Controller SecOps Dashboard
Peacetime traffic analytics Attack-time traffic analytics
©2023 Check Point Software Technologies Ltd. All rights reserved. | April 2023 | Page 5
CUSTOM THRESHOLDS SETTING Custom threshold settings allow administrators to create detection thresholds for virtually any application or service they deploy, even if it is proprietary. This is done by setting the protocols and ports used for these services and setting the proper threshold values. Custom threshold setting provides great flexibility for Cyber Controller users to protect any and every service and application that they wish to deploy. In addition to the above, Protector Cyber Controller adds a "weekly top talkers" trend table which allows administrators to set any threshold (standard or custom) in accordance with the actual traffic trends which their network experiences. This enhances greatly the administrators' ability to set detection thresholds to perfection.
FLEXIBILITY WITH CUSTOMIZED OPERATIONS Protector Cyber Controller is able to activate and deactivate various types of predefined operations after a workflow rule entry and exit criteria are matched. As part of the predefined operations, Cyber Controller can divert, and block traffic based on a BGP or a flow Spec rule. Cyber Controller can also deploy different types of policies and profiles on a single or a group of mitigation devices. Cyber Controller also enables the customer to define and program its own customized operations to match the unique needs of its network. Further on, Cyber Controller ensures that the new customized operations are activated whenever protection is required in accordance to a rule criteria match within its workflow engine.
Set thresholds based on real traffic trends
©2023 Check Point Software Technologies Ltd. All rights reserved. | April 2023 | Page 6
PROTECTOR CYBER CONTROLLER USE CASES Cyber Controller supports four main deployment use cases: Use Case 1: Out-of-path detection using Cyber Controller and Flow Detector. Mitigation is accomplished using Check Point DDoS Protector installed in a local scrubbing center. In use case 1, flow-based telemetry is used to detect network-layer attacks from peering edges while a high- capacity mitigation center, utilizing DDoS Protector device(s) is used to protect the infrastructure. In this use case, the attack detection is done by Flow Detector for centralized management, control and support.
Use Case 2: Cyber Controller and third-party flow telemetry detector This use case is essentially the same as use-case 1. The difference is that in this use-case, detection is done using a third-party flow telemetry device (such as Nokia, Arbor and Genie).
Cyber Controller and Flow Detector
Cyber Controller and third-party flow telemetry detector
©2023 Check Point Software Technologies Ltd. All rights reserved. | April 2023 | Page 7
Use Case 3: Out-of-path detection via Flow Detector and mitigation by Cyber Controller on the peering edge router. In use case 3, flow-based telemetry is used to detect network-layer attacks from peering edges and upon detection, Cyber Controller triggers mitigation on the peering edges using BGP Flow Spec/Blackhole. Cyber Controller characterizes the anomaly to create the most accurate Flow Spec as possible and block it in the router. In this use case, the attack detection is done by Flow Detector for centralized management, control, and support.
Use Case 4: Two-tier detection and mitigation. This use case demonstrates detection and mitigation using a multi-tier solution. It is tailored to defend against sophisticated application-level (L7 / TLS) attacks, where the applications are protected by a DDoS Protector in- line/SmartTap mode, equipped with strong SSL/TLS detection capabilities. The DDoS Protector that is used for detection is also equipped with signaling capabilities – to higher-tier (DDoS Protector) mitigation devices so that it can activate higher-tier mitigation, when required. Mitigation tiers are built so that the first level of mitigation can be done by the same DDoS Protector detecting the attack. The second level of mitigation could be delegated to the DDoS Protector devices located in the operator's local scrubbing center.
Mitigation by Cyber Controller on the peering edge router
Two-tier detection and mitigation
©2023 Check Point Software Technologies Ltd. All rights reserved. | April 2023 | Page 8
The last tier of mitigation could be the Cloud network, where traffic will be diverted to, by the Cyber Controller. Additionally, there is the ability to copy DDoS Protector configuration and baseline information between mitigation tiers, e.g., from the DDoS Protector in the CPE to the DDoS Protector in the scrubbing center and Cloud. This capability allows immediate mitigation without additional learning and detection time. PROTECTOR CYBER CONTROLLER FOR SERVICE PROVIDERS USE CASE BENEFITS
Use Case
Attack Detection Method
Operation Benefits
1 Flow Detector Traffic diversion to scrubbing center using BGP / BGP Flowspec
Best quality-of-mitigation solution in the industry Wide attack coverage, mitigating all types of DoS/DDoS attacks Highest mitigation accuracy, blocks attack traffic without blocking legitimate user traffic Single pane of glass Single vendor solution
2 Third-party NetFlow-based detector
Traffic diversion to scrubbing center using BGP / BGP Flowspec
Best mitigation solution in the industry Wide attack coverage for mitigation of all types of DoS/DDoS attacks Highest mitigation accuracy to block attack traffic without impacting legitimate user traffic
3 Flow Detector BGP Flowspec Rate-limit / blocking anomaly traffic on router
Fast detection and mitigation (min – 2sec) Rich visibility - anomaly analytics, router dropping statistics. Non-intrusive – fully Out-of-path solution, no need to install machines in data path.
4 DDoS Protector Local mitigation with DDoS Protector Traffic diversion to scrubbing center using BGP Inject mitigation policy to peering DDoS Protector Shared mitigation policy between mitigation devices Set blackholing rule on peering router
Use case 1 plus: On-premises attack mitigation by DDoS Protector Flexible operations per incident to resolve any service provider use case Application-layer protection Low and slow attack protection
SUMMARY Protector Cyber Controller allows service providers to easily automate security incident response operations, even in the most complex and highly distributed environments. The cyber command and control application maximizes security effectiveness with minimal operational effort and overhead. Cyber Controller extends Check Point’s DDoS infrastructure protection solution by adding always-on/Smart Tap and hosted customer protection use cases, for service providers to provide the widest attack detection coverage coupled with immediate attack mitigation.