Riverhead Networks Announces "Centralized Protection" for Helping ISPs Protect Customers From DDoS Attacks Deployment Innovation for MPLS Networks Allows Servic

22.09.2003, 16:17

CUPERTINO (USA, California) September 22 (PROTEXT/MARKETWIRE/ots) - Riverhead Networks, a leading provider of distributeddenial-of-service (DDoS) and worm solutions that ensure businesscontinuity for ISPs, data centers and large enterprises, todayannounced a new "centralized protection" architecture thatsupports more scalable, flexible and cost-effective deploymentoptions for service providers who want to protect theirMultiprotocol Label Switching (MPLS)-based networks -- and theircustomers -- from DDoS attacks.

"Our service provider customers are eager to deploy DDoSdetection and mitigation solutions to protect their owninfrastructures, and to extend those services to theircustomers," said Yuval Rachmilevitz, president and CEO ofRiverhead Networks. "The challenge is finding a way to cost-effectively deploy such solutions in highly distributedenvironments supporting scores of online businesses spread overthe provider's service area. Riverhead's centralized protectioncapabilities, enabled by our 'long diversion' technology, are adirect response to customer demands for scalable options fordeploying DDoS protection in large environments."

How it Works

In a typical service provider environment, DDoS detection andmitigation devices such as the Riverhead Detector and RiverheadGuard would be deployed at all edge points within theinfrastructure where protection is needed. The centralizedprotection feature allows ISPs to consolidate a smaller numberof Guards in a central location and share them among multiple,geographically dispersed customers.

The key to centralized protection is a concept called "longdiversion." When an attack is detected by a Riverhead Detectoror other third-party device, all traffic destined for thetargeted device, regardless of its location, is rerouted, orlong diverted, from all peering points to the centralized Guard.The Guard analyzes incoming traffic on a per-flow basis, applyinga series of patented technologies included in Riverhead's uniqueMulti-Verification Process (MVP) architecture to identify andremove malicious packets before returning legitimate transactionsto the network, ensuring uninterrupted operations. Bymaintaining business continuity, the Riverhead solution offerssuperior DDoS protection than other common techniques such as"sinkholing," which sends all traffic addressed to a targeteddevice -- both good and bad -- to a dedicated server foranalysis, never to be seen again.

Centralized protection also greatly simplifies installation,administration and maintenance, enabling DDoS protectionservices to be easily provisioned for individual users on demand.In addition, the deployment allows service providers to scaleDDoS protection services easily and efficiently, withoutrequiring any unnecessary upfront investments.

Competitive Advantage

For service providers looking for ways to deliver services inan efficient and cost-effective manner, Riverhead's centralizedprotection feature represents a considerable competitiveadvantage.

"Distributed denial-of-service attacks are problematic forservice providers and enterprises alike," said Eric Hemmendinger,research director for security and privacy at Aberdeen Group."But the sprawl of service provider environments can make DDoSprotection too expensive to deploy globally unless there is a wayto centralize the DDoS mitigation solution. Riverhead's approachto DDoS prevention -- which provides for centralized protection -- offers a cost-effective approach that can be a foundation forrevenue-enhancing services."

Availability

The Riverhead Guard with centralized protection is availableand shipping now.

About Riverhead Networks

Riverhead's solutions defend networks against crippling DDoSand worm attacks, securing Internet availability. By identifyingand filtering out malicious traffic, the company's securitysystems ensure business continuity for ISPs, hosting centers andlarge enterprises, maintaining network and server availabilityfor legitimate users.

Riverhead's patent-pending Multi-Verification Process (MVP)architecture automatically blocks attack packets and forwardsreal customer transactions, without relying on other networkdevices. "Dynamic diversion" enables Riverhead to redirect onlytraffic flowing towards a targeted resource through theRiverhead Guard to block malicious packets, maximizingscalability and reliability benefits.

Riverhead Networks is funded by Sequoia Capital, CiscoSystems, Gemini Israel Funds, Intel Capital and Koor VentureCapital. For more information about Riverhead, visitwww.riverhead.com.

Riverhead Networks, Riverhead Detector, Riverhead Guard andMulti-Verification Process are trademarks of Riverhead NetworksInc. All other brand and product names are trademarks orregistered trademarks of their respective holders.

Contacts: Lenny Bonsall Riverhead Networks 408.253.5738lenny@riverhead.com

Subscribers please note that material bearing the slug"PROTEXT" is not part of CTK's news service and is not to bepublished under the "CTK" slug. Protext is a commercial serviceproviding distribution of press releases from clients, who areidentified in the text of Protext reports and who bear fullresponsibility for their contents.

PROTEXT