Glossary

We frequently update our glossary with terms that may be used in our products and in our industry in general.

  • 95th Percentile

    A bandwidth billing method in which traffic samples are collected over the billing period, the highest 5% are discarded and the next highest value is charged. Console shows the 95th percentile on bandwidth histograms for burstable billing.

  • Amplification Attack

    A reflection attack in which small spoofed requests are sent to third-party servers that answer with much larger responses, aimed at the victim. NTP, DNS, SSDP, CLDAP and memcached are commonly abused. Also known as DrDoS.

  • Anomaly Detection

    Anomaly detection identifies network intrusions and misuse by monitoring system activity and classifying it as either normal or anomalous.

  • Asymmetric Routing

    A network in which the two directions of a conversation follow different paths, so a monitoring or filtering device sees only one of them. Wanguard Filter is stateless by design and works correctly in such networks.

  • Attack Signature

    These signatures reflect patterns in system or network activity that signal a possible virus or hacker attack. IPS and firewalls use these signatures to distinguish between legitimate and potentially malicious activity.

  • Autonomous System (AS)

    A network or group of networks under one administration that presents a common routing policy to the Internet, identified by an AS number. Sensors report top talkers by source AS and by transit AS.

  • BGP

    Border Gateway Protocol, the routing protocol used between autonomous systems. Wanguard uses BGP announcements to blackhole attacked addresses or to divert traffic to a scrubbing center.

  • BGP FlowSpec

    A BGP extension (RFC 5575, updated by RFC 8955) that distributes granular filtering rules - matching addresses, protocols, ports and packet lengths - to routers, so attack traffic can be dropped upstream instead of at the network edge.

  • Botnet

    Botnet is generally used to refer to a collection of compromised machines harboring worms, Trojan horses, or backdoors under a common command and control infrastructure. A botnet's originator can control the group remotely, usually through a means such as IRC, and usually for nefarious purposes.

  • Console

    The web application at the center of Wanguard and Wansight. It aggregates data from every Sensor and Filter deployed in the network and provides dashboards, graphs, traffic reports, alerting and user management.

  • DDoS Protection

    DDoS protection is provided by any form of hardware and/or software that prevents DDoS attacks or DoS attacks from affecting network traffic and internet operations.

  • Deep Packet Inspection (DPI)

    Inspection of packet payloads rather than headers alone, used to recognize attack patterns inside traffic that otherwise looks legitimate.

  • Denial of Service (DOS) attacks

    Denial of Service (DoS) attacks are designed to hinder or completely stop the normal functioning of a website, network, server or other resource. A Distributed Denial of Service attack, aka DDoS, differs from a DoS only in method. A DoS is conducted from one computer or server, whereas a DDoS is a DoS organized to occur simultaneously from a large number of computers or servers.

  • Distributed Denial of Service

    Distributed Denial of Service is an attempt to make a computer resource unavailable to its intended users. Typically the targets are high- profile web servers, the attack aiming to cause the hosted web pages to be unavailable on the internet.

  • Distributed Denial of Service (DDoS) attack

    A Distributed Denial of Service Attack is one in which a multitude of compromised systems attack a single target, thereby causing denial of service for users of the targeted system. The flood of incoming messages to the target system essentially forces it to shut down, thereby denying service to the system to legitimate users.

  • Enterprise network security

    Security products to protect enterprise networks from intrusions, attacks and viruses.

  • False Positive

    Legitimate traffic that is incorrectly reported as an anomaly or an attack. Detection thresholds and profiles are tuned to keep false positives rare without delaying real detections.

  • Filter

    The Wanguard component that activates automatically during an attack and generates granular filtering rules that drop malicious packets while legitimate traffic keeps flowing. It can filter in software or offload rules to supported network cards and switches.

  • Flow Sensor

    The Wanguard and Wansight component that collects and analyzes NetFlow, sFlow, jFlow and IPFIX records exported by routers and switches. It provides traffic accounting, graphs and anomaly detection without seeing the packets themselves.

  • GeoIP

    A database that maps IP addresses to countries and organizations. It is used for per-country traffic tops and for filtering rules that match on country.

  • Internal threat

    Network security threats that happen within the perimeter of an enterprise. Most security threats today are comprised of inside-the-perimeter or internal threats.

  • Internal threat protection

    The technology to protect the inside of an enterprise from botnets, DDoS, zombies, worms, viruses and unauthorized introduced unknowingly or intentionally.

  • IP Group

    A named set of IP addresses or subnets - a customer, a data center, a department - that is monitored, graphed, alerted on and billed as a single entity.

  • IPFIX

    IP Flow Information Export, the IETF standard for flow export (RFC 7011), derived from NetFlow v9. Collected and analyzed by Flow Sensor.

  • jFlow

    The flow export implementation found on Juniper equipment. It is collected by Flow Sensor in the same way as NetFlow.

  • Netfilter

    The packet filtering framework built into the Linux kernel. It is one of the backends Wanguard Filter can use to apply the rules it generates.

  • NetFlow

    A flow export protocol introduced by Cisco in which routers summarize traffic into records describing each conversation. Flow Sensor supports NetFlow versions 5, 7 and 9.

  • Network Behavior Anomaly Detection

    Behavior-based anomaly detection compares a profile of all allowed application behavior to actual network traffic. Any deviation from the profile is flagged as a potential attack. Behavior anomaly detection has the potential to detect attacks of all kind – including "unknown" attacks on custom code.

  • Network Intrusion Detection

    Network intrusion detection identifies inappropriate, incorrect, or anomalous activity. Network intrusion detection systems that operate on a host to detect malicious activity on that host are called host-based intrusion detection systems, and intrusion detection systems that operate on network data flows are called network intrusion detection (ID) systems.

  • Network Intrusion Detection Prevention

    Network intrusion detection prevention is enabled by any form of hardware and/or software that detects inappropriate, incorrect, or anomalous activity.

  • Network security solution

    Security solution to protect the network from intrusions, attacks and viruses.

  • Network security technology

    Security products to protect the network from intrusions, attacks and viruses.

  • Network TAP

    A passive hardware device inserted into a link that copies all traffic to a monitoring port without affecting the link itself. An alternative to port mirroring for feeding Packet Sensor.

  • NTP Amplification

    An amplification attack that abuses NTP servers which answer small spoofed queries with much larger replies, flooding the spoofed address with the responses.

  • Null Routing

    Discarding traffic by routing it to a null interface. It is the mechanism behind blackholing an address that is under attack.

  • Packet floods

    Form of DDoS attack that causes Internet hosts to be unable to stop dealing with packets addressed to them. Once a host's network link becomes congested, IP routers respond to the overload by dropping packets arbitrarily, which causes a decline or stoppage in Internet service.

  • Packet Sensor

    The Wanguard and Wansight component that captures packets from a mirrored port, a network TAP or an in-line interface and analyzes them in real time.

  • Packet Sniffing

    Capturing raw packets from a network interface in order to analyze traffic in detail, including headers and payloads.

  • Port Mirroring (SPAN)

    A switch or router feature that copies traffic from selected ports or VLANs to a monitoring port, where Packet Sensor can analyze it without being in the traffic path.

  • Remotely Triggered Black Hole

    RTBH: announcing a route tagged with an agreed BGP community so that upstream providers drop all traffic toward the attacked address. The target is isolated, but transit links and the rest of the network stay uncongested.

  • Scrubbing Center

    On-premises or cloud infrastructure that receives diverted traffic, removes the attack and returns the clean traffic to its destination.

  • sFlow

    A sampled flow export standard implemented by many switch vendors, in which one packet in N is sampled and exported together with interface counters. Flow Sensor supports sFlow versions 4 and 5.

  • SYN Flood

    A denial of service attack that sends large numbers of TCP SYN packets, usually with spoofed source addresses, to exhaust the connection table of the target.

  • SYN Proxy

    A mitigation technique in which the filtering device completes the TCP handshake on behalf of the protected server and forwards only the connections whose source answers correctly, defeating spoofed SYN, SYN-ACK and ACK attacks.

  • Threat remediation

    The technology required to stop a threat – an intrusion, an attack or a virus from proliferating in the network.

  • Threshold

    The traffic rate - in packets, bits or flows per second - above which a Sensor declares an anomaly for a monitored IP address, subnet or group.

  • Top Talkers

    The IP addresses, subnets, IP groups, ports, protocols or autonomous systems responsible for the most traffic during a given interval.

  • Traffic Anomaly

    Traffic that departs from the expected pattern of an endpoint, such as a sudden rise in packets per second or a protocol that is normally absent. An anomaly raises an alert and can trigger an automated response.

  • Traffic Decoder

    One of the traffic classes a Sensor accounts for and graphs separately - IP, TCP+SYN, UDP, ICMP, DNS, HTTP, NTP and many others - which is what makes it possible to see the shape of an attack rather than just a rise in bandwidth.

  • Traffic Diversion

    Announcing a more specific route so that traffic for an attacked prefix is pulled through a scrubbing center (off-ramp), then returning the cleaned traffic to its destination (on-ramp), often through a GRE tunnel.

  • Trojans

    Trojan horses are malicious programs that damage the host system upon installation. The main distinction between viruses, worms and Trojans is that Trojans do not self-replicate.

  • Wanguard

    Andrisoft software for detecting and mitigating DDoS attacks on large networks. Flow Sensor and Packet Sensor detect anomalies, Filter scrubs the attack traffic and Console manages and reports on everything.

  • Wansight

    The traffic monitoring and analytics edition of the Andrisoft software: the same Sensors and Console as Wanguard, without the attack mitigation features.

  • Worms

    Worms are computer programs that replicate independently, but do not infect other files. Today worms use all available means of replication including LANs, the Internet, email, IRC channels, file-sharing networks, mobile phones and other transport channels.

  • Zero day attack

    Network attacks that take advantage of software vulnerabilities for which there are no available fixes. These attacks are initiated the moment the vulnerabilities are exploited by black hat hackers.

  • Zombie

    A zombie computer or a zombie for short, is a computer attached to the Internet that has been compromised by a hacker, a computer virus, or a Trojan horse. Generally, a compromised machine is only one of many in a botnet, and will be used to perform malicious tasks of one sort or another under remote direction. Most owners of zombie computers are unaware that their system is being used in this way.