๐๐๐๐ฟ๐ฒ ๐ฆ๐ฒ๐ฐ๐๐ฟ๐ถ๐๐ ๐ก๐ฒ๐๐: ๐๐๐๐ฟ๐ฒ ๐๐๐ผ๐ฆ ๐ฆ๐ฒ๐ป๐๐ถ๐ป๐ฒ๐น ๐ฆ๐ผ๐น๐๐๐ถ๐ผ๐ป ๐ฎ๐ป๐ฑ ๐ช๐๐ ๐ฃ๐น๐ฎ๐๐ฏ๐ผ๐ผ๐ธ ๐๐ป๐๐ฒ๐ด๐ฟ๐ฎ๐๐ถ๐ผ๐ป
Learn how to how to integrate the Azure DDoS Sentinel Solution with the Azure WAF Playbook to enable a powerful automated detection and response system.
With this integration, the Azure DDoS Sentinel Solution and the WAF Playbook work together to prevent attacks with the steps described below:
1๏ธโฃDuring the first stage of a multi-vector attack campaign, initiated by a malicious actor, the DDoS attack floods the customerโs application, creating chaos and serving as a diversion for the subsequent attack.
2๏ธโฃUpon identifying the DDoS attack, Azure DDoS protection mitigates the attack and generates logs that are transmitted to Microsoft Sentinel.
3๏ธโฃMicrosoft Sentinel extracts the source IP addresses of the attackers from the logs and triggers the WAF Playbook.
4๏ธโฃThe WAF Playbook adds the attack IP addresses to a custom WAF rule with a block action. Azure WAF becomes ready to mitigate the forthcoming stages of the adversary's attack cycle.
5๏ธโฃHaving employed the DDoS attack as a smokescreen, the adversary now attempts to breach the application to take the sensitive data.
6๏ธโฃAzure WAF acts by blocking access from the source IP addresses of the attacker, thereby preventing them from reaching the data.
https://techcommunity.microsoft.com/t5/azure-network-security-blog/enhancing-your-azure-security-azure-ddos-sentinel-solution-and/ba-p/3913420
#azure #azuresecurity #azurenetworksecurity #ddos #azureddos #waf #azurewaf #sentinel #microsoftsentinel #microsoft #soc #automation #soar #siem #playbook #cybersecurity #microsoft #microsoftsecurity #cloudsecurity