Domain Names Registration, Transfer Domains, Domain/Mail Forwarding, Managed DNS, Thawte Digital SSL Certificates, Live Chat Services, Linux & Windows Web Hosting, Email Hosting, Web Design, WebSite Builders, WebSite Templates, SEO, Dedicated Servers
Home Domain Names Web/Email Hosting Digital SSL Certificates Website Builder Live Chat Services Templates Documentation

June 3rd, 2008

Web / Email Hosting Features - Data Center Security

Features / Security

Our Holistic Security Approach

In order to reduce security risks to minimum, a holistic approach to security is required. Our security processes are born out of a clear definition of the threats to our system.

Security threats are a result of the various interaction points that an application provides to the external world, and the various users that can interact with these interfaces. For instance Your Customers, Your Resellers, Your staff, Our Staff, Anonymous Internet Users and Third Party Servers are interacting with our Systems at any given point of time. Each of these actors need to have different access levels and different rights and permissions.

Security Goals

Privacy - Information within our infrastructure and systems will only be accessible by authorized users

Integrity - Data and information within our infrastructure cannot be tampered with by any unauthorized user

Data Protection - Data within the systems cannot be harmed, deleted or destroyed

Identification and Authentication - Ensures that any user of the system is who he claims to be and eliminates chances of impersonation

Network Service Protection - Ensures that networking equipment is protected from malicious hacking attempts or attacks that threaten uptime

Our Holistic Security Model

Our Security platform and process leverage on multiple levels of security - consisting of Security Systems and Equipment1 combined with Security Procedures and Practices2 and Auditing Processes3, to ensure unparalleled security for all the services we provide. The platform tackles security at 7 different levels.
Level 1 - Datacenter Security
Our global datacenter partnerships are a result of a comprehensive Due diligence process. Security and stability are two of the most important variables in our due diligence process. All datacenters are equipped with surveillance cameras, biometric locks, authorization-based access policies, limited datacenter access, security personnel, and similar standard security equipment, processes and operations. What separates us however is the fact that our due diligence process also incorporates a measure of proactiveness demonstrated by the datacenter towards security. This is measured by evaluating past practices, customer case studies, and the amount of time the datacenter dedicates towards security research and study.
Level 2 - Network Security
Our global infrastructure deployments incorporate DDOS mitigators, Intrusion Detection systems, and Firewalls both at the edge and the Rack level. Our deployments have weathered frequent hacking and DDOS attempts (sometimes as many as 3 in a single day) without any degradation.

Protection against Distributed Denial-of-Service (DDoS) Attacks
Denial of Service is currently the top source of financial loss due to cybercrime. The goal of a Denial-of-Service attack is to disrupt your business activities by stopping the operation of your web site, email or web applications. This is achieved by attacking the servers or network that host these services and overloading the key resources such as bandwidth, CPU and memory. The typical motives behind such attacks are extortion, bragging rights, political statements, damaging competition etc. Virtually any organization that connects to the Internet is vulnerable to these attacks. The business impact of large sustained DoS attacks is colossal, as it would lead to lost profits, customer dissatisfaction, productivity loss etc due to inavailability or deterioration of service. A DoS attack in most cases would even land you with the largest bandwidth overage invoice that you have ever seen.

Our Distributed Denial-of-Service protection system provides unrivaled protection against DoS and DDoS attacks on your internet-facing infrastructures i.e. your websites, email and mission critical web applications, by using sophisticated state-of-the-art technology which automatically triggers itself as soon as an attack is launched. The DDoS mitigator’s filtering system blocks almost all fraudulent traffic and ensures that legitimate traffic is allowed up to the largest extent possible. These systems have seamlessly protected several web sites from large service outages caused by simultaneous attacks as large as 300+ Mbps in the past, thus allowing organizations to focus on their Business.

Firewall Protection
Our round-the-clock firewall protection system secures the perimeter and delivers the very best first line of defense. It uses highly adaptive and advanced inspection technology to safeguard your data, website, email and web applications by blocking unauthorized network access. It ensures controlled connectivity between the servers that store your data and the Internet through the enforcement of security policies devised by subject matter experts.

Network Intrusion Detection system
Our network intrusion detection, prevention and vulnerability management system provides rapid, accurate and comprehensive protection against targeted attacks, traffic anomalies, “unknown” worms, spyware/adware, network viruses, rogue applications and other zero-day exploits. It uses ultramodern high-performance network processors that carry out thousands of checks on each packet flow simultaneously with no perceivable increase in latency. As packets pass through our systems, they are fully scrutinized to determine whether they are legitimate or harmful. This method of instantaneous protection is the most effective mechanism of ensuring that harmful attacks do not reach their targets.
Level 3 - Host Security
Hardware Standardization We have standardized on hardware vendors that have a track record of high security standards and quality support. Most of our infrastructure and datacenter partners use equipment from Cisco, Juniper, HP, Dell etc.

Host Based Intrusion Detection System
With the advent of tools that are able to bypass port blocking perimeter defense systems such as firewalls, it is now essential for enterprises to deploy Host-based Intrusion Detection System (HIDS) which focuses on monitoring and analyising the internals of a computing system. Our Host-based Intrusion Detection System assists in detecting and pinpointing changes to the system and configuration files - whether by accident, from malicious tampering, or external intrusion - using heuristic scanners, host log information, and by monitoring system activity. Rapid discovery of changes decreases risk of potential damage, and also reduces troubleshooting and recovery times, thus decreasing overall impact and improving security and system availability.
Level 4 -  Software Security
Our applications run on myriad systems with myriad server software. Operating Systems include various flavors of Linux, BSD, Windows. Server Software includes versions and flavors of Apache, IIS, Resin, Tomcat, Postgres, MySQL, MSSQL, Qmail, Sendmail, Proftpd etc etc. We ensure security despite the diverse portfolio of software products we utilize by following a process-oriented approach.

Timely Application of Updates, Bug Fixes and Security Patches
All servers are registered for automatic updates to ensure that they always have the latest security patch installed and that any new vulnerabilities are rectified as soon as possible. The largest number of intrusions result from exploitation of known vulnerabilities, configuration errors, or virus attacks where countermeasures ARE already available. According to CERT, systems and networks are impacted by these events as they have “not consistently” deployed the patches that were released.

We fully understand the requirement for strong patch and update management processes. As operating systems and server software get more complex, each newer release is littered with security holes. Information and updates for new security threats are released on an almost daily basis. We have built consistent, repeatable processes and a reliable auditing and reporting framework which ensures that all our systems are always up-to-date.

Periodic Security Scans
Frequent checks are run using enterprise grade security software to determine if any servers have any known vulnerabilities. The servers are scanned against the most comprehensive and up-to-date databases of known vulnerabilities. This enables us to proactively protect our servers from attacks and ensure business continuity by identifying security holes or vulnerabilities before an attack occurs.

Pre-Upgrade testing processes
Software upgrades are released frequently by various software vendors. while each vendor follows their own testing procedures prior to release of any upgrade, they cannot test inter-operability issues between various software. For instance a new release of a database may be tested by the Database vendor. However the impact of deploying this release on a production system running various other FTP, Mail, Web Server software cannot be directly determined. Our system administration team documents the impact analysis of various software upgrades and if any of them are perceived to have a high-risk, they are first beta-tested in our labs before live deployment.
Level 5 - Application Security
All of the application software that is used in the platform is built by us. We do not outsource development. Any 3rd party Products or Components go through comprehensive training and testing procedures where all elements of such products are broken down and knowledge about their architecture and implementation is transferred to our team. This allows us to completely control all variables involved in any particular Product. All applications are engineered using our proprietary Product Engineering Process which follows a proactive approach towards security. Each application is broken down into various components such as User Interface, Core API, Backend Database etc. Each layer of abstraction has its own security checks, despite the security checks performed by a higher abstraction layer. All sensitive data is stored in an encrypted format. Our engineering and development practices ensure the highest level of security with regards to all application software.
Level 6 - Personnel Security
The weakest link in the security chain is always the people you trust. Personnel, Development staff, Vendors, essentially anyone that has privileged access to your system. Our Holistic Security Approach attempts to minimize security risk brought on by the “Human Factor”. Information is divulged only on a “need-to-know” basis. Authorization expires upon the expiry of the requirement. Personnel are coached specifically in security measures and the criticality of observing them.

Every employee that has administrator privileges to any of our servers goes through a comprehensive background check. Companies that skip out on this are putting to risk all sensitive and important data belonging to their customers, as no matter how much money is invested into high-end security solutions, one wrong hire - having the right amount of access - can cause greater damage than any external attack.
Level 7 - Security Audit Processes
In a vast deployment of globally distributed servers, audit processes are required to ensure process replication and discipline. Are all servers being patched regularly? Are the backup scripts running all the time? Are offsite backups being rotated as desired? Are appropriate reference checks being performed on all personnel? Is the security equipment sending out timely alerts? These and many such questions are regularly verified in an out-of-band process that involves investigation, surveys, ethical hacking attempts, interviews etc. Our audit mechanisms alert us to a kink in our security processes before it is discovered by external users.

Tags: , , , , , , , , , , , , , , , , , , , , , ,

February 22nd, 2008

Overselling Web Hosting, a good practice or a bad one?

Is overselling a good practice or a bad one? There are a lot of different takes on this, and I would like to share my thoughts on it.

Overselling, in the simplest of terms, is selling more than you have, based on the assumption that not every Customer would use all of the resources provided to him. However, if consumers begin to use 100% of the resources promised to them, it becomes a major problem for both, the Provider as well as the Consumer. On the other hand, overselling could be considered a good practice, since it actually keeps a check on end Customer prices. If overselling was not practiced by companies, getting web-space would be much more expensive than what it is today.

Overselling done by Hosting providers can be understood by drawing a parallel to a more common scenario, that of telecommunications companies. Usually telecom companies oversell many times over their installed capacities, based on the common logic that not all Customers will use their mobile phones at one time, or to the fullest capacity. Now, when all Customers do use their allocated connections at the same time, the quality of service plummets below the promised mark. Hence, on days like New Year’s eve, when most of us try to get in touch with our dear ones, it is almost impossible to make a call. Blame it on overselling. Overselling however, keeps prices at low rates. If there would be no overselling, only a few of us would have mobile phones and those few, would pay some hefty fees to use them.

Coming back to the Hosting industry, let’s discuss the technicalities of overselling. The most common parameter oversold by Hosting Providers is bandwidth. Let us take, for example, a web hosting company that has a server with a 120 GB hard drive and 800 GB bandwidth. They start selling plans with 1GB space and 10GB transfer quota. After selling 80 plans the entire available bandwidth gets reserved and you’d normally assume that the host has hit the ceiling in terms of available bandwidth resources and can’t sell anymore. But that’s not what happens in reality. It’s common knowledge that not all websites consume the entire bandwidth allotted to them. The peak level bandwidth consumption of these websites may never cross 350-400 GB. Now, the web hosting company decides to maximize the profits of their server (cost is constant) by utilizing the extra bandwidth and selling more packages. They sell another 40 plans with the same parameters of 1GB space and 10 GB bandwidth. This space and bandwidth when added to the previous plans, sums up to 120 GB space and 1200 GB bandwidth. Naturally it helps in cutting down the rates and services become that much cheaper. This host is assuming (hopefully intelligently) that the peak bandwidth consumption will yet not cross 800GB, and in most cases that could be right. But, unaccounted overselling is what results in poor quality of service and you surely want to stay miles away from such providers.

I will not say overselling is the best practice, but under strictly controlled measures can be beneficial. There are so many web hosts, catering to every niche in the industry today, that choosing one has become more difficult than ever before. It has become practically impossible to decide one purely on the basis of the plans on their website; you never know whose overselling and by how much. I would keep in mind a couple of ratios, that more often than not, help you determine the “degree of overselling”, if you can call it so. From my experience and a lot of research, I would say that overselling starts when bandwidth to space ratio exceeds 15:1 (which is more of a conservative estimate). I have seen providers selling at 50:1 and even higher, which is nothing but just a disaster waiting to happen. You can also check the cost to bandwidth ratio which starts getting bad if it goes lower than $0.50 for 1GB. These numbers are not proven anywhere; its just something I consider looking at while deciding Hosting Providers.

What’s in it for you?

With regards to overselling, our ratios speak for themselves. Our bandwidth to space is a phenomenal 2/1. Compare it to the fact that overselling begins at somewhere about 15/1, we are way off it! Surprisingly though, we have managed to still offer some of the lowest prices out there.

Tags: , , , , , , , , , , , , , ,


All mentioned prices on our site may change without prior notice. According to policies and restrictions provided by Registries and Certification Authorities, Domain services, Live Chat services and SSL Certificates after purchased cannot be canceled or deleted and are not applicable for refunds. Only Web/Email Hosting and Website Builder services are applicable for refunds during the 30 Day Money Back Guarantee period. Read more...

Pay with your Credit Card. We accept all major Credit Cards.  Pay Securely Online

Copyright © 2007-2008 by VAIOWEB. All Rights Reserved.