Customer Stories / Financial Services

2023
BitBank Logo

Improving DDoS Attack Response Using AWS Shield with Bitbank

Learn how bitbank in the financial services industry redesigned its DDoS attack response using AWS Shield Advanced.

Improved

DDoS attack response speed

Complies

with Financial Services Agency regulations

Secure and stable

service availability

Attack detection

without needing to scale up personnel

Overview

With distributed denial-of-service (DDoS) attacks on the rise, cryptocurrency exchange Bitbank Inc. (bitbank) decided to change its response workflow and upgrade its security using Amazon Web Services (AWS). DDoS attacks rose 30 percent globally between early 2021 and early 2022, and keeping private keys safe without interrupting customers’ access to their funds is imperative for bitbank. Working alongside the AWS team, bitbank created a new process for responding to DDoS attacks. With this new process and services like AWS Shield, a managed DDoS protection service that safeguards applications running on AWS, bitbank has improved response speed to DDoS attacks, makes sure there is no loss of opportunity for customers, and achieves secure service availability and stability.

finger pressing computer key with bitcoin, dollar symbol and exchange word. crypto mining concept

Opportunity | Using AWS Shield to Redesign DDoS Response Workflow for Bitbank

Bitbank was founded in 2014 and provides trade data, charts, and technical analysis tools to nearly 600,000 users in Japan. The company started as a cryptocurrency exchange and is preparing to expand its services into other regions. As customers keep their digital assets with the company in the form of digital wallets, security has always been of high importance to bitbank. But its workflow to accomplish this wasn’t efficient. Each time the company discovered a DDoS attack, it had to decide how to respond, gain internal approval from the chief technology officer, and then implement a response. With DDoS attacks on the rise and nearly 440,000 DDoS events recorded in the first half of 2022, bitbank wanted to improve its response time and make sure its services stayed available so that customers would not have any loss of opportunity and bitbank would not lose out on revenue opportunities. Furthermore, it is vital to comply with Financial Services Agency regulations and take further measures to keep private keys to digital wallets safe.

Bitbank is cloud native and has been using AWS services since its inception. After evaluating various cloud service offerings, the starting company chose AWS. “AWS stood out because of the range of services, strong documentation, and high quality of support it provides,” says Shogo Ishikawa, infrastructure engineer at bitbank. To keep its origin server protected from traffic, the company uses Amazon CloudFront, a content delivery network service built for high performance, security, and developer convenience. The company used this solution to reduce pressure on the regional server by sending responses from the edge cache.

kr_quotemark

Using AWS Shield Advanced and the new processes we have in place, we have the peace of mind to focus on our other work.”

Kensuke Ota
Manager of the Information Security Team, bitbank

Solution | Improving DDoS Attack Response Speed Using AWS Shield Advanced

To make the distinction between an increase in natural traffic and a DDoS attack, the company uses AWS Shield Advanced. Now, whenever the company identifies an attack, bitbank teams follow a predetermined process that no longer needs additional approval. Furthermore, the company has access to support from the AWS Shield Response Team whenever a security event arises. Bitbank began the implementation of its new process in 2022 and completed the majority in October 2022.

Bitbank received support from AWS Enterprise Support, 24/7 technical support from high-quality engineers, and other AWS teams for this redesign of its DDoS attack response workflow. During this transition process, bitbank was alerted to the threat of a DDoS attack. The company took action immediately and, alongside the AWS team, switched to AWS Shield Advanced and made the necessary configurations to prevent the attack from happening—all within a few hours. To automate many of the configuration tasks for its new response workflow, bitbank chose AWS CloudFormation, used to model, provision, and manage AWS and third-party resources by treating infrastructure as code. “The biggest advantage of AWS-managed services is that we can automate processes for our operations,” says Shogo Ishikawa. “Being able to achieve secure attack detection without needing to scale up personnel is an advantage for small-scale organizations.”

Bitbank also uses AWS WAF, which businesses can use to protect themselves against common web exploits and bots that can affect availability, compromise security, or consume excessive resources. The company uses AWS WAF to make rules changes in its firewall as situations and needs change. Bitbank redesigned its response workflow for DDoS attacks and, as part of the process, upgraded AWS WAF and changed from AWS Shield Standard to AWS Shield Advanced, which is tailored to help protect against sophisticated DDoS events on more layers of an application.

With the new DDoS attack response workflow, bitbank is secure in the availability of its services and its ability to respond to and mitigate any DDoS attacks. “Using AWS Shield Advanced and the new processes we have in place, we have the peace of mind to focus on our other work,” says Kensuke Ota, manager of the infrastructure security team at bitbank. The new workflow is also much faster in responding to DDoS attacks because it does not involve additional permissions to take effect. When a DDoS attack is detected, bitbank can begin following the predetermined mitigation process immediately. This safeguarded availability of service for bitbank results in direct benefits to its customers. End users experience no loss of opportunity for trading during DDoS attacks because the new process is quick to deal with them, making sure there is no loss of availability of services for customers.

Architecture Diagram

DDoS Response Workflow

Click to enlarge for fullscreen viewing. 

Outcome | Expanding Securely Using AWS

Bitbank now has the time for innovation and expansion and is looking at other AWS services to make security more pervasive. Bitbank wants to bring the pieces of its security together into one unified solution, like AWS Shield Advanced and AWS GuardDuty—a threat detection service that continuously monitors AWS accounts and workloads for malicious activity and delivers security findings for visibility and remediation—to create a secure operational posture for the company.

Bitbank is also considering expansion to regions outside of Japan and would use AWS to scale to these other regions. “The business landscape is ever-changing, and that change is really fast,” says Kensuke Ota. “We are very happy to continue using AWS-managed services to improve our business.”
 

About bitbank inc.

Founded in 2014, bitbank inc. is a cryptocurrency exchange in Japan. The company has around 600,000 user accounts and provides trade data, charts, and technical analysis tools on multiple web and smartphone solutions.

AWS Services Used

AWS Shield

AWS Shield is a managed DDoS protection service that safeguards applications running on AWS.

Learn more »

Amazon CloudFront

Amazon CloudFront is a content delivery network (CDN) service built for high performance, security, and developer convenience.

Learn more »

AWS WAF

AWS WAF helps you protect against common web exploits and bots that can affect availability, compromise security, or consume excessive resources.

Learn more »

AWS CloudFormation

AWS CloudFormation lets you model, provision, and manage AWS and third-party resources by treating infrastructure as code.

Learn more »

Get Started

Organizations of all sizes across all industries are transforming their businesses and delivering on their missions every day using AWS. Contact our experts and start your own AWS journey today.