Customer Stories / Software & Internet / New Zealand

2024
RedShield logo

Strengthening Web Application Security at Scale Using AWS Global Accelerator with RedShield

Learn how RedShield enhanced the scalability and resiliency of its web-application-security services using AWS.

Days instead of months

to resolve critical security issues for customers

1.3 Tbps peak traffic mitigated

from DDoS attacks

Tens of millions

of application traffic requests handled per second

Maintained business continuity compliance

during deployment and in production

Provides

warranted risk reduction

Overview

Web-application-security company RedShield provides a warranted risk-reduction management service that helps customers thoroughly understand, prioritize, and manage security risks according to business priorities. The service outsources full responsibility to RedShield for deploying security controls and application-specific software patches to reduce risk without impacting business continuity.

Often, businesses focus on functional capabilities, such as web-application-firewall tools as a service. However, successfully deploying these controls depends on critical nonfunctional capabilities, such as change management, monitoring, and event response.

To deliver and warrant measurable risk reduction for its customers, RedShield assumes responsibility for both functional and nonfunctional capabilities. As web attacks become more sophisticated and frequent, RedShield needs to continually enhance its security solution.

After a thorough market analysis, RedShield selected Amazon Web Services (AWS) and adopted several services, including AWS Global Accelerator, which improves application availability, performance, and security using the AWS global network. This architecture provides the required scalability, resiliency, and functionality to deliver excellent web application security and risk reduction at scale.

Two people sitting at computer

Opportunity | Using AWS to Scale Web Application Security for RedShield

RedShield’s service keeps customers informed about evolving cyberattacks so that they understand and prioritize security risks. The service manages these risks by reviewing application security testing data and conducting weekly audits. RedShield proposes solutions that are based on technical and economic considerations and focuses on identifying and managing business continuity risks. It runs test plans to minimize the likelihood of risks materializing and maintains operational event-response capabilities to minimize disruptions.

With the continual rise in the volume and sophistication of distributed denial of service (DDoS) attacks, it is no longer enough to detect and then dynamically introduce protection networks. Confirming that these networks cater for all scenarios is increasingly difficult. “Even if we were scrubbing 99 percent of attack traffic, the remaining 600 Gbps could disrupt the application,” says Matt Taylor, head of business development at RedShield.

RedShield needed a solution with automatic scaling to analyze many inbound transactions. The company also wanted to geographically distribute its points of presence to make applications more difficult for attackers to target. “It was clear that AWS matched our requirements exactly,” says Taylor.

In 2020, RedShield began migrating its on-premises infrastructure to AWS. “CPU wasn’t an issue, automatic scaling was awesome for us, and AWS Global Accelerator gave us what no one else was offering: the ability to publish in 80–100 data centers,” says Taylor. The company created technical designs and built a proof of concept by early 2021. To migrate its existing customers, RedShield ported its entire configuration to AWS. However, to support its large workloads efficiently, it needed to change how it managed IP addresses.

The standard AWS Global Accelerator quota for each AWS account is 20 accelerators, but RedShield needed around 500 to quickly onboard new customers. So RedShield turned to AWS Enterprise Support, which provides businesses with a concierge-like service to achieve outcomes and find success in the cloud. It engaged the AWS Enterprise Support team early in the process to evaluate RedShield’s network architecture and provide appropriate guidance for deploying AWS Global Accelerator resources. The team recommended that RedShield move away from its previous single-account, bring-your-own-IP-address approach to a multi-account architecture. It also suggested using IP addresses provided by AWS Global Accelerator to benefit from its scaling mechanisms while reducing costs. During the implementation, the AWS Enterprise Support team used the AWS Infrastructure Event Management (AWS IEM) program, which offers support for planning and running business critical events.

kr_quotemark

On AWS, you get a massive defensive and distributed presence. In peacetime, this gives you speed, and during unrest, it gives you protection.”

Matt Taylor
Head of Business Development, RedShield

Solution | Mitigating Attacks Peaking at over 1.3 Tbps Using AWS Global Accelerator

Static IP addresses from AWS Global Accelerator are anycast from all AWS edge locations at the same time, so RedShield has increased the resiliency of its existing attack surface. “We were partially using anycast across the United States, Australia, and New Zealand, but to have it massively scale across the entire AWS architecture was significantly better,” says Taylor. As RedShield shifted to using IP addresses from AWS, it began adopting its multi-account strategy to onboard new customers quickly and improve its networking performance at scale. By using multiple accounts, the company better positioned itself to scale for thousands of customers while maintaining high performance and security (under the AWS Shared Responsibility Model). “Because we’re using AWS Global Accelerator, all traffic enters the AWS network at the closest possible point,” says Taylor. “Our customers have experienced 40 percent more speed of page load.”

RedShield uses AWS to provide crucial, virtually always-on DDoS protection. The company uses Elastic Load Balancing (ELB), which distributes network traffic to improve application scalability, to make its infrastructure flexible and resilient. “On AWS, you get a massive defensive and distributed presence,” says Taylor. “In peacetime, this gives you speed, and during unrest, it gives you protection.” RedShield’s cloud infrastructure on AWS has mitigated attacks peaking at over 1.3 Tbps, including 25 million Domain Name System requests per second and 1.2 million HTTP requests for web application login per second.

On AWS, RedShield helps customers resolve issues quickly and with minimal impact. “We’ve had a customer come to us with a huge issue that penetration testers said would require a rearchitecting of the application to fix,” says Taylor. “Their developers said it would take 6 months. We got them back up and running within 2 days—and that was over the weekend.” RedShield is providing fast, globally distributed access to its customers’ websites while enhancing resiliency on AWS. The company has also reduced the manual work required to maintain its services by 50 percent and expects to further reduce labor costs. “We wanted to minimize complexity so that we could maximize innovation,” says Taylor. “By going all in on AWS, we’re using AWS optimally while driving costs down.”

Outcome | Offering Cybersecurity to More Customers in AWS Marketplace

RedShield plans to finish the migration by the end of 2024. The company wants to offer its services to even more customers through AWS Marketplace, where businesses can find, test, and buy managed services that run on AWS.

“Using AWS services including AWS Global Accelerator, we have a future-proof, scalable, large defensive capability,” says Taylor. “We can leave the management of the infrastructure and scaling to AWS and focus on what we’re good at: delivering secure outcomes.”

About RedShield

RedShield is a web-application-security company that provides a warranted risk-reduction service that outsources responsibility to RedShield for deploying security controls and software patches to reduce risk without impacting business continuity.

AWS Services Used

AWS Global Accelerator

AWS Global Accelerator is a networking service that helps you improve the availability, performance, and security of your public applications.

Learn more »

AWS Countdown

AWS Countdown helps you throughout the project lifecycle to assess operational readiness, identify and mitigate risks, and plan capacity, using proven playbooks developed by AWS experts.

Learn more »

AWS Enterprise Support

AWS Enterprise Support provides a comprehensive suite of resources, including proactive planning, advisory services, automation tools, communication channels, and 24/7 expert support.

Learn more »

Elastic Load Balancing

Elastic Load Balancing (ELB) automatically distributes incoming application traffic across multiple targets and virtual appliances in one or more Availability Zones (AZs).

Learn more »

More Software & Internet Customer Stories

no items found 

1

Get Started

Organizations of all sizes across all industries are transforming their businesses and delivering on their missions every day using AWS. Contact our experts and start your own AWS journey today.