Thank you for Subscribing to Telecom Business Review Weekly Brief
Telecom Business Review | Friday, April 09, 2021
DDoS attack is a malicious attempt to make a server or a network resource unavailable to users, typically by temporarily disturbing or interrupting the services of a host connected to the Internet.
Fremont, CA: Unlike aDoS( Denial of Service ) attack, in which one computer and one internet connection are utilized to flood aimed resources with packets, a DDoS(Distributed Denial of Service) attack uses many computers and many Internet connections, usually distributed globally in what is referred to as a botnet.
Anti-DDoS Protection Techniques
Stay ahead of the industry with exclusive feature stories on the top companies, expert insights and the latest news delivered straight to your inbox. Subscribe today.
There are three primary types of DDoS attacks, each with its unique protection strategy and tools:
Volume Based Attacks
Volume-based attacks generate large network-level requests and overwhelm network equipment or servers. These can incorporate UDP floods, ICMP floods, and other attacks with spoofed network packets.
To protect from volume-based attacks, anti-DDoS providers perform large-scale "scrubbing," utilizing cloud servers to inspect traffic, discard malicious applications and let legitimate ones through. This method can deal with massive, multi-gigabyte DDoS attacks. This is also known as DDoS deflation.
Protocol Attacks
Protocol attacks produce requests that leverage weaknesses in network protocols. These involve SYN floods, fragmented packets, and the Ping of Death.
To protect against facing protocol attacks, anti-DDoS tools mitigate them by blocking bad traffic before it reaches your site. In addition, advanced solutions can analyze traffic and differentiate legitimate users from malicious, automated clients and bots.
Application Layer Attacks
In an application layer attack, attackers generate many requests to web applications or other software applications, which appear to come from legitimate users. These incorporate GET/POST floods, low-and-slow attacks, or specific attacks opposing Apache or Windows vulnerabilities.
To protect from application-layer attacks, anti-DDoS systems monitor the behavior of site visitors, block bad bots responsible for application-layer attacks, and challenge unrecognized visitors using multiple mechanisms, such as JavaScript tests, cookie challenges, and CAPTHAs.
Anti-DDoS Software Solutions
Anti-DDoS software runs over present hardware, analyzing and filtering out malicious traffic. Generally, Anti-DDoS software is more cost-effective and simpler to manage than hardware-based solutions.
Still, software and script-based solutions can only offer partial protection from DDoS attacks, are prone to false positives, and will not help mitigate volume-based DDoS attacks. In addition, locally-installed software is more easily overwhelmed than appliances or Cloud-based solutions, which are much more scalable in the face of huge attacks.
Anti-DDoS Firewall
DDoS attacks try to overwhelm the server/firewall by flooding it with a high volume of apparently legitimate requests.
Conventional firewalls are hard-pressed to effectively block DDoS attacks, often becoming the bottleneck for the massive requests and making the attack worse.
Some weaknesses of conventional firewalls can be relieved by adapting network topography and optimizing the deployment and configuration of firewalls and violation prevention/detection systems (IPS/IDS). But even optimal firewall deployment and configuration cannot eradicate DDoS damage, especially in application layer attack scenarios.
Web application firewalls (WAF) can work as an anti-DDoS firewall, which can intelligently weed out bad requests and are an effective and economical alternative for DDoS protection. WAFs, usually deployed in the Cloud, respond to suspicious application requests by sending a cookie or other response – guaranteeing the user is real, and the request is valid before enabling access into the system.
Anti-DDoS Hardware Solutions
Anti-DDoS hardware is a physical layer of security between potential attackers and your network. Even though anti-DDoS hardware can protect from particular types of attacks – other types, like DNS attacks, are not influenced by hardware, as the damage is done before traffic reaches the device.
Hardware protection can be expensive. Including the capital expense of the hardware itself, there are significant operating expenses of the facilities and skilled manpower necessary to maintain, house, and run the equipment. Extra costs are equipment depreciation and upgrades.
Anti-DDoS Hosting
One usual method of reducing the risks of a DDoS attack involves contracting with a DDoS-ready hosting provider that already has the equipment required to absorb bad traffic in the event of a DDoS attack. Still, Anti-DDoS hosting is low efficacy and significantly more costly than conventional hosting.
Within the Anti-DDoS hosting ecosphere, there are commonly two options available to website owners:
• Dedicated hosting – tends to be very expensive and not flexible/scalable.
• Rented hosting – both costly and restricted by the hosting provider's total capacity and the hosting plan's specific capacity.
Still, neither option provides intelligent application layer DDoS mitigation. Additionally, Anti-DDoS hosting is less cost-effective than other options because absorbing DDoS traffic comes at a cost and does not offer smart behavior/signature-based identification.
In a regular Anti-DDoS hosting scenario, website owners pay on an ongoing basis for bandwidth to absorb a likely attack – even if no such attack is ongoing. Therefore, it is more cost-effective and flexible to recognize attacks and scale on-demand to respond to them.
More in News