Written by:

This article has also been published in Norwegian on Digi.no. You can find the first part of this blog series here.

 

The most commonly used methods and solutions for dealing with denial-of-service attacks have not kept pace with how applications and services are built today.

As a result, these methods are not particularly effective. To put more appropriate measures in place, it is important to take a step back and gain an overview of our service architecture, usage patterns and potential bottlenecks.

Rather than relying on a trial-and-error strategy along the lines of, "Block country X and set these limits on the number of connections", it is more useful to ask questions such as: "What has changed from the normal traffic pattern, who is behind these changes, and are they affecting the availability of our applications?"

This is information you should expect your solutions to provide, without requiring you to take manual action. Modern solutions that understand usage patterns and traffic content, and continuously adjust accordingly, already exist.

Ask the right questions

An important step in any assessment is to ask: where are the bottlenecks?

This is the same question an attacker is trying to answer. Attackers, for their part, are looking for the most efficient way to carry out their actions. In other words, attackers look for where they can have the greatest impact with the least effort. If we have bottlenecks that are costly to scale, or simply cannot be avoided, we should build our defences around them.

Another question to consider is: Where can I absorb the attack? With a globally distributed security architecture, volumetric attack traffic can be detected and filtered at distributed PoPs (Points of Presence) located closer to the sources of the attack.

This happens before the traffic reaches the organisation's own infrastructure. The same architecture can protect services from L3/L4 attacks (network and infrastructure) through to advanced L7 attacks (application and service).

When attackers can rapidly change tactics, traffic patterns and infrastructure, often with the help of AI, we as defenders need to keep pace. Automation is no longer a luxury, but a necessity.

There is no time for manual analysis and measures that depend on human interaction at every stage when the nature of an attack can change within seconds. Doing so gives the attacker a significant advantage and a greater ability to sustain the attack. Modern protection must therefore be able to automatically detect, classify and mitigate much of the incident.

People are still necessary for control and oversight. The question therefore becomes: how quickly can we move from detection to actual mitigation?

By addressing these questions and developing a strategy for dealing with denial-of-service attacks, organisations can ensure consistent management of the security capabilities needed to provide robust applications.

If the only possible route into an Internet-facing environment is through such a solution, the likelihood of attackers finding gaps they can exploit is minimised, while the cost of carrying out a successful attack becomes disproportionately high.

Of course, everything comes at a cost. For many organisations, DDoS is primarily a low-risk problem because the consequences are limited to downtime and the resulting impact on revenue, reputation and similar factors. The main point, however, is that protecting against these attacks is relatively straightforward if organisations are willing to do the work and make the necessary investments.

A behavioural problem

The cybersecurity industry needs to stop treating DDoS as simply a problem of too much traffic that can be solved by adding more blocking rules. Modern DDoS is a behavioural problem, one that threatens distributed application infrastructure with many dependencies.

The defence therefore needs to understand behaviour and, in doing so, be at least as distributed and adaptive as the attacker. Organisations that depend on high availability of their services and the trust of the public and their customers must also consider solutions that are effective against today's threat actors and attack methods.

 

This article has also been published in Norwegian on Digi.no. You can find the first part of this blog series here.

 

Get in touch