DDoS blog series: How do we work to protect against DDoS attacks
There is no shortage of recommendations for how to better prepare for these attacks. However, many of the measures being recommended are outdated

Written by:



This article has also been published in Norwegian on Digi.no. You can find the second part of this blog series here.
This summer, we have seen an increase in successful distributed denial-of-service (DDoS) attacks against important Norwegian online services. The scale of the attacks, and the importance of the services affected, have attracted considerable media attention. Both the causes and possible countermeasures have been discussed, particularly the need for mapping and documentation.
The cybersecurity industry has responded with well-intentioned recommendations and measures to help organisations prepare for attacks and manage them while they are ongoing. At the same time, many of the measures being discussed are partly outdated when it comes to defending against modern attack methods. That does not mean they are irrelevant or should be abandoned, but they need to be complemented by more modern techniques and tools.
Every organisation wants its services to remain available and stable. It is no longer enough to call your ISP once an attack is underway and hope that blocking traffic from a handful of countries or setting limits such as "a maximum of 500 requests per IP" will be sufficient. Particularly if you cannot be certain that these measures will not themselves affect service availability.
Looking more closely at individual packets will rarely be effective during a DDoS attack, as the traffic may not inherently differ from legitimate traffic. A botnet can, and will, send perfectly valid HTTP requests from a large number of legitimate IP addresses and geographical locations.
Static thresholds are a fairly blunt instrument. Set the threshold too low and legitimate users are affected. Set it too high and the attack can continue below the threshold. Geo-blocking has the same weakness: geography alone is a poor indicator of intent.
Modern technology
Most organisations today deliver their applications through hybrid platforms, often distributed across different cloud service providers and physical infrastructure in shared and private data centres. As a result, there is rarely a single Internet connection that can be protected to maintain the availability of an application. To protect applications effectively, organisations need to understand and see the connections between the different dependencies they rely on.
Protecting an organisation's Internet connections is, of course, still important. Otherwise, they remain a potential weakness, just as they have in the past. But every point of exposure needs to be mapped and designed to withstand DDoS attacks, both at the application level and against more sophisticated methods of disruption.
Modern applications need to be protected with modern technology designed for the same conditions as the environments in which they operate. In practice, this means cloud-based infrastructure with automated, AI-driven continuous detection and mitigation of attack attempts, without requiring intervention from the service owner or ISP.
Trying to address DDoS attacks using traditional methods becomes an endless game of cat and mouse, requiring a reactive response every time an attack occurs, often repeatedly during a single wave of attacks.
Overreliance on existing solutions
To protect against DDoS attacks, organisations have often invested in DDoS protection from hyperscalers and cloud providers. Unfortunately, our experience is that these services often fall short, and we continue to see Norwegian organisations experience downtime as a result of DDoS attacks. This is despite these services being marketed as premium offerings and carrying a relatively high price tag. We are surprised by how limited some of these solutions appear to be, and how little practical value they can provide during real attacks.
One current example is Microsoft Azure DDoS Protection. The product uses dynamic thresholds to detect DDoS attacks. The service has no insight into the nature of the traffic, such as protocols, content or characteristics, and instead focuses solely on volume. As a result, if a DDoS attack increases slowly enough, the thresholds may simply rise in line with the traffic volume. The service will then fail to provide the intended protection, something attackers are aware of.
We have seen several examples of this among our clients. Services have become unavailable as a result of relatively simple DDoS attacks that gradually increased in volume. These services are also often something of a "black box", leaving customers with limited ability to understand the details of how the underlying protection actually works. At least, not until the attack has taken place, downtime has occurred, and a post-incident analysis begins.
We therefore recommend challenging providers to explain in detail what their services actually protect against. Organisations should then assess whether that level of protection is sufficient for their own environment.
This article has also been published in Norwegian on Digi.no. You can find the second part of this blog series here.
Get in touch


