Written by:

 

This article has also been published in Norwegian on Digi.no. You can find the first part of this blog series here.

 

Why traditional DDoS protection is no longer enough

Traditionally, organisations have relied on large, dedicated "anti-DDoS" appliances in their own data centres, with the reasonable hope that these would have sufficient capacity to withstand an attack. At the same time, IP addresses and countries that repeatedly appeared as sources of malicious traffic would be actively blocked.

Today, applications are distributed across clouds, data centres and SaaS products. It is no longer possible to protect them in the traditional way. At the same time, the volume of traffic that threat actors are now able to direct towards endpoints is often so high that organisations would need disproportionately large and expensive appliances in place just in case an attack occurs.

Even cloud-based systems with autoscaling cannot absorb this traffic without services being negatively affected. In addition, attacks do not necessarily consist solely of high volumes of empty traffic, such as typical SYN floods. Attackers are using modern methods, including advanced web-based volumetric attacks. The traditional defences described above are not capable of either detecting or withstanding these types of attacks.

Two approaches to modern DDoS protection

To withstand both these new attack methods and the enormous volumes of traffic that threat actors are able to generate, there are primarily two methods for protecting services effectively:

The first is to use “Global Server Load Balancing”, which effectively means replicating application entry points across locations around the world. The aim is for a request from the US to reach an endpoint in the US, while a request from London reaches an endpoint in London. In this way, a global attack is distributed across a large number of data centres, making the volume reaching each individual data centre manageable.

The second method is to use services designed to terminate and scrub web traffic before it reaches your own endpoints and can cause downtime.

Choosing the right DDoS protection

These two mechanisms are most commonly combined into a single service, which in turn forms part of what we today call a Content Delivery Network, or CDN. There are many providers to choose from, some more effective than others. There are significant differences in both the underlying resilience and the technology used by different CDN providers.

There are also differences in how traffic is routed from a CDN provider to an organisation's own endpoints. Again, it is important to choose services that are actually suited to your architecture and infrastructure.

Although "the simplest solution is often the best", we recommend looking beyond the solutions hyperscalers can provide within their own platforms. While these may be suitable for many organisations, there is no single right answer. Particularly in larger, distributed environments combining cloud services, private data centres and SaaS solutions, it makes sense to consider a broader range of technical solutions and a service level tailored to your needs before, during and after a potential attack.

The cost of a properly sized and effective solution, tailored to the services that need protection, will not necessarily be higher than what organisations are paying today. At the same time, few things are more expensive than continuing to pay for solutions that do not work when they are needed most...

 

Get in touch