Categories
DDos Attack: What It Is And What To Do To Prevent It
Interesting fact: the first successful DoS attack occurred in 1974, when a teenager named David Dennis caused terminals at the University of Illinois Computer Computing Laboratory to malfunction. He wrote a programme that sent an EXT command to all available devices, causing 31 terminals to hang.
However, the schoolboy used only one computer to pull off his plan. In 1999, someone came up with the idea of combining 114 computers to attack the University of Minnesota. The technique was quickly adopted by others, and now we have DDoS attacks as they are. DDoS stands for Distributed Denial-of-Service, while DoS is simply Denial-of-Service.
That is, if your server suddenly received a huge number of requests and they are repeated VERY often, because of which the server stopped responding, then we can talk about a DDoS attack. It's like if all the grandmothers of a town decided to call at the same time and get through to the only clinic in town.
Now seriously. To launch a DDoS attack, attackers use Internet-connected devices. Often these are Internet of Things devices that have been infected with malware and are now under the hacker's control. This is how botnets are created. They usually have not 2 or 3 devices, but thousands or even millions. When such an army simultaneously sends a request to the victim's IP address, the victim cannot withstand such pressure and stops functioning.
When a server stops working or works very slowly, the company loses customers. This is why competitors often resort to DDoS attacks. They order an attack on their competitors, and while they are trying to deal with the consequences of the attack, they gain customers and, consequently, profit.
At the end of March 2021, StormWall experts reported that the number of DDoS attacks in 2021 will increase by 20% compared to last year. They attribute this to the fact that many people now work and study remotely, which increases the number of novice hackers among students and schoolchildren. And the fact that many people work remotely increases the criticality of Internet services.
Experts also say that the development of 5G networks may provoke an increase in the number of denial of service attacks, as such an attack can be performed even from a mobile device.
Types of DDoS attacks
Let's look at the main types of DDoS attacks.
-
Network level attacks (L3/L4) – use a huge number of packets to overload bandwidth or server resources. These include SYN Flood, UDP Flood and ICMP Flood.
-
Application layer attacks (L7) – mimic the behaviour of normal users, making them harder to detect. For example, HTTP Flood attacks can overwhelm a web server by sending hundreds of thousands of requests.
-
Amplification Attacks. Exploit vulnerabilities in open services to amplify malicious traffic. These include DNS Amplification, NTP Amplification, Memcached Amplification.
-
Botnet attacks use a network of infected devices (botnet) to generate traffic en masse.
Examples of famous DDoS attacks
In 2016, the Mirai botnet attacked ISPs and major services such as Twitter, Netflix and Reddit using infected IoT devices.
In 2018, GitHub suffered one of the largest DDoS attacks in history with peak traffic of 1.3 Tbps.
In 2020, Google reported a 2.54 Tbps DDoS attack that targeted one of its customers.
It doesn't matter which method you choose. The important thing is to take steps to minimise the impact of the attack. The analytical department of Scinero Software Limited tells you what is the minimum you can do to prevent a DDoS attack from achieving its goals.
How to prevent a DDoS attack?
Expand the bandwidth of the channel
The easiest thing you can do to increase your resilience to DDoS attacks is to make sure your virtual dedicated server has enough bandwidth to handle the surge in traffic.
Create a distributed infrastructure
Create a load balancing system to distribute traffic to multiple servers. This will make it harder for a hacker to reach their target. If possible, have data centres in different countries. If an attack happens, the attacker will only be able to take out a portion of your servers. The rest will still be functioning. Therefore, the damage to your business will be less.
Set special settings
Properly configured firewalls and firewalls can recognise and block attacks. For example, if an attack attempt is detected, they will stop receiving ICMP packets or block responses from a DNS server outside the company network.
Protection by DNS provider
You can entrust infrastructure protection to your DNS provider. They should have the necessary knowledge and capabilities to provide protection against DDoS attacks. However, it is better to discuss this with them separately.
Use cloud-based solutions
Cloud services such as Cloudflare, AWS Shield, Akamai and Imperva can effectively filter malicious traffic, reducing the risk of a successful attack.
Monitor traffic in real time
Tracking anomalous bursts of activity will allow you to react quickly to potential threats and take protective measures in advance.
Perform network segmentation
Dividing the network into isolated segments minimises the impact of a DDoS attack by limiting the affected area.
Use advanced AI technologies for defence
Security vendors offer special tools against DDoS attacks that use artificial intelligence. They analyse incoming traffic and automatically block suspicious requests.
Make a plan of action in case an attack has already happened
Companies should think about where attackers might strike and put a response plan in place to mitigate the impact of attacks. Some organisations employ a team of specialists who know how to act in the event of an incident.
It is important to take measures, both preventative and counter-attack, to minimise the likelihood of intrusion and negative consequences for the company.

















