|
| |||
|
|
Fend Off Collateral Damage of DDoS Attacks Jeffrey Lyon, CISSP-ISSMP, founder of Black Lotus Communications, a DDoS mitigation firm specializing in the defense of service providers and enterprises.. JEFFREY LYONBlack Lotus Communications Distributed denial of service (DDoS) attacks are increasing in scope and frequency, and companies in high-risk industries face numerous challenges when it comes to defending themselves. While DDoS attackers don’t generally target data centers directly, that hasn’t spared them from DDoS-related problems. In a recent report, the Ponemon Institute found that DDoS accounted for about 18 percent of data center outages, up from two percent in 2010. As these attacks generate larger and larger amounts of traffic, data centers are finding it harder to recover from spillover repercussions. To preserve uptime regardless of DDoS activity, data centers should follow these guidelines: Learn the risks and prepare for them. Teach your users to ignore attacker inquiries. Protect your networks. Additionally, the primary reason why firewalls are not sufficient to stop DDoS attacks is that they were not intended for this purpose. Although some brands and models say they will offer DDoS protection, the primary concern is that the devices are stateful (they “maintain state”), which in layman’s terms mean that they track every connection that travels through the device, limiting the amount of traffic that can be realistically handled. DDoS mitigation equipment is a special category of firewall generically referred to as a packet filter. It’s important to note that traditional firewalls or stateful firewalls are the ones that are not effective. Protecting your networks also means upgrading to modern equipment. Your service contracts should be up-to-date, and any new products you purchase should have a track record of withstanding prolonged attacks. However, even if you take these precautions, it’s possible that your data center could feel the effects of a DDoS attack. That’s why contingency planning is so important. Approach your network protection holistically, with secure network and system architecture, onsite packet filters, skilled security staff, and additional mitigation capacity that can help you during a worst-case scenario. The Ponemon Institute found that some data centers aren’t at all ready for the potential impact of DDoS outages, which can cost many hundreds of thousands of dollars to mitigate. Beyond the cost of emergency mitigation, unplanned downtime represents an untenable expense for data centers. When staying operational is at the core of your value proposition, it’s essential to follow best practices to avoid DDoS-created outages. Industry Perspectives is a content channel at Data Center Knowledge highlighting thought leadership in the data center arena. See our guidelines and submission process for information on participating. View previously published Industry Perspectives in our Knowledge Library. |
|||||||||||||