Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - How to Protect your Business from a DDoS Attack
Articles

How to Protect your Business from a DDoS Attack

ISBuzz TeamBy ISBuzz TeamOctober 14, 20154 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Protect your Business from a DDoS Attack
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Successful attempts by hackers like Lizard Squad to take down major websites have become so common that barely a week goes by without another victim.  Recently, the Thai Government, Reddit and the National Crime Agency’s have been targeted by Distributed Denial of Service (DDoS) attacks.

The number and intensity of DDoS attack are rising in 2015. For businesses reliant on their websites this is an alarming trend. But it is not a surprising one given that web application security is often poorly understood and incorrectly deployed.

A DDoS attack can take different forms, but essentially it involves a website’s servers being hit by a large number of‘requests’which disable or significantly reduce the performance of the website. To co-ordinate and deploy sufficient requests, an attacker will have access to an army of compromised systems, made up of the systems of ‘normal’internet users infected with malware. A recent and concerning development is the availability of DDoS armies for hire by the hour.

Law enforcement agencies have not had much success fighting this growing area of cybercrime.  DDoS attackers commonly use‘bulletproof hosting’for their own control servers that command their DDoS attack army. Such services often operate from countries that provide immunity against western law enforcement.

Businesses therefore need to make sure they are taking appropriate steps to protect their websites from a DDoS attack. For most, this will mean buying in a security solution and there are some common pitfalls that can be easily avoided.

Many businesses make the most fundamental mistake of all: attempting to secure their web applications with the wrong technology. A network firewall can protect Layer 4 protocols and even do deep packet inspection. But truly protecting against web application layer attacks generally requires terminating the HTTP or HTTPS protocols and often rewriting traffic to identify and mitigate threats.  Just as a network firewall is not designed to stop spam, it is also not designed to stop web application attacks. This type of misunderstanding leaves the web application exposed, and gives the administrator a false sense of security. A web application firewall is much better suited to combatting DDoS attacks.

Key to any DDoS protection is the ability distinguish real users from malicious requests so that suspicious traffic can be blocked or challenged. But this is not easily done. One effective screening method is integrated IP reputation intelligence that contains real-time insight and historical intelligence. Be warned though that this only works if the reputation criteria are updated frequently enough to combat against new and emerging threats.

It’s also worth considering some form of dynamic client fingerprinting as part of any DDoS solution. Mechanisms that can detect suspicious clients using script injections and challenge suspected malicious requests with a CAPTCHA test can be a lifesaver when a DDoS army is very distributed, stays below the rate control radar, and its user systems have not been blacklisted.

One final consideration is whether to hold DDoS protection in the cloud or on-premises. Typically, cloud-based services work by redirecting all the incoming traffic first to the cloud via DNS manipulation, scrubbing the traffic, and then relaying it to the destination server. Such solutions promise easy setup and low maintenance. However, it is worth bearing in mind that persistent attackers can also bypass the cloud layer and target your servers directly, so an on-premises solution can be indispensable.

While we are going to see more high-profile DDoS casualties over the course of the year, I am predicting a far stronger response from administrators as they fight to build in effective security around their web applications. The first and simplest action to be taken here is to use the right tool for the job. A network firewall will leave web applications exposed so be sure to opt for a web application firewall to combat DDoS.  Also look for a DDoS solution that uses IP reputation intelligence, but make sure its reputation criteria is frequently updated to avoid becoming obsolete. And for that extra layer of confidence and security, consider fingerprinting and robot testing.[su_box title=”Wieland Alge, VP and GM, EMEA at Barracuda Networks” style=”noise” box_color=”#336588″]Wieland AlgeWieland Alge is a vice president and general manager at Barracuda, It provides cloud-connected security and storage solutions that simplify IT. These powerful, easy-to-use and affordable solutions are trusted by more than 150,000 organisations worldwide and are delivered in appliance, virtual appliance, cloud and hybrid deployments. Barracuda’s customer-centric business model focuses on delivering high-value, subscription-based IT solutions that provide end-to-end network and data security.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

AppSec is dead, long live AI security

April 29, 20265 Mins Read

Managing App Access on Frontline Devices in an Always-On World

March 9, 20264 Mins Read

OWASP Top 10 2025: New Enemies, Old Foes, and an Approach to Vulnerability Remediation That Must Evolve

January 22, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}