Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - DDoS Attacks:  Know Your Enemy
Articles

DDoS Attacks:  Know Your Enemy

ISB Editorial StaffBy ISB Editorial StaffApril 20, 20164 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
DDoS Attacks
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Distributed-denial-of-service (DDoS) attacks are more frequent today than they’ve ever been, according to the latest report by Verisign.  In the final quarter of 2015, DDoS attacks globally rose by 85% compared with the previous year – and 15% on the previous quarter alone.  Not only that – they’re also getting more dangerous, deploying higher volumes of packets than ever before.

DDoS attacks aren’t just an annoyance;  they can be extremely damaging.  Offline websites and networks are non-trading websites and non-operating networks, which can lead to substantial revenue losses. And they’re a more insidious form of cyberattack than you might think; research by Kaspersky has suggested that around a third of all DDoS attacks coincide with a network intrusion, which can lead to loss of sensitive data.

Fortunately, there are some simple defensive tactics available, all of which make your network less vulnerable to DDoS disruption. These include:

  • Network segmentation. By dividing your network into discrete segments, and separating public and internal systems from each other, each protected by a separate firewall, you can maintain internal services even during a full-blown attack targeted at public systems.
  • Limiting the number of new connections being set up. By setting parameters for the number of new connections set up during a specific time period or in total from a single user or network, you can make it far harder for criminals to overload the protected systems.
  • Managing load balancing and bandwidth. Bandwidth shaping is most often used to manage legitimate traffic volumes during busy periods, for example Black Friday. However, if configured intelligently, it can also be a powerful weapon against DDoS attacks.
  • Considering the use of packet scrubbing services. Packet scrubbing reduces traffic volumes by diverting traffic via an ISP.

These are all well-established defensive measures, which many organisations may already have in place as part of your overall information security posture.  After all, network segmentation isn’t just good practice from a DDoS defense point of view; it also protects the network against damaging APT attacks, for example.  However, as DDoS attacks continue to proliferate, it’s clear that we need additional defensive measures against them.

Knowing your enemy

We’ve all heard the old adage ‘know thy enemy’ – and this is particularly relevant to DDoS attacks.  Most botnets, which are the originating point for DDoS attempts, are centered in a particular geographic location or group of IP addresses, and the majority of botnet command and control centers worldwide are actually located in a small list of countries, which includes China, Ukraine, Russia, Pakistan, and Turkey.  By establishing the locations – i.e. the unique IP addresses – from which the attacks originate, it’s possible to dramatically reduce the impact of an attack, in real time, by blocking those IP addresses.

This can be done by advanced next-generation firewalls, using a feature called geographic IP (GeoIP) blocking.  It works by generating an ongoing ‘heat map’ of where traffic arriving at the firewall or gateway originates from.  Using GeoIP, organizations’ IT and security teams can use the security gateway’s management console to get a real-time, highly visual overview of the traffic volumes hitting their network – and are able to quickly identify any unnatural traffic patterns that could signal the start of a denial-of-service attack.

If a DDoS attack is detected, the organization’s IT team can simply use the GeoIP feature to configure the security gateway to block the originating IP addresses in real time.  This way, the malicious traffic is rejected and simply bounces off the gateway, nullifying the impact of the attack and enabling the organization’s website and services to continue working, without significant interruption.

Closing your network’s borders

The great advantage of this approach is that it is flexible,  enabling organizations to dynamically respond to what is actually happening on their networks.  GeoIP can also be used pre-emptively, as there are huge numbers of websites and domains that shouldn’t be connected to, because they are known to host or control botnets, or distribute malware.  These IP addresses can be blocked in the gateway, to reduce exposure to potential attacks.

There are also countries or geographic regions globally where your organisation does not currently do business – and so it’s likely that traffic from hosts in these regions may be suspicious.  For example, if an organization that has no trading relationships in North Korea suddenly receives volumes of traffic originating from the country, it’s likely to be malicious activity.  So IP addresses from this and similar countries can be blocked, using GeoIP capability to act as a ‘border control,’ stopping undesirable traffic from reaching networks.

So when it comes to defending against DDoS attacks, establishing where the attack is being launched from is critical to being able to defend against it.  When you know this about your enemy, you can stop an attack in its tracks.

ISB Editorial Staff
  • ISB Editorial Staff
    Navigating the Cyber Threat Landscape: Key Insights from Trellix ARC’s Q1 2023 Report
  • ISB Editorial Staff
    Experts’ Responses: Cyber Security Predictions 2022
  • ISB Editorial Staff
    ISB Virtual Conference: Key Cyber Security Challenges and Solutions in 2021
  • ISB Editorial Staff
    Cyber Security Predictions 2021: Experts’ Responses

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}