Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Defending Your Business From The Changing DDoS Attack Landscape
Articles

Defending Your Business From The Changing DDoS Attack Landscape

Samir DesaiBy Samir DesaiMarch 22, 2021Updated:August 5, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
UK Websites Suffer 21% Increase in DDoS Attacks in Q4 2015
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Cyber-crimes are changing and businesses need to understand how to protect themselves from falling victim to online attacks. Cyber-criminals are operating on an increasingly sophisticated level. One trend that particularly stands out is the rise in larger size Distributed Denial of Service (DDoS) attacks.

For example, in mid-February 2020, AWS reported its largest DDoS attack ever, where its security service mitigated a 2.3 Tbps attack. Across all industries, DDoS attacks ranging in size from 10 to 100 Gbps increased by 50% in 2020.

While there are many high-profile cyber-attacks such as the AWS case, there are also many attacks that go unnoticed or unreported. Businesses that may see these ‘tip of the iceberg’ attacks, also need to be aware of what sits beneath the surface. The growing issue lies with the daily, low-level metric attacks that are impacting businesses. According to industry estimates, 95% of all attacks can be categorised as being sub-5 Gbps. The consequential impact of these attacks is internet access being blocked, as well as server and network resources being inaccessible.

In today’s highly competitive digital business environment, downtime or latency can be more devastating to a business than previously considered. Therefore, businesses need to ensure they are equipped with a strong defence strategy to mitigate any incoming attacks.

The evolution of DDoS attacks

Businesses first need to understand what they’re up against. DDoS attacks have been around for nearly as long as the internet. However, just as the internet has evolved, so has the attack landscape.

Industry estimates further indicate that multi-vector DDoS attacks continue to increase. Traditionally, criminals would use one direct method of attack, but now, multi-vector attacks are performed in quick succession in an attempt to evade protection measures. DDoS activity is also known for its pervasiveness, short duration and repetitive attacks.

With rising levels of DDoS activity, attacks can be impossible to mitigate without early threat detection and automated traffic profiling systems. It’s not uncommon for businesses to realise they’ve been attacked once a website application slows to a halt or crashes. This is especially true for sophisticated attacks, which use a blended approach and simultaneously target multiple layers of the Open Systems Interconnection (OSI) model.

DDoS attacks target databases, applications, and infrastructure simultaneously to increase their chances of success. To protect against these attacks, businesses need a strategy, as well as a reliable DDoS prevention and mitigation solution. IT security buyers need to invest in an integrated security strategy that protects all infrastructure across multiple layers.

Implementing the right defence strategies

Businesses need to develop a DDoS defence plan based on a thorough security assessment. When a DDoS attack strikes, there is no time to think about the best steps to take. The plan needs to be defined in advance, to enable prompt reactions and avoid any negative impacts.

Some key elements of an effective plan include organising a response team, defining notification and escalation procedures, and including a list of internal and external contacts who will need to be informed when an attack is taking place. Additionally, a list of assets, such as web servers, network elements, or applications directly connecting to the internet with corresponding public IP addresses, should be defined and protected in the event of an attack.

Implementing multiple protection strategies in parallel will also mitigate network security threats. These include next-generation security features, such as advanced intrusion prevention and threat response systems, which combine firewalls, VPN, anti-spam, content filtering, and network security with DDoS mitigation solutions. Together, these next-generation security features enable constant and consistent network protection to manage a DDoS attack.

Focusing on a secure network architecture is vital to security too. Businesses should create redundant network resources, where if one server is attacked, the others can handle the extra network traffic. When possible, servers should be located in different places geographically since dispersed resources are more difficult for attackers to target.

Finding the right partner

Businesses should also consider outsourcing DDoS prevention to internet service providers (ISPs) with cloud-based DDoS mitigation services, as this offers several advantages. Seek out providers offering “always-on” solutions, as these can absorb huge volumes of malicious traffic, with minimal latency impact, before it reaches its intended destination. Where enterprises need to augment their always-on solutions with some control over how and when mitigation can be applied, ISPs that offer customer-initiated traffic redirect capabilities in an automated fashion have a significant advantage. In addition, DDoS solution services provided through an integrated Tier 1 Internet Service Provider benefit from threat intelligence capabilities that constantly monitor the larger internet for the latest DDoS tactics and emerging attack trends.

DDoS attacks will likely continue to form a significant part of the enterprise security threat landscape. Traditional security measures will not be able to hold up against the advancing level of sophistication of these DDoS attacks. In order for businesses to keep up, they’ll need to be well prepared and implement consistent measures to protect against such attacks. Only then will businesses be less exposed to the costly repercussions of a DDoS attack.

Samir Desai

Samir Desai is GTT’s vice president of managed and security services. He has over 20 years of experience in telecoms product concept development, specifically in fixed, wireless managed data and information security segments. Samir oversees GTT’s global portfolio of innovative solutions delivering a comprehensive SASE experience to his customers. Products under his remit include Secure SD-WAN, Network & Cloud Security, Managed Detection & Response and Managed Network Services.

  • Samir Desai
    Is SASE The Solution To Modern Cyber Threats?

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}