DDoS – A Not-So-New Network Attack Method

2013-07-12 02:17:48
With the aim of supporting organizations and enterprises in Vietnam to access effective anti-DDoS solutions, in 2012, Tinh Van Group became the official distribution partner of Arbor Networks products in Vietnam. Additionally, to provide clearer information about DDoS, its impacts, and prevention solutions, with the help of Arbor Networks, from 2012 to now, Tinh Van Group has also organized seminars on DDoS and Arbor Networks' anti-DDoS solutions for several government agencies. At the same time, it has supported some units in conducting practical trials of DDoS prevention solutions using Arbor Networks equipment, with results that have been recorded.
In early July, several major online newspapers in Vietnam such as Vietnamnet.vn, Tuoitre.vn, Dantri.com.vn, Thanhnien.vn, and the news site Kenh14.vn showed signs of being attacked by Distributed Denial of Service (DDoS) attacks, making it impossible or very difficult for many people to access these sites. During the attack, the access addresses of these online newspapers and news sites experienced low access speeds, intermittent connectivity, and even complete inaccessibility.
What is DDoS?
DDoS, as defined by Arbor Networks, is a type of attack that overwhelms a target either by having too many connections or too much bandwidth directed at the target. The result makes the target impossible or very difficult to access. Other infrastructure elements (routers, switches, load balancers, etc.) can also be damaged in a DDoS attack. A variety of attack types, including connection floods, TCP SYN floods, ICMP and UDP floods, can be used in DDoS attacks. DDoS attacks often use a network of zombie computers in a botnet, and source addresses can be spoofed.
Regarding DDoS prevention methods, Senior Technology Advisor of the security firm Sophos (UK) – Carole Theriault stated that the nature of DDoS is that it cannot be controlled, only mitigated. Tightening management of databases, applications, and firewalls can help somewhat prevent many denial-of-service attacks.
When under attack, the website owner can expand bandwidth, although this is a very costly solution. In countries with developed IT infrastructure, many companies provide this service in emergencies or during peak access hours when bandwidth needs to be increased. In Vietnam today, this "not-so-new" attack method remains a nightmare for many websites with no way to recover.
Detecting and Mitigating DDoS Threats
The impact of a DDoS attack can affect and create a threat that can devastate any organization from a financial and brand perspective. A disrupted online service can cost millions of dollars and thousands of angry customers. If external threats or internal weaknesses are exploited, it can also lead to the loss of sensitive business information. All three types of incidents can cause irreparable damage to a company's brand.
Arbor Networks, Inc. is a leading provider of network security and management solutions for network service providers and enterprises of various types. Arbor Networks has extensive relationships with network service providers, with deployments in over 90% of core network providers and over 70% of network service providers worldwide, contributing to supporting and providing many security solutions and ensuring safety. Traffic monitoring through ATLAS® is a unique collaborative effort with over 230 ISPs worldwide sharing 35 Tbps of internet bandwidth. This helps Arbor customers be effectively protected on a wide scale. Arbor Networks' proven solutions help develop and protect users of network services, enterprises, and effectively protect brands.
As a leading provider of network security solutions and a major Internet research center on cybercrime trends, Arbor brings extensive experience and perspective to the big picture of complex DDoS challenges. Arbor provides comprehensive security solutions for network systems, real-time network security analysis, and provides full information intelligently, enabling customers to proactively enhance the protection of their network systems. Arbor Networks brings over ten years of experience working with the largest and most modern service providers in the world, as well as enterprises and governments. Arbor Networks focuses on developing a select few products capable of providing information for modern network security, identifying threats to detect and mitigate DDoS attacks that threaten service availability.
Arbor Networks – Security Solutions and Protection of Critical Internet Infrastructure
Arbor Pravail solutions are built on advanced network technology and intelligent security to protect against new threats and potential risks that enterprises face.
– Network bandwidth awareness: Identify risks of threats and alert with intelligent capabilities for timely alert actions. Intelligent security action: Deep visibility and intelligent processing to monitor and identify critical applications and sensitive systems. – Availability protection: Identify and mitigate DDoS attacks as well as botnets at the network perimeter.
Arbor Networks – Products and Solutions
Pravail NSI
Pravail NSI provides situational awareness for wide area networks, network visibility and intelligent security, enabling network operators to be fully aware of both new and old threats to proactively protect against attacks on their systems.
Pravail APS
Pravail Availability Protection System (APS) provides out-of-box protection against attacks. It blocks DDoS attacks at the application layer, provides dynamic threat data from ATLAS to block botnets, offers simple deployment, and the ability to send cloud signals to service providers to remotely block DDoS, ensuring comprehensive protection of system availability from threats.
Arbor Peakflow® Solutions.
As the security platform for the majority of service providers worldwide and many leading enterprises, the Arbor Peakflow platform includes Arbor Peakflow SP and Threat Management System (TMS).
Arbor Peakflow SP solutions combine network-wide anomaly detection and bandwidth monitoring techniques with Peakflow TMS for threat management, automatically detecting and removing attack traffic while maintaining legitimate traffic.
– Identify and mitigate dangerous threats such as botnets and DDoS attacks on bandwidth as well as application-layer DDoS attacks. – Enhance availability and ensure quality of service. – An appropriate investment strategy for service providers, allowing them to use Arbor solutions as an advantage to ensure availability and security, providing differentiated quality in infrastructure management to ensure service quality such as MPLS, VPN, and anti-DDoS security services.
Huy Ha
