Follow Us

We use cookies to provide you with a better experience. If you continue to use this site, we'll assume you're happy with this. Alternatively, click here to find out how to manage these cookies

hide cookie message

Data centres now 'magnets' for DDoS attacks, says Arbor report

Bigger, badder but also sneakier

Article comments

Data centres have become “magnets” for DDoS attacks with many recording a marked rise in incidents during 2013, Arbor Networks’ latest Worldwide Infrastructure Security Report has found.

During the year, the number of data centres experiencing DDoS attacks rose to 70 percent from less than half in 2012, the firm discovered from a customer survey backed up by trend data from its own Atlas global monitoring system.

Importantly, 26 percent said that DDoS attacks had exceeded the total data centre bandwidth, around double the number experiencing the same in the previous year.  Ten percent had seen more than 100 attacks per month.

Standing back a bit and this shift to focus on data centres appears to be part of a trend to attack customers indirectly by attempting to overload their service providers.  Eighty-three percent of data centre operators said they could see attacks up to layer 3 or 4 with only 23 percent able to see as far as layer 7.

As an aside, Arbor also noticed a tendency to rely on firewalls (56 percent) and IDS/IPS systems (42 percent) to battle DDoS attacks, probably by closing ports or filtering certain types of traffic. This s a drastic response although it might work on some occasions; it also stops useful applications from working at all, in effect killing service.

But DDoS mitigation firms have a vested interest in drawing attention to these limitations because they can be one way of getting around the need to use more sophisticated services.

It was less of a surprise that DDoS attacks sizes reached new peaks during 2013, including the notorious Spamhaus reflection attack that peaked at 309Gbps. Attacks above 100Gbps are now well documented, Arbor said, including those targeting specific parts of Internet infrastructure such as the open DNS servers that turned Spamhaus into a household name.

It is curious that amplification/reflection attacks should have continued to rise despite what happened to Spamhaus. “People became aware that there is a lot of infrastructure out there to do this. Spamhaus gave them the knowledge,” suggested Arbor EMEA solutions architect, Darren Anstee. SSL was another infrastructure target, he said.

“From the ISP to the enterprise, IT and security teams are facing a dynamic threat landscape and very skilled and patient adversaries,” said Arbor president, Matthew Moynahan. “There is no single, magic bullet solution and it is a mistake to think technology alone can secure a network. Multi-layered defenses are clearly needed, but so is a commitment to best practices for people and process.”

Disappointingly, Arbor devotes almost no space to the nature of the motivations behind DDoS. These will include low-level criminal enterprises and extortion through political activism. The larger unknown is the extent to which nation states are now conducting DDoS attacks as part of economic and political war. Thus far, vendors seem determined not to be drawn into speculating on this theme.



Share:

More from Techworld

More relevant IT news

Comments



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Choose – and Choose Wisely – the Right MSP for Your SMB

End users need a technology partner that provides transparency, enables productivity, delivers...

Download Whitepaper

10 Effective Habits of Indispensable IT Departments

It’s no secret that responsibilities are growing while budgets continue to shrink. Download this...

Download Whitepaper

Gartner Magic Quadrant for Enterprise Information Archiving

Enterprise information archiving is contributing to organisational needs for e-discovery and...

Download Whitepaper

Advancing the state of virtualised backups

Dell Software’s vRanger is a veteran of the virtualisation specific backup market. It was the...

Download Whitepaper

Techworld UK - Technology - Business

Innovation, productivity, agility and profit

Watch this on demand webinar which explores IT innovation, managed print services and business agility.

Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

From Wow to How : Making mobile and cloud work for you

On demand Biztech Briefing - Learn how to effectively deliver mobile work styles and cloud services together.

Watch now...

Site Map

* *