Reduce Vulnerabilities & Defend Your Brand Against DDoS Attacks

Distributed denial-of-service (DDoS) attacks are on the rise and the repercussions can be detrimental to businesses. Gartner has estimated the cost of downtime from DDoS attacks to be $300,000 per hour and a successful application attack costs, on average, $4.42 million per incident.

Yet, beyond the financial impact - a customer’s trust in a brand is truly what’s at stake with these cyber attacks. In fact, 31% of consumers have discontinued their relationship with a company due to a security breach and a significant number of consumers have lost their trust in a brand as a result.  

DDoS attacks only seem to be growing. As recently as September 2022, the Japanese government was targeted by an organised cyber criminal group called Killnet. Killnet planned a sustained DDoS attack that eventually overcame the government’s cyber defenses. Yet, the Japanese government was protected by one of the most recognised names in web security. Then, earlier this month, on U.S. soil, Killnet perpetrated a DDoS attack targeting major airports, including Los Angeles International and Chicago O'Hare, among others.

The modus operandi of the Killnet attacks is to employ a variety of DDoS techniques, including combining application attacks with volumetric network attacks. It deploys these in waves of attack that also target a company’s origin.

As online attacks increase in size, frequency and sophistication, businesses need to seek holistic security solutions to help detect and streamline resolution. 

Attacks On The Rise

DDoS attacks are here to stay. In fact, according to the 2022 Verizon DBIR (Data Breach Investigations Report), the number one security threat is a DDoS attack (46% of attacks) - and it’s growing every year. The number one targets are web applications and servers (56% of attacks), with DBIR highlighting web apps that remain unpatched and legacy apps that are older than four years as being the most affected.

Where Do Vulnerabilities Lie?

Companies remain vulnerable because they don’t protect all of their network against DDoS attacks. As attacks target both the network and application layers, organisations must protect against several attack vectors.

According to the Verizon DBIR, the second leading breach pattern is a basic web application attack, so businesses will also benefit from a Website Application Firewall (WAF)  solution. Once you deploy a WAF, your defenses improve significantly. Research by Edgio has found that that businesses can detect and contain a breach 77 days faster, on average.

As network architectures have evolved, so have DDoS attacks, exposing websites and networks to vulnerabilities, including the critical applications and processes dependent on those networks.

One vital part of an IT network that needs protection - and gets overlooked - is your origin. The origin server is where the original web page is stored. One job of a content delivery network (CDN) is to store, or cache, copies of the web pages on its edge servers that are located a short distance from the web app user. Global edge servers enable businesses to deliver lightning-fast performance to website and app users. The CDN hides the origin IP address, but devious cyber criminals, like Killnet, find and attack this chink in the armour. Deploying robust application security and DDoS scrubbing solutions are recommended to protect and mitigate against direct-to-origin DDoS attacks. DDoS scrubbing identifies bad traffic and redirects it away from critical systems.

This combination of defenses provides businesses with a full spectrum, holistic cyber security strategy and means attacks never reach their infrastructure, applications, and internet-facing websites.

How To Defend Against DDoS Attacks

Even though the threat landscape continues to evolve, there are still several steps you can do to protect your business and brand from DDoS attacks. Organisations should adopt a scalable, holistic security platform and protect their network, applications and origin using an edge-based DDoS protection solution. Direct-to-origin attacks can be defended against using a DDoS scrubbing solution and a security operations centre can improve business security responsiveness. 

It’s impossible to eliminate the risk of attacks, but there are practical steps business leaders can implement to protect and secure their organisation, before it’s too late.

Paul McNamara is Senior Solutions Engineer at Edgio

You Might Also Read: 

You Should Prepare Your Organization For A DDoS Attack:

 

« Cyber Threats & Nuclear Fears
What Security Issues Do 5G Network Providers Need To Address? »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

DigitalStakeout

DigitalStakeout

DigitalStakeout enables cyber security professionals to reduce cyber risk to their organization with proactive security solutions, providing immediate improvement in security posture and ROI.

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

IAC

IAC

IAC is a specialist Irecruitment consultancy covering Internal Audit, Risk, Controls, Governance, IT Audit, and Cyber Security roles.

PBOSecure

PBOSecure

PBOSecure is a dynamic and progressive IT consultancy company specializing in IT and Industrial Control System (ICS) security.

Morphus Information Security

Morphus Information Security

Morphus is an information security company providing Red Team, Blue Team and GRC services as well as conducting research in cybersecurity and threat analysis.

AUREA Technology

AUREA Technology

The photon counter SPD_OEM_NIR from AUREA Technology is designed for quantum key distribution at telecom wavelengths.

Etonwood

Etonwood

Etonwood specialises in infrastructure and vendor technology recruitment in areas including cloud platforms, cyber security and service management.

Sikich

Sikich

Sikich LLP is a leading professional services firm specializing in accounting, advisory, technology and managed services.

Trellix

Trellix

Trellix is an extended detection and response (XDR) solutions provider created from a merger of McAfee Enterprise and FireEye Products.

Inversion6

Inversion6

Inversion6 (formerly MRK Technologies) is a cybersecurity risk management provider that offers custom security solutions.

DEKRA

DEKRA

DEKRA’s promise is to ensure the safety of human interaction with technology and the environment.

WireGuard

WireGuard

WireGuard is a communication protocol and free and open-source software that implements encrypted virtual private networks (VPNs).

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

DigitalXForce

DigitalXForce

DigitalXForce is the Digital Trust Platform for the New Era – SaaS based solution that provides Automated, Continuous, Real Time Security & Privacy Risk Management.

Backblaze

Backblaze

The Backblaze Storage Cloud provides a foundation for businesses, developers, IT professionals, and individuals to build applications, host content, manage media, back up and archive data, and more.

Nuke From Orbit

Nuke From Orbit

Nuke's mission is to put you back in control of your digital identity when your smartphone gets stolen.

runZero

runZero

runZero delivers the most complete security visibility possible, providing you the ultimate foundation for successfully managing exposures and compliance.

Secure Domains

Secure Domains

Secure Domains is the first company in the GCC to offer cloud-based DNS firewall services and security through its flagship SaaS product, DNS Armor.