Itโs all too easy to think of cybersecurity in terms of defending against headline-generating risks: ransomware, zero-day vulnerabilities, credential-stealing malware and socially-engineered hack attacks.
But, in my best Morpheus from the Matrix voice, what if I were to tell you that one of the oldest threats to your organisation remains as active as ever? That it has evolved to incredible new heights and can cost you dearly in terms of both reputation and bottom line? What could this attack on security steroids possibly be?
The answer: distributed denial of service. DDoS to its frenemies. The good news is that law enforcement has just had significant success in taking down some of the platforms that rent the attack itself out to anyone for any reason.
Attacks on DDoS
The latest Group-IB intelligence insights report confirmed my suspicions that DDoS should be higher on the cyber-defender priority schedule.
Ransomware incidents were down 4%, initial access credentials broker sales down 20% and DDoS attacks up by a whacking 88%. That’s almost double, people.
And the threat is evolving, as evidenced by a Windows denial of service vulnerability for which Microsoft doesnโt yet have a fix.
Zhiniang Peng, an Associate Professor at Huazhong University of Science and Technology, discovered the denial-of-service attack exploiting a vulnerability patternโโ in User Datagram Protocol remote services that are employing Windows Deployment Services.
But the biggest danger is from the ready-made, ready-to-roll, attacks-as-a-service platforms that literally rent out DDoS by the hour.
DDoS attacks for hire
Europol has confirmed that is has arrested four people thought to be behind the operation of such DDoS for hire platforms. โThe suspects are believed to be behind six separate stresser/booter services that enabled paying customers to flood websites and servers with malicious traffic – knocking them offline for as little as EUR 10,โ Europol said in a statement.
The law enforcement takedown resulted from a global investigation, with action in four countries (including the US) where nine domains associated with the platforms were seized.
Itโs vital to note here that the platforms in question didnโt require any technical ability other than being able to fill in a form. Yes, really. An attacker simply needed to enter the target IP address, select the duration of the attack, and pay the fee. Thatโs it.
Europol said that the resulting fully automated attacks could โoverwhelm even well-defended websites.โ
The good news is that this is just part of the global Operation PowerOFF action being taken against DDoS for hire platforms; further arrests and takedowns can be expected. In the meantime, organisations are advised to take mitigating action now.
How to protect yourself from DDoS attacks now
โThere are several protections companies can implement, many of which they should already have in place,โ said Randolph Barr, CISO at Cequence Security.
โCloud-based solutions from providers like AWS and Google Cloud offer tools to help mitigate these attacks. Additionally, AI/ML-powered solutions can detect abnormal traffic patterns and differentiate between bots and real users.”
He added: “Rate limiting is another mitigation method, but it has its limits when dealing with large traffic volumes.โ
The key takeaway, according to Barr, is that DDoS is becoming increasingly sophisticated.
โBad actors are refining their strategies, targeting not only network infrastructures but also application layers and, most critically, APIs.”
Donโt say you havenโt been warned.
Related DDoS attack articles