Oh great, even DDoS DNS attacks come with hidden costs now


This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.


It’s hopefully not a revelation to anyone that DDoS attacks typically come with devastating financial losses. The service disruptions alone are estimated to cost upwards of £325,000 per attack, but these outages aren’t the only financial impact that DDoS-favouring threat actors can inflict. A lesser-known but equally damaging method is the targeting of Domain Name Systems (DNS). These attacks can cause as much damage as the next when it comes to downtime, and they come hand-in-hand with hidden costs for victims.

Whose domain even is this?

DNS services are one of the foundational blocks of the internet, though they can often go unnoticed. Sometimes referred to as the ‘internet phonebook’, they translate domain names as a human might see them (think www.) into machine-readable IP addresses (like 123.4.5.67). This translation request (a DNS query) is triggered each and every time someone visits a website. Unlike most other systems, DNS responds to every incoming query it receives, without validating the legitimacy of requests. While that’s conducive to smoother internet operations, it’s also a glaring weak spot for threat actors to exploit.

DNS servers also have another, hidden vulnerability that can be manipulated to cause even more financial harm. This vulnerability isn’t where you would assume it to be. Enterprise-grade DNS hosting systems are built to handle vast numbers of requests, so while a DDoS attack targeting them can cause disruptive downtime, the associated costs are all out in the open already. This secret weak spot lies instead with the billing model commonly used for DNS services. Most providers charge their customers based on the total number of DNS requests received during each billing cycle. And in ‘normal’ or ‘day-to-day’ operations, it’s a reasonable and logical set-up that benefits the customer – they only pay for what they use. But, if a threat actor exploits this and floods your DNS system with requests, these monthly bills could soon skyrocket.

Money on the mind

Of course, these astronomical costs are exactly what threat actors are counting on to exacerbate the effects of downtime. In DNS-targeted DDoS attacks, the servers are overwhelmed with mountains of malicious requests. Despite being illegitimate, these are processed exactly the same as legitimate requests. As such, they contribute to the running total of DNS queries used to calculate the month’s bill.

You’d be forgiven for thinking that a DNS request isn’t very costly, and you’d usually be right. The popular pay-as-you-go billing method means that most of the time, customers are charged fairly for the resources they use in a month. However, most of these payment plans are based on a tiered system. So as soon as requests go over the pre-agreed limit, organizations are liable for overage fees – on top of the bigger bills. When organizations are already dealing with the chaos caused by outages, a vastly inflated bill is the last thing anyone wants to see.

Out of the shadows, into the light, and under protection

Thankfully, these DNS-targeting DDoS attacks are far from impossible to prevent. The main issue isn’t prevention methods, but awareness of the vulnerability in the first place. DNS servers are easily overlooked when it comes to DDoS protection but once organizations are aware, they can take action.

With DNS, it starts with the basics. For the many organizations currently operating without any protection at all, implementing DNS protection services is an essential first step. These should include rate-limiting and filtering functions to screen incoming requests for malicious traffic and block it before it reaches the DNS server, which will prevent false requests from driving up costs. Another route is to consider moving to a DNS provider that offers flat-rate pricing. While this approach doesn’t bring any protection, it does mitigate additional financial damages from DNS DDoS attacks and could reduce incentives for threat actors to carry them out.

Whatever method you choose, it’s imperative that organizations bring the vulnerabilities of DNS servers into the light and address them. During a DDoS attack, the immediate focus is naturally on restoring availability and minimizing downtime, but these additional DNS costs can deliver a sucker punch to already-impacted wallets after an incident. DNS protection can’t fall by the wayside anymore. Organizations need to prioritize it instead of underestimating the financial impact it can have. Taking action now to safeguard both your services and your finances will be worth it.

Some great stories you might’ve missed

Donny Chong
Donny Chong

Donny Chong is a Product & Marketing Director at Nexusguard, where he's responsible for designing the company’s solutions for the enterprise segment. He has contributed to TechFinitive under the Opinions section.