Intellics

DDoS Attacks Abstract and Real (I)

Academic Introduction

From the OWASP perspective DoS attacks are classified as OAT-015 Denial of Service. From the perspective of the information system owner, this is a state of the system, when real users can't connect to it, because system 100% of the time processing requests of malicious users.

Information system like any complex application has multiple chained components. But abstractly this is some ingress Internet channel, connected to various types of balancing solutions, and frontend servers returning responses to users. DoS attacks (despite classification) can be not fully automated. If for example backend servers have vulnerabilities or specifically heavy requests, attackers can consume all backend resources by certain requests from the browser, made manually.

On another side, we have DDoS attacks, when rather simple requests, or request sequences, can be delivered from thousands of hosts on the Internet distributed across the globe. These attacks are usually fully automated and aimed to fully consume the internet channels available for service.

Mitigation Measures

What is the difference between targeted, non-automated DoS attacks, and massive DDoS attacks?

Massive DDoS attacks are performed by IoT devices, home routers, and other semi-embedded systems. Malicious software running on such devices can't produce complicated sequences of HTTP requests and handle user sessions. Unfortunately, these devices can produce a gigantic amount of ingress traffic (up to millions of requests per second, and thousands of gigabits per second).

How bad it is? Many companies of "enterprise" level, can rent internet channels with throughput ~100Gbps. And massive modern botnets can easily consume entire channel capacity. Only a few companies have enough resources to process such an amount of malicious traffic (e.g. Google, Amazon, etc.) For others "to be targeted" by such botnet is equal to "lost access to the website". Basically without huge investments into network architecture and equipment, it's impossible to challenge botnet owners. There are companies, who let you process such volumes of traffic through their networks to "scrub" it. These are well-known giants such as Akamai, Cloudflare, and technology companies like Qrator Labs.

In the next post, we will discuss the complexity of traffic "scrubbing" and different methods offered on market.