Skip to main content

The Anatomy of DDoS Attacks: Download E-Book

Page 1

The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats AN E-BOOK BY ADAPTURE

2

ADAPTURE /// The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats


Contents

4

6

What is a DDoS and What Does It Do?

10

How Does a DDoS Work?

12

DDoS Detection

16

DDoS Mitigation Steps

22

Response Time Implications and Regulations

26

You’ve Stopped the Threat...For Now

28

How Can ADAPTURE Set You Up to Weather an Attack?

ADAPTURE /// The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats


Is your marketing team excited about all the new traffic that’s been hitting your site recently? You have a solid crew in the marketing department, so perhaps this doesn’t surprise you. You attribute it to the new marketing campaign that kicked off last month or just the natural fluctuations in social media engagement. But what if the answer was more sinister? Don’t misunderstand us. Your marketing team is just as stellar as they were before, but it’s important to remember that, as digital technology advances, cybercriminals simply become smarter and more cunning. That extra traffic may not be entirely legitimate.


What is a DDoS and What Does It Do?

When mainstream code exploits and data infiltrations fail, some hackers resort to a different form of cyberattack. DDoS attacks are often deployed by individual hackers, organized crime rings, and select government agencies who are looking to cause critical network disruptions and generic operational chaos (or even to cause further internal complications, but more on that later). A DDoS, or distributed denial of service, is a geographically spread form of cyberattack that targets a selected service (server, website, or other network resource) with the goal of rendering that service unresponsive. One avenue of attack is to use the aggregate force of compromised devices, or botnets1, to send increasing amounts of legitimate-looking “traffic” to overwhelm a company’s internet accessible resources. Consequently, when legitimate users attempt to access the site, product, or service, they are thwarted by slowed response times, no available resources, limited or no site access, or an HTTP “503 Service Unavailable” status code. The server or service becomes so bogged down with illegitimate traffic, it is unable to respond to the genuine requests, thus the “denial of service.”

1

6

ROUSE, MARGARET (2017). “BOTNET.” TECHTARGET.

ADAPTURE /// The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats


What is a DDoS and What Does It Do?

The IoT Gateway The most recent area of growth for DDoS attack potential is the Internet of Things (IoT). While IoT devices are arguably beneficial for human health, safety, and convenience, the cybersecurity side of the story is rather grim, making it one of the most important security priorities to date in the industry. According to the IDC, the IoT will have achieved critical mass by 2020, connecting the enormous intelligence of the cloud to billions of mobile devices—30 billion to be exact. Remember that a device doesn’t have to be Wi-Fi enabled to be IoT connected; Bluetooth-only devices are also vulnerable to hacking. This rising tide of not-so-protected mobile and wearable technology collectively acts as a gateway for increased cybercrime. But the prevalence of IoT devices isn’t all bad. While IoT device security often leaves something to be desired, the vulnerabilities caused by this global connected device network has increased the intensity and approach of security conversations. The result has been the development of a new spectrum of technologies that identify and defend against these vulnerable endpoints.

8

ADAPTURE /// The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats


The reason IoT has become this new attack vector is due in large part to the architecture of IoT devices. Most IoT devices have full memory and processing power but minimal management access. Some devices are just instructional code on a chipset with no built-in access security features. Think about if you had a tablet or laptop with no credential login and you leave it on a table in a coffee shop all day. Anyone that knows that device is there can walk up to it and use it for any purpose they feel. This is literally the state that many IoT devices are in. They have internet access and no security or access control. Now, add to that the situation the 30 Billion accessible devices and you have a pretty scary picture of the future of IoT devices.


How Does a DDoS Work?

With the explosive growth of (unsecured) IoT devices, DDoS attacks have grown by 91% since 20162. But, thankfully, DDoS attacks still aren’t free to deploy. They cost money just like any task that requires compute power. Hackers build their own networks of compromised endpoints (see how a university was attacked by its own vending machines and smart light bulbs3), or they can rent time on a botnet, which is listed on the dark web, to add to their numbers. These endpoints can range from the aforementioned IoT devices to your grandmother’s old desktop. Rookie hackers will often use tools like Low Orbit Ion Cannon4 to haphazardly throw all that they have at a company’s networks, while seasoned veterans take a subtler—and more effective—approach.

RAYOME, ALISON (2017). “DDOS ATTACKS INCREASED 91% IN 2017 THANKS TO IOT.” TECHREPUBLIC. 2

SMITH (2017). “UNIVERSITY ATTACKED BY ITS OWN VENDING MACHINES, SMART LIGHT BULBS, & 5,000 IOT DEVICES” CSO. 3

POOJARY, KARTHIK (2012). “FIVE DDOS ATTACK TOOLS THAT YOU SHOULD KNOW ABOUT.” COMPUTER WEEKLY. 4

10

ADAPTURE /// The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats


Rather than wasting money on suicide missions, these experienced hackers will, instead, slowly test to see if a company is a viable target or not. Attackers must first establish whether the company’s network traffic is being sifted through a cloud-based DDoS protection software before expending more resources. To accomplish this, the hacker sends a probe (a small amount of botnet-driven traffic) to test for attack efficacy. If this initial traffic is not detected or blacklisted by the company’s monitoring systems, the hacker can then ramp the traffic up on an exponential curve and, over time, these attacks can completely cripple a network.


DDoS Detection

The critical problem with modern DDoS attacks is that hackers are using legitimate pathways to subtly send what looks like legitimate traffic. If you are a small to medium business or SMB, you might attribute these initial small spikes to successful marketing campaigns, industry fluctuations, or generic growth as a company. Alternatively, if you’re a larger organization, you may not notice these spikes at all until it’s too late. It’s easy to know when you’re in the midst of a 500,000-instance botnet traffic storm, but detecting an impending one is a different matter altogether. Your primary goal is to recognize the threat as soon as possible after an attack begins—no matter how small the traffic increase.

But first, let’s discuss what to do if you’re already under attack.

12

ADAPTURE /// The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats


DDoS Detection

How Do You Know What is Real and What is Malicious? It’s up to you and your IT team to detect and respond to DDoS attacks in a timely and rational manner. Your first instincts in these scenarios are not always the most rational; you must change your incident response mentality when you are under a DDoS attack. Your first instinct might be to block everyone. Don’t. This is exactly what the hacker wants you to do. By blindly shutting your site or network down entirely, the hacker gets what he or she wanted in the first place. Remember that the goal of the attacker is almost never what it seems to be; usually he or she is hiding his or her primary motivations. Many times, the attacker wants more than for you to just shut down and frustrate your clients. Some hackers will launch an additional attack on your critical systems while the DDoS

14

ADAPTURE /// The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats


attack is still going on, using the botnet as a distraction technique. In these cases, if you simply address the DDoS symptoms in the moment, you could be overlooking something far more malicious. If your company is under a DDoS attack, remember that you have more control in these scenarios than you feel at the time. But, you must make sure that you identify the specific problem before acting. In these beginning stages, stopping the bleeding isn’t as important as finding out why you’re bleeding. Start by analyzing the situation— if you act impulsively and without the necessary intel, you may very well make a bad situation much worse. Let’s discuss proper response protocols


DDoS Mitigation Steps

STEP 1 – DATA COLLECTION The first order of business should be the meticulous collection of investigative data through your log files, trace reports, and any other available raw aggregate data reserve. Analysis of these reports should help you determine the common threads in your network traffic. Fortunately for us, many hackers are relatively lazy and will only have 1-2 instructions for these bots, making the attack vectors somewhat homogeneous and easy to identify once you determine the patterns. The way to discern the good traffic from the bad is through the close analysis of: »» Log analysis (bandwidth to show usage) »» Security Information Manager (SIM) »» External monitors (to determine how fast a site is responding) You can’t analyze all this data alone; you need the combined forces of your operational teams, which brings us to our next step.

16

ADAPTURE /// The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats


STEP 2 – RESPONSE TEAM Once you have collected these data points and analytics, deliver them to your designated mitigation team. You should have already established this First-Response Team long before you started getting suspicious spikes in traffic, and you should consider incorporating members from the following in no specific order: »» Application and Development Team »» Legal Team »» C-Suite (for fast approvals in messaging, announcements, budgets, etc.) »» Risk Analysis Team »» Architecture Team (for LoB) »» Networking Team (preferably the manager) »» Security Team (Solution Architects to augment security rules for the future) »» Database Team (to determine what is being requested and why) The makeup of your team will vary depending on your specific needs. What matters most is that you have one, and that the team is empowered to take decisive action when it matters most.


DDoS Mitigation Steps

STEP 3 – DISCOVER WHY Take advantage of the specific-to-your-networks expertise and knowledge that your team members have established over the course of their employ with your company: »» The Network Team knows what a normal amount of traffic looks like for your networks and will be able to tell you what looks “off” and what looks legitimate (e.g. If, for the past few months, the average has been 2 GET requests per second, then you can suspect that those with 5 or more are invalid). »» The Application and Development Team knows how the application(s) should function and will be able to discern (within the code) what the attack has changed or affected. »» The Architecture Team knows how the application(s) install and how they should function within the physical or virtual environment; they will be able to identify if/how the attack has altered its behavior or efficacy. »» The Security Team will be able to run specific diagnostics against your security devices to identify malicious code, compromised Firewalls, or to determine if critical data has been accessed without authorization.

18

ADAPTURE /// The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats


Together, these team members will be able to discern how you are being attacked, whether the traffic is inbound or outbound, if the attack is being directed from inside the country or from a foreign nation, etc. Most importantly, they should determine why the attack is happening and what is being targeted. To do this, they need to try to determine the motives of the hacker. Was the attack meant to: »» Simply take your networks down? »» Limit your availability in a certain region? »» Distract you from a secondary attack on your critical data? Et cetera. Armed with these logs, analytics, and determined answers, your Response Team will begin architecting a tailored halting, containment, and reporting strategy for this particular DDoS attack.


DDoS Mitigation Steps

STEP 4 – HALTING THE ATTACK It’s finally time to stop the bleeding by halting the attack both inbound and outbound so it is no longer gaining traction and affecting your networks. Depending on the situation, your best option may be to completely shut your systems down while you mitigate any breaches that occurred. Preferably, you can write a rule to stop the traffic based on your Response Team analytics, what kind of DDoS attack it is, and where the attack is coming from. Armed with this information, your Development and Security Teams can build a reverse-engineered blueprint of the attack and write a tailored network traffic filter that blacklists illegitimate traffic while enabling legitimate traffic to continue.

STEP 5 – CONTAINMENT After halting the attack, and if you have determined that a data breach has occurred, you can begin executing your containment strategy by quarantining all affected devices. Once quarantined, your Security Team will thoroughly check them for newly introduced vulnerabilities or data loss and begin the eradication process (depending on your security technology and software). This is where you find and remediate any secondary or obscured attacks.

20

ADAPTURE /// The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats


STEP 6 – REPORTING This step is often where we see larger corporations make their greatest mistakes, whether it be by reporting too soon with too little information or sitting on the announcement for too long (which causes public outcry and further security vulnerabilities for the end users). Depending on your compliance requirements, you are likely under strict rules regarding how you report a breach to the appropriate authorities. Beyond that, however, you must decide when and how to report the attack to the general public. But before you do, ask yourself these questions: »» Have you remediated the issue enough to report? »» Is there another vector of influence available to the attackers? By announcing the breach and how it occurred, are you opening yourself up to additional attacks? »» Do you have enough intelligent information to announce the attack? »» How will this affect your brand (C-level consideration)? The attack itself is a serious issue but reporting it could substantially hurt your brand equity. You have to weigh the moral implications of the breach (user data security, performance, etc.) against what is necessary to further protect your business. It’s a difficult balancing act, and you will heavily rely on the wisdom and expertise of your C-Suite and Legal Team to make these final decisions.


Response Time Implications and Regulati

Why does response time matter? On a generic level, you need to reclaim control of your networks as quickly as possible. You are dealing with a rogue individual dictating your ability to provide the services you have promised your clients. Getting back to normal operations is essential your business. Additionally, there are far other critical reasons to work diligently towards a timely response—namely the protection of user data, your compliance strictures, and your company’s legal liability. Your response time is critical because you need to know if and for how long the hacker has been siphoning data from your systems, and if they have been, where that data has gone. You need this information because the FBI requires it of you. As your team members go through the motions of your predetermined halting, containment, and reporting strategies, they will also be required to follow the practices for proper Chain of Custody before all procedural documentation is handed over to the authorities (the FBI provides a free booklet detailing their requisite Chain of Custody protocols called Cybersecurity Response Readiness5).

5

22

(2018) INCIDENT RESPONSE POLICY. FBI.

ADAPTURE /// The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats


ions

The FBI protocols are thorough, and you must meticulously follow them, bearing in mind that improper Chain of Custody can result in delayed remediation and hinder your ability to respond to the breach, if the FBI seizes your equipment as part of an active crime scene.


Response Time Implications and Regulati

Shortcuts Aren’t Worth It Planning and execution, according to the proper standards, takes time. We get it; you’re ready to act now. This DDoS attack costs you money every second it continues operating. But shortcuts will not pay off. When you don’t take the proper steps, it affects your ability to get the correct data. For example, you might make hurried assumptions about the attack vectors, so you impulsively block China to defend yourself. But, you still do business there, so you’ve effectively undercut legitimate action. Instead of taking detrimental shortcuts and operating off instinct rather than analytics, rely on the expertise and alacrity of your Response Team to thwart the attack.

24

ADAPTURE /// The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats


ions


You’ve Stopped the Threat...For Now

Alright, you’ve successfully thwarted the attack. Your Response Team has executed all mitigation procedures and submitted the proper documentation to the FBI for proof of Chain of Custody. Now what? What should your next steps be? Once the dust settles, you should turn your attention to your: »» Root Cause Analysis (RCA) to determine what happened with the assistance of your Architects and the FBI »» After Action Report (AAR) to determine what happened after the response with your C-Suite and the FBI »» In-house Communication Protocols to ensure that all data of the attack remains within the Response Team (ensuring that there are absolutely no leaks or end arounds, so you may even want to lock down email and messaging to prevent attack information leaks) After these post-analyses, you can begin the remediation of discovered flaws. Your RCAs and AARs will be used by your Response Team to design a new security roadmap for future operations. Because you know your vulnerabilities better, you can now more intelligently architect solutions moving forward. And if you want to avoid these kinds of attacks in the future, it may be time to consider a more robust security technology and/or strategic solution.

26

ADAPTURE /// The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats


How Can ADAPTURE Set You Up to Weath

The security experts at ADAPTURE help you bolster your defenses and monitoring initiatives in three simple ways: process, strategy, and (best-in-class) technology.

Process ADAPTURE engineers work closely alongside your Response Team to help you with your pre-planning protocols—we become an extension of your existing security forces. If you are currently suffering from the aftermath of a DDoS attack, we come in and help you manage the remediation process, leveraging the data collected through your RCAs and AARs. Our practiced technicians are well-versed in Chain of Custody protocol and will ensure the delivery of the proper procedure and documentation to the FBI in a breach occurrence.

Strategy Once mitigation is through, our experts help you thoroughly digest the reports and analytics of both before, during, and after the attack. In so doing, we help you better plan against this and similar attacks in the future.

28

ADAPTURE /// The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats


her an Attack?

As we have discovered in our years of experience, DDoS is more than an attack; it is a behavior—the illegitimate use of legitimate action to reach an end goal. When you contract with ADAPTURE, our experts provide an “unbiased eye” that can look at the type of attack (and other similar attack vectors) to determine your company’s risks as well as the best actions for remediation. Because we can see outside of the threat, we provide unbiased insight and uncompromised response time procedure.


How Can ADAPTURE Set You Up to Weath

Technology ADAPTURE offers full support for recommended technology solutions like, F5 Networks Silverline6 and Hybrid DDoS Defender. Silverline is a fully-managed, cloud-based DDoS protection service that detects and mitigates large-scale, SSL, or application-targeted attacks—effectively defending your company from attacks that exceed hundreds of gigabits per second. Compatible both on-premise and off, Silverline guarantees the security of your networks no matter where or how you operate. More specifically, Silverline provides L3-L7 protection through cloud scrubbing technologies that detect, identify, and mitigate threats in real-time, automatically returning legitimate, “sanitized” traffic to your site (allowing you to stay online during the DDoS attack and mitigation). Silverline is more than an automation and mitigation tool, however; it also grants you more visibility into your environments, further arming you and your Response Team during a crisis (and during normal operations).

(2018) “DDOS PROTECTION.” F5 NETWORKS. HTTPS://F5.COM/PRODUCTS/DEPLOYMENTMETHODS/SILVERLINE/CLOUD-BASED-DDOS-PROTECTION 6

30

ADAPTURE /// The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats


her an Attack?

F5’s Hybrid DDoS Defender, HDD, solution takes Silverline to the next level. While Silverline works as a cloud-based service, some organizations do not want to send all of their traffic to an external inspection site. Hybrid DDoS Defender gives you the flexibility of keeping your traffic local with DDoS mitigation technology but switching to the cloud-based scrubbing service when the traffic reaches a level that would cause a disruption in service. This gives you the best of both worlds for detecting a slow ramp type of attack locally or an all-out assault on your organization.


Customization as a Service

While we highly recommend Silverline and HDD for

environment is unique and has very specific demand

technologies on the market, we are well-suited to technology for your company’s needs.

Wo

32

ADAPTURE /// The Anatomy of DDoS Attacks: Detecting and Responding to DDoS Threats


r our clients, we also understand that each

ds. Because ADAPTURE knows the available

o recommend alternative and appropriate

orried about a DDoS attack? Contact a Solutions Architect at ADAPTURE to take back control of your networks and defend against future DDoS campaigns.


Turn static files into dynamic content formats.

Create a flipbook
The Anatomy of DDoS Attacks: Download E-Book by ADAPTURE - Issuu