logo level
SME
Agency
Large enterprise
contactOperationalControl Panel
newswhat-is-ddos

What is DDoS?

You may have heard that a website is ‘down’ or unavailable. Sometimes this lasts only a few minutes, sometimes longer. The causes of this are of course diverse. In this article, we take a closer look at one of the causes, namely hackers and more specifically the DDoS technique they use.

Large enterpriseAgency‎‎ㅤ19/01/2016
What is DDoS? image

What is DDoS?

DoS stands for Denial of Service. DDoS stands for Distributed Denial of Service.

In such a Denial of Service, the aim is to render servers or networks unusable by deliberately overloading them. As a result, they can no longer perform their task properly, and the application or website goes ‘offline’.

A DoS attack is usually launched from multiple locations towards one specific victim, because this is more effective. In this case, we speak of a Distributed DoS, a DDoS.

image330

Why do hackers do this?

Who are they, what drives them? Hard to say, unfortunately, attackers often remain anonymous, because the attacks usually come from infected PCs and servers that cannot be directly linked to the perpetrators.

But we can look at the top reasons why these kinds of attacks are carried out.

Extortion

It seems like an easy way to make money. You manage to take down the website of a company or someone wealthy and then demand ransom. The weak spot here is, of course, that the attacker steps out of anonymity and the victim has a trail to track down the perpetrator.

Destroying business

Online presence is crucial today. So if you bring down someone’s site, you can quickly cause a lot of damage to that business. Think of direct financial losses, for example in an online store, but also reputational damage. If your site doesn’t work, customers quickly get the impression that you don’t have your business in order.

It is believed that this is the most common form of DDoS. The perpetrator may be your competitor, or simply someone unhappy with your presence or who had a bad experience with you. The problem, of course, is that the perpetrator is rarely, if ever, traceable.

Politics / activism

A political party, by definition, has opponents, people who disagree with their views. That sometimes makes the websites of political parties a target, especially if they make the news with a controversial stance.

And governments are not always innocent either. One of the biggest DDoS attacks in recent history, the one on Github.com, is believed to have been coordinated by the Chinese government. Or governments attacking each other - cyber war :)

Just for fun

The last reason I want to highlight is amateurs who do this for fun. We sometimes call them ‘script kiddies’, who launch attacks simply because they can. Just as some enjoy hacking websites, others get a kick out of taking a site offline. Get a life, you might think.

What does Linode have to do with DDoS?

Linode has existed since 2003 and is one of the oldest cloud providers, though perhaps less known to the general public. Compared to a provider like Amazon Web Services (aws.amazon.com), they have far fewer features, but they focus on offering high-quality virtual servers at a very reasonable price.

In that market, Linode has faced heavy competition from Digital Ocean. They entered at the right time with a cheaper offering and, above all, a well-thought-out marketing strategy. More on that in another article - let me focus on what’s happening with Linode.

Linode’s reputation has always been very good. Until now.

Since December 25, 2015, Linode has been the victim of large DDoS attacks, which are still ongoing today (January 8, 2016). On their status page (status.linode.com), you can read all the details. On New Year’s Eve, they even made the news here because the Joker website went offline due to these attacks. On that same evening, the BBC was also under attack. Other well-known sites were also affected.

Is cloud computing infallible then?

Unfortunately, that’s a misconception. The term “cloud computing” gives you the illusion that your website or application runs ‘somewhere in the air’. But no matter what you call it, the computing power you rent doesn’t come from the sky. It comes from physical hardware in brick buildings, connected with kilometers of power and network cables.

Of course, cloud computing is also about scale. And don’t underestimate it: a provider like AWS or Linode is spread across dozens of data centers and has literally thousands of physical servers.

But even large providers can be brought to their knees. So it can happen to you too.

What can I do?

A big problem with DDoS is the asymmetric cost: cheap to execute, very hard to defend against.

If your hosting provider claims they are not vulnerable to DDoS attacks, don’t just take it with a grain of salt, you might as well take the whole salt shaker. And if they claim they can handle a DDoS attack because they have ‘enough bandwidth’ or because they own a firewall of brand WC-Eend, it’s time to end the sales conversation.

So what can you actually do?

Let’s look at the most common situations. The first scenario is that you are not the target, but your provider is, as is now the case with Linode. There is literally nothing you can do in this situation. You can either trust your provider or move to another.

Your provider is attacked

Suppose a few years ago you decided to host all your websites with Linode. That was a perfectly defensible decision. Still, I don’t think it’s such a great idea to move your servers to Linode right now. Remember the phrase “No one ever got fired for buying IBM”? Today, that has become “nobody gets fired for buying Amazon.”

That may be true, but we still believe it’s common sense not to rely on a single provider. What exists today may not be the case tomorrow.

You are attacked yourself

What if you yourself are the target of an attack? Then moving to another provider won’t help, because the attacker will just follow you there. You can then try to rely on the bandwidth, firewalls, and expertise of your provider. But if the attacker puts enough power behind their attack, it’s like fighting a losing battle.

If it really gets that bad, only the big guns help, and by that I mean the really big guns. You need to be protected by services specialized in mitigating DDoS. They will place themselves between the visitor and your server and try to block attacks.

image330

One of the most well-known players is Cloudflare. They have data centers all over the world that do nothing but this. So, they have the tools needed to recognize an attack, preventing it from reaching your application. In addition, they have the scale and the bandwidth to avoid being brought to their knees during an attack. Since, in principle, all they have to do is forward the traffic as it comes in, they can offer this in an economically viable model.



Conclusion

It remains a complex subject. That’s why we find it important to provide you with accurate information, without sales talk or unnecessary buzzwords. Want more info?

Stay informed

Subscribe to our newsletter and receive the latest updates on our products and services.

By subscribing, you agree to our privacy policy