4 June 2018
Use monitoring service for early detection of DDOS attacks
Average losses from DDoS attacks are estimated around 50 thousand dollars for small organizations and almost 500 thousand dollars for large enterprises. Eliminating the consequences of a DDoS attack will require additional employee time, diversion of resources from other projects to ensure security, develop a software update plan, upgrade equipment, etc.
A notable trend of DDoS attacks is the expansion of the "list of victims". It now includes representatives from virtually all sectors. In addition, methods of attack are being improved. According to Nexusguard, at the end of 2016 the number of DDoS attacks of a mixed type increased significantly, using several vulnerabilities at once. Most often they were subjected to financial and state organizations. The main motive of cybercriminals (70% of cases) is the theft of data or the threat of their destruction for the purpose of redemption. Less often - political or social goals. That's why the defense strategy is important. It can prepare for an attack and minimize its consequences, reduce financial and reputational risks.
How to monitor DdoS attacks?
You can use a program that will filter incoming requests and provide the necessary level of security for the site, it is possible to monitor the resources of the server infrastructure serving the site. And thanks to such monitoring, it is quick to find out about possible problems with the site.
The use of alarms can be especially effective when adjusting an existing DDoS protection solution to more strongly filter requests in the event of an attack. For example, if there is a significant increase in the response time from site hosting, additional mechanisms that block malicious requests are included.
The following network infrastructure parameters can be used for monitoring and signaling:
- Amount and % of active use of the network connection channel to the server (hosting).
- Status of IT security systems and critical resources (for example,% CPU, Load Average or % wait).
- Known information about the structure of the attack: attacking subnets, the channel used, the type of attack.
- Effectiveness or inefficiency of current protection means (signatures, user verification, blocking).
0
0
Comments
Facebook improves connectivity in the African region with an undersea internet cable
7 November 2021Can blind spots be avoided when monitoring DCs?
3 November 2021Influence of automation in DC on engineering personnel
30 October 2021The frequency of accidents in DC has decreased and the sum of damage has increased significantly
26 October 2021
How to avoid mistakes when choosing a hosting
How to avoid mistakes when choosing a hosting
Chinese manufacturer Loongson will enter the market ..
Chinese manufacturer Loongson will enter the market with 16-core processor in 2020
Please sign-in to comment here