Distributed denial-of-service (DDoS) attacks are particularly hostile: Threat actors deliberately attempt to disrupt operations of publicly exposed sites, systems, and APIs.
When successful, they can degrade performance, disrupt user experience, and even render mission critical workloads completely unavailable.
They are a growing method employed by attackers to harm and immobilize organizations beyond stealing or exposing valuable data — and by one estimate, they have increased by 150%.
“DDoS attacks attempt to overwhelm their victims’ services by exhausting the resources and provisioned capacity to take them offline,” said Emil Kiner, senior product manager for Cloud Armor. “Attacks have evolved in frequency, size, and sophistication.”
This is in part, Kiner said, to the proliferation of “DDoS-for-hire” services, easy access to attack toolkits and the exponential growth of potentially vulnerable internet connected devices.
To protect its customers against this growing threat, Google Cloud today announced the general availability of Cloud Armor advanced network Distributed Denial of Service (DDoS) protection.
The service provides “always-on” attack detection and mitigation for Google Cloud customers in gaming, telecommunication and other transmission control protocol (TCP)-based services that are exposed to the internet and vulnerable to DDoS attacks.
“As attack sizes grow, it has become unsustainable and unscalable for individual organizations to provision enough capacity to handle attack volumes,” said Kiner.
Higher Volume, Trickier ExploitsDuring a DDoS attack, threat actors direct a high volume of traffic against the victim website, API, or other internet exposed service, Kiner explained.
The typical goal is to degrade the performance of the victim’s application or service to the point where it is inaccessible to legitimate users, he said. This is either because its server(s)’ resources have been exhausted or are consumed in handling incoming traffic volume, or because the infrastructure costs to operate the victim service become too high during the attack.
High-volume attack traffic is commonly sent from a larger botnet of compromised internet connecting devices that can, in aggregate, send more than enough traffic to overwhelm even highly provisioned servers, said Kiner. Or attackers will attempt to trick otherwise legitimate servers to send traffic towards the victim to amplify the total attack size.
Ultimately, there are many different attack types, and they continue to expand in type and sophistication. One common method is application level Layer 7 or HTTP floods, in which attackers flood servers with requests specifically for pages with large loading volumes.
Another is network level volumetric protocol based attacks (such as TCP SYN floods). With this method, attackers rapidly initiate a connection to a server without finalizing the connection, thus forcing the server to waste resources waiting for only half-opened connections.
Other techniques can include Network Time Protocol amplification, DNS reflection, UDP flood, and packets carrying spoofed IP to internet-enabled devices running Character Generator Protocol (CharGEN).
Real-time DetectionKiner pointed out that last June, Google successfully detected and mitigated an HTTP/S flood attack against one of its customers.
The flood rose to 46 million incoming malicious requests per second. At the time, it was the largest ever publicly disclosed attack coming from more than 5,000 compromised devices from more than 130 countries.
Leveraging real-time machine learning, Cloud Armor Adaptive Protection was able to alert the customer, and a recommended protective rule was deployed before the attack ramped to full magnitude.
“Cloud Armor was able to detect, analyze, and block the attack ensuring the customer's service stayed online and continued serving their end-users,” said Kiner.
The expanded Cloud Armor advanced network Distributed Denial of Service (DDoS) provides detection and mitigation for workloads behind External Network Load Balancer, Protocol Forwarding, or VMs with Public IP addresses. It expands on the customer infrastructure Google can protect with a GCP native offering to defend workloads from network level volumetric DDoS attacks.
Among Cloud Armor’s key highlights:
- Advanced network DDoS protection that defends workloads from the most common volumetric DDoS and protocol DDoS attacks. Also informs customers about past and ongoing DDoS attacks through mitigation alert logging via Cloud Logging.
- Operation at the edge of Google’s network by monitoring workloads' health, analyzing incoming traffic, and deploying the most appropriate mitigation at the network edge.
- Generation of three types of event logs when mitigating DDoS attacks, including detecting an incoming attack, providing consistent updates about the attack, and determining a conclusion of the attack and the end of mitigation.
Beyond deploying tools, Kiner advised organizations to perform thorough threat modeling to understand their attack surface and the nature of the threats they are exposed to. Also, careful capacity planning is important to ensure that services are provisioned to handle not just the average level of expected usage, but to account for cyclical peaks.
Comments