
In Week 7 we are nearing the end of STRIDE, and have come to Denial of Service. A key component of security is availability. In today's world of eCommerce and viral marketing companies all want to drive the most visitors to their site. If the web servers are not able to handle the connections users will see the dreaded "Page Cannot Be Displayed" error message. Why it's possible this is caused by a huge number of legitimate consumers, a sort of good problem, it's also possible that a DoS or DDoS attack is occurring.
Launching a Distributed Denial of Service attack sounds like it would be something only available to top hackers. In a standard DoS attack simply blocking the traffic, or discarding all traffic, from the source IP address may be enough to end the attack. With a DDoS attack there could be hundreds or many thousands of source IP addresses. The attack could also evolve so the source addresses are changing throughout the attack. That makes traditional mitigation methods entirely ineffective.
Now for the even worse news. Bad actors have decided to offer up botnets for DDoS attacks using the same subscription model that modern companies use for their software. It's possible for anyone that has access to the Internet, and in most cases some Bitcoin for payment, the ability to start launching DDoS attacks. According to CSO Online the cost for renting that type of attack could cost as little as $10/month. So not only does the attack not take any skill, it also is cheap enough that it's accessible to nearly anyone. This price scales up, and there are indications that even the massive Mirai botnet with more than 400,000 devices can be rented.
With the ease of the attacks now it can be difficult for companies to defend against them. eSecurity Planet recommends that companies hosting web servers take some basic precautions. Just like with other incidents you should have a DDoS policy and procedure to follow. It's also a good idea to move websites to hosting companies. Dedicated hosting companies have higher bandwidth and high performing routers that can better withstand the attacks. Coupled with staff experienced in handling DDoS attacks a web host can be a great ally in your security team.
https://www.esecurityplanet.com/network-security/5-tips-for-fighting-ddos-attacks.html
https://www.bleepingcomputer.com/news/security/you-can-now-rent-a-mirai-botnet-of-400-000-bots/
https://www.csoonline.com/article/3180246/data-protection/hire-a-ddos-service-to-take-down-your-enemies.html
https://www.wired.com/story/reaper-iot-botnet-infected-million-networks/
https://www.cisco.com/c/en/us/products/collateral/security/traffic-anomaly-detector-xt-5600a/prod_white_paper0900aecd8011e927.html