Light Reading

Cloud Providers: Beware DDoS Domino Effect

Tom Bienkowski
7/7/2014
50%
50%

In this day and age, almost every organization is using the Internet as a platform for business as they realize the benefit of outsourcing online operations such as websites, storage, e-commerce, email, and domain name system (DNS). It makes sense because it allows them to focus more on the core business. It also brings about lower costs and requires fewer internal resources. As such, cloud and hosting providers are experiencing significant growth as they meet this market demand. But with this increase in growth comes a proportional increase in risk.

With the proliferation of cyber threat and "hacktivist" movements, any organization can be the target of a cyber attack, specifically distributed denial-of-service (DDoS) attacks. These days, they are occurring daily because of botnet-for-hire services that charge as little as $2 an hour. However, hosting providers incur a higher risk of being the targets of DDoS attacks than other businesses operating online. Why? They aggregate the risk of all their customers.

The Wikipedia definition of the "domino effect" is a chain reaction that occurs when a small change causes a similar change nearby, which then causes another similar change, and so on in linear sequence. The term is used as an analogy to a falling row of dominoes.

A DDoS attack on one hosting customer can potentially take down the entire operation because they all share the same network infrastructure. In the same way cloud hosting providers pool resources such as bandwidth and storage for their customers, they also pool the aggregated risk of all their customers.

Due to the multi-tenancy nature of cloud-based data centers, a volumetric DDoS attack against one tenant can lead to a domino effect of service outages. Imagine that an attack is launched against one tenant. If the massive amount of malicious traffic bombarding this one tenant can cause the cloud data center to go down or clog up the shared resources, the entire data center can be taken offline or severely slowed. If a company's data center is down because of a DDoS attack, its customers will lose revenue, and the hosting provider will lose revenue and credibility which impacts the viability of the business. This type of outage can be devastating to the reputation and finances of all involved. To make matters worse, the aftershock continues long after the attack has been mitigated.

Because of this looming threat, cloud hosting providers need to proactively defend themselves to ensure service remains available to all of their customers in the event of an attack.

How to avoid becoming the bullseye
The good news is that the risks associated with DDoS attacks can be mitigated. If you don't want to be a victim of the DDoS domino effect, consider four simple strategies that any hosting provider can implement to protect service availability for their customers and themselves:

  • Subscribe to "clean pipes" service from all upstream service providers. Clean pipes will ensure that large-scale DDoS attacks are detected and mitigated in the cloud before they have an impact on the cloud data center, and before customers suffer an outage.
  • Implement an on-premise DDoS mitigation solution. It will enable hosting providers to detect and eliminate stealthy, application-layer DDoS attacks. These attacks target specific applications such as log-in forms and downloads. Due to their narrow focus, they do not require a large amount of traffic, making them very difficult to detect.
  • Monitor traffic inside and outside the cloud data center. Monitoring traffic patterns and protocols is essential to detecting network misuse. Certain systems should be communicating with each other while others should not. When those that should not communicate with each other are communicating, it could mean trouble.
  • Offer additional anti-DDoS service to customers. Operators of cloud data centers can generate additional revenue by offering highly valued DDoS mitigation services to customers. For example, customers who subscribe to the service will have malicious traffic directed against them mitigated. Customers who do not subscribe to the service will simply have their traffic blackholed. This type of service can be a true differentiator in the highly competitive hosting space. The difference between winning and losing business is more and more frequently coming down to valued-added services like managed backup, email and DDoS mitigation.

By taking these precautions, hosting providers can increase their reliability and service availability while generating more revenue by offering valued DDoS protection services to their customers.

— Tom Bienkowski, Director of Product Marketing, Arbor Networks.

(1)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View
danielcawrey
50%
50%
danielcawrey,
User Rank: Light Sabre
7/7/2014 | 4:45:13 PM
Tenants
With so many different tenants on a cloud provider's plate, it would seem problematic to be able to stop an all-out DDoS. But technology is improving, and it is clear that providers have no choice but to have procedures in place to prevent the so-called domino effect.

Here's hoping that they work, because major cloud outages are always widely reported and gives the technology a bad rap, fair or unfair. 
More Blogs from Column
Bigger. And Better. But definitely bigger.
When trying to develop innovative technologies, engineers must be willing to take risks, make mistakes and move ahead incrementally without having all the data.
Mobile network operators have the network and a business model that makes them well suited to lead the charge as the Internet of Things (IoT) takes off.
Gathering useful information for real-time management of Ethernet and IP networks is a non-trivial issue.
There are three important questions service providers need to address for in-market and out-of-market expansion.
Flash Poll
From The Founder
The New IP is actually bigger even than business. Like another hugely important tech that Light Reading is digging into right now, the New IP has the potential to change the world by fundamentally advancing what it is possible for people to achieve with communications.
LRTV Huawei Video Resource Center
The Power of Five Convergences in OceanStor OS

3|4|15   |   6:24   |   (0) comments


OceanStor OS is Huawei's brand-new storage operating system. While inheriting the consistent high stability, reliability and performance from the company's previous storage products, OceanStor OS abounds in new converged storage features. Specifically, the new storage operating system achieves "five convergences" to lift storage convergence to a higher level.
LRTV Huawei Video Resource Center
4K Brings Extreme Video Experience

3|4|15   |   8:10   |   (0) comments


4K video is a hot topic in the video industry. It will certainly bring an extreme video experience to end users. At the same time, however, it will also pose a big challenge to operators. Check out this Huawei 4K experts' discussion about how operators can achieve success in 4K video service.
LRTV Interviews
DT's Virtualization Vision for Europe

3|4|15   |   10:23   |   (0) comments


Light Reading CEO Steve Saunders talks virtualization, cloudification and standards with Deutsche Telekom's Axel Clauberg at Mobile World Congress.
LRTV Custom TV
ZTE's Wireline at MWC 2015

3|4|15   |   6:35   |   (0) comments


Light Reading speaks with Jane Chen, ZTE's Senior VP of Wireline Business, about innovations in her product line at Mobile World Congress.
LRTV Custom TV
ZTE at MWC 2015

3|4|15   |   4:24   |   (0) comments


Dr. Dick Chen of ZTE USA gives Light Reading an overview of what's new at ZTE's pavilion at Mobile World Congress 2015.
LRTV Interviews
Ericsson CEO Talks Telco Data Center Tech

3|4|15   |   05:45   |   (0) comments


At Mobile World Congress, Ericsson CEO Hans Vestberg discusses telco data center technology, business models, small cells and more.
Between the CEOs
EXCLUSIVE: Cisco's Chambers on Reinvention

3|3|15   |   8:24   |   (1) comment


Light Reading CEO Steve Saunders talks transformation and virtualization – including Light Reading's independent testing of the vendor's virtualization solutions – with Cisco CEO John Chambers at Mobile World Congress in Barcelona.
LRTV Documentaries
The Three Cs of MWC15

3|2|15   |   2:33   |   (1) comment


My visit to this year's Mobile World Congress is going to dominated by three Cs – cloud, cells and coffee.
LRTV Huawei Video Resource Center
Huawei Shares Its Vision of the Future of Mobile Networks Innovations

2|26|15   |   2:30   |   (0) comments


Mobile broadband is changing our lives. It's reshaping the Internet, industry, and society. It allows us to freely connect with one another anytime, anywhere. At this year's Mobile World Congress, Huawei will share its latest insights and newest ideas and technologies that will shape the future of MBB. They will showcase their end-to-end MBB solutions that will ...
LRTV Huawei Video Resource Center
Accelerate Digitizing, Boost Digital Business

2|26|15   |   6:14   |   (0) comments


A new digital revolution is leading us to a better connected world. Together with millions of digital partners, Huawei will help CSPs to build their digital service ecosystem and aggregate a wide variety of digital services. In this video, we find out how Huawei is going to help CSPs implement digital operations.
LRTV Huawei Video Resource Center
The Secret Recipe to Enabling Hyper-Growth Industries

2|26|15   |   3:38   |   (0) comments


With a number of successful cases on network capability exposure, Huawei is going to share the secret recipe to enabling hyper-growth markets with a step-by-step approach.
LRTV Documentaries
BTE 2015 Is Bigger & Even Better

2|25|15   |   03:13   |   (4) comments


This year's Big Telecom Event (BTE) in Chicago is going to provide more opportunities than ever for networking, getting to grips with key industry challenges and opportunities and, equally as important, having some fun.
Upcoming Live Events
March 17, 2015, The Cable Center, Denver, CO
April 14, 2015, The Westin Times Square, New York City, NY
May 12, 2015, Grand Hyatt, Denver, CO
May 13-14, 2015, The Westin Peachtree, Atlanta, GA
June 8, 2015, Chicago, IL
June 9-10, 2015, Chicago, IL
June 9, 2015, Chicago, IL
June 10, 2015, Chicago, IL
All Upcoming Live Events
Infographics
Net neutrality, broadband services and the current outlook on data consumption, as presented by the New Jersey Institute of Technology.
Hot Topics
Internet Pioneers Decry Title II Rules
Carol Wilson, Editor-at-large, 3/2/2015
Wheeler: We'll Enforce Title II 'Case-By-Case'
Sarah Thomas, Editorial Operations Director, 3/3/2015
New CenturyLink CTO in Major Overhaul
Carol Wilson, Editor-at-large, 3/4/2015
Verizon Takes Radio Dot to Detroit, VoLTE Overseas
Sarah Thomas, Editorial Operations Director, 2/27/2015
Like Us on Facebook
Twitter Feed
Webinar Archive
BETWEEN THE CEOs - Executive Interviews
Check out Light Reading's interview with Jay Samit, the newly appointed CEO of publicly traded SeaChange International Inc. With a resume that includes Sony, EMI, and Universal, Samit brings a reputation as an entrepreneur and a disruptor to his new role at the video solutions company. Hear what he had to say about the opportunities in video, as well as the outlook for cable, telco, OTT and mobile service providers.