Light Reading
Aggregating customer traffic in a multi-tenant setting can also aggregate the risk of DDoS attacks

Cloud Providers: Beware DDoS Domino Effect

Tom Bienkowski
7/7/2014
50%
50%

In this day and age, almost every organization is using the Internet as a platform for business as they realize the benefit of outsourcing online operations such as websites, storage, e-commerce, email, and domain name system (DNS). It makes sense because it allows them to focus more on the core business. It also brings about lower costs and requires fewer internal resources. As such, cloud and hosting providers are experiencing significant growth as they meet this market demand. But with this increase in growth comes a proportional increase in risk.

With the proliferation of cyber threat and "hacktivist" movements, any organization can be the target of a cyber attack, specifically distributed denial-of-service (DDoS) attacks. These days, they are occurring daily because of botnet-for-hire services that charge as little as $2 an hour. However, hosting providers incur a higher risk of being the targets of DDoS attacks than other businesses operating online. Why? They aggregate the risk of all their customers.

The Wikipedia definition of the "domino effect" is a chain reaction that occurs when a small change causes a similar change nearby, which then causes another similar change, and so on in linear sequence. The term is used as an analogy to a falling row of dominoes.

A DDoS attack on one hosting customer can potentially take down the entire operation because they all share the same network infrastructure. In the same way cloud hosting providers pool resources such as bandwidth and storage for their customers, they also pool the aggregated risk of all their customers.

Due to the multi-tenancy nature of cloud-based data centers, a volumetric DDoS attack against one tenant can lead to a domino effect of service outages. Imagine that an attack is launched against one tenant. If the massive amount of malicious traffic bombarding this one tenant can cause the cloud data center to go down or clog up the shared resources, the entire data center can be taken offline or severely slowed. If a company's data center is down because of a DDoS attack, its customers will lose revenue, and the hosting provider will lose revenue and credibility which impacts the viability of the business. This type of outage can be devastating to the reputation and finances of all involved. To make matters worse, the aftershock continues long after the attack has been mitigated.

Because of this looming threat, cloud hosting providers need to proactively defend themselves to ensure service remains available to all of their customers in the event of an attack.

How to avoid becoming the bullseye
The good news is that the risks associated with DDoS attacks can be mitigated. If you don't want to be a victim of the DDoS domino effect, consider four simple strategies that any hosting provider can implement to protect service availability for their customers and themselves:

  • Subscribe to "clean pipes" service from all upstream service providers. Clean pipes will ensure that large-scale DDoS attacks are detected and mitigated in the cloud before they have an impact on the cloud data center, and before customers suffer an outage.
  • Implement an on-premise DDoS mitigation solution. It will enable hosting providers to detect and eliminate stealthy, application-layer DDoS attacks. These attacks target specific applications such as log-in forms and downloads. Due to their narrow focus, they do not require a large amount of traffic, making them very difficult to detect.
  • Monitor traffic inside and outside the cloud data center. Monitoring traffic patterns and protocols is essential to detecting network misuse. Certain systems should be communicating with each other while others should not. When those that should not communicate with each other are communicating, it could mean trouble.
  • Offer additional anti-DDoS service to customers. Operators of cloud data centers can generate additional revenue by offering highly valued DDoS mitigation services to customers. For example, customers who subscribe to the service will have malicious traffic directed against them mitigated. Customers who do not subscribe to the service will simply have their traffic blackholed. This type of service can be a true differentiator in the highly competitive hosting space. The difference between winning and losing business is more and more frequently coming down to valued-added services like managed backup, email and DDoS mitigation.

By taking these precautions, hosting providers can increase their reliability and service availability while generating more revenue by offering valued DDoS protection services to their customers.

— Tom Bienkowski, Director of Product Marketing, Arbor Networks.

(1)  | 
Comment  | 
Print  | 
Newest First  |  Oldest First  |  Threaded View
danielcawrey
50%
50%
danielcawrey,
User Rank: Light Sabre
7/7/2014 | 4:45:13 PM
Tenants
With so many different tenants on a cloud provider's plate, it would seem problematic to be able to stop an all-out DDoS. But technology is improving, and it is clear that providers have no choice but to have procedures in place to prevent the so-called domino effect.

Here's hoping that they work, because major cloud outages are always widely reported and gives the technology a bad rap, fair or unfair. 
More Blogs from Column
Share your views on the next five years and find out what your peers think too.
The complexity of cloud service sourcing will boost demand for infrastructure-as-a-service.
Automation saves you from repeating the same things over and over again.
Terabit Demonstrator Project to be unveiled at SC14 in New Orleans.
We can take these five rules and apply them to SDN and NFV to see if these two technologies make sense for cable, starting with Rule 1 in this post.
Flash Poll
From The Founder
It's clear to me that the communications industry is divided into two types of people, and only one is living in the real world.
LRTV Interviews
The New Wave of IP + Optical Integration

11|21|14   |   04:29   |   (7) comments


At the Alcatel-Lucent Technology Symposium, Heavy Reading senior analyst Sterling Perrin talks about how SDN has reshaped the discussion around packet and optical integration.
LRTV Huawei Video Resource Center
Huawei Highlights at BBWF 2014

11|20|14   |   3:40   |   (1) comment


Broadband World Forum is one of the world's largest telecoms, media and technology events with over 7,800 senior executives from across the globe converging on Amsterdam every year to identify the Next Big Thing. BBWF is an exciting place to meet the entire industry under one roof and identify the latest in network innovation, service optimization and customer ...
LRTV Huawei Video Resource Center
How Will BCMS Stimulate Margin for Broadband Operators?

11|19|14   |   6:52   |   (0) comments


In BBWF 2014, Liu Shuqing emphasizes the value of FMC 2.0 based full service experience by throwing light on the BCMS solution. The underlying principle of this innovative technique is to create network robustness and driving network from connection oriented to ACE – BAND oriented infrastructure, in which applications, cloud, and user experiences will be an asset ...
LRTV Huawei Video Resource Center
SingleFAN3.0: Better Connected Experience

11|19|14   |   3:06   |   (1) comment


At the BBWF 2014, David Hu, the VP of Huawei Access Network Product Line, talked about the future of access networks – SingleFAN3.0: faster broadband, wider coverage, and smarter connection.
LRTV Interviews
Basil Alwan Interview: The Road to Cloud

11|19|14   |   09:09   |   (0) comments


Alcatel-Lucent's head of IP and Transport talks about the migration towards a web-like networking environment, the impact of the cloud, SDN and NFV, and the yet-to-be-announced FP4 chip.
LRTV Documentaries
FairPoint Makes a Fair Point About Analytics

11|19|14   |   1:56   |   (1) comment


The US-based communication service provider gets to grips with advanced analytics, tackling data and breaking down the silos within its own business.
LRTV Documentaries
Analytics Lets C Spire Get to Know Subs

11|19|14   |   3:01   |   (2) comments


It's all about the data for US operator C Spire as it uses analytics to personalize its customer service down to individual subscribers.
LRTV Interviews
Nuage Branches Out With SDN: CEO Interview

11|17|14   |   9:32   |   (0) comments


Sunil Khandekar, CEO of Alcatel-Lucent's SDN-focused unit Nuage Networks, talks about the opportunities and challenges of breaking out of the data center into wide-area networks.
Light Reedy
Telecom Analytics Grows Up

11|14|14   |   1:15   |   (4) comments


The big data analytics debate has moved on from a year ago, with some experts suggesting it's no longer a technology challenge.
LRTV Huawei Video Resource Center
Huawei Compass

11|14|14   |   3:17   |   (1) comment


At OpenStack Summit 2014, Shuo Yang, Huawei Principal Cloud Infrastructure Architect introduced Huawei Compass, the software tool for solving customers' problems on the journey of OpenStack Cloud.
LRTV Huawei Video Resource Center
Huawei's Cloud Strategy in European Region

11|14|14   |   2:56   |   (1) comment


At OpenStack Summit 2014, Dr. Gotz, CTO of Huawei IT in European Region introduced Huawei's cloud strategy in European region.
LRTV Huawei Video Resource Center
Huawei's Contribution on OpenStack

11|14|14   |   5:58   |   (0) comments


At OpenStack Summit 2014, Dennis Gu, Huawei Chief Architect of Cloud Computing introduced the relationship between OpenStack and cloud computing, and Huawei's contribution on OpenStack.
Upcoming Live Events
December 2, 2014, New York City
December 3, 2014, New York City
December 8-10, 2014, Reykjavik, Iceland
February 12, 2015, Atlanta, GA
April 14, 2015, New York City, NY
May 6, 2015, McCormick Convention Center, Chicago, IL
May 13-14, 2015, The Westin Peachtree, Atlanta, GA
June 9-10, 2015, Chicago, IL
Infographics
Irish Telecom outlines the rise of VoIP technology, including its adoption within businesses and their perception of its quality.
Hot Topics
Bell Labs Chief Slams 'Toy' Networks
Robert Clark, 11/19/2014
$38.3M: Ain't That a Kik in the SMS
Sarah Reedy, Senior Editor, 11/20/2014
Do You Have a 2020 Vision?
Dennis Mendyk, Vice President of Research, Heavy Reading, 11/21/2014
The New Wave of IP + Optical Integration
Ray Le Maistre, Editor-in-chief, 11/21/2014
Google, AT&T, BT Unite on Network Data Models
Carol Wilson, Editor-at-large, 11/20/2014
Like Us on Facebook
Twitter Feed