144
Hal Roberts, Ethan Zuckerman, and John Palfrey
• 75 percent had installed security software or hardware on their existing servers, with
92 percent reporting that this measure was “ somewhat effective ” or “ effective. ”
• 62 percent had upgraded their Web server hardware, with 88 percent reporting that
this measure was “ somewhat effective ” or “ effective. ”
• 43 percent had downgraded the functionality on their existing sites, with 33 percent
reporting that this measure was “ somewhat effective ” or “ effective. ”
• 40 percent had subscribed to a denial-of-service-protection or other security service,
with 100 percent reporting that this measure was “ somewhat effective ” or
“ effective. ”
• 38 percent had hosted content temporarily on a large hosting provider (Blogger,
LiveJournal, etc.), with 67 percent fi nding that this measure was “ somewhat effective ”
or “ effective. ”
• 36 percent had changed their hosting providers, with 80 percent reporting that this
measure was “ somewhat effective ” or “ effective. ”
• 29 percent had changed their Web application software, with 75 percent reporting
that the change was “ somewhat effective ” or “ effective. ”
The vast majority of sites that experience DDoS attacks try to update the confi gurations of their local computers by fi xing the existing Web application software, installing local security hardware or software, and installing upgraded local Web server
hardware, or some combination of these three approaches. These basic strategies can
all be taken by individual sites without help from core network providers, though in
some cases core technical expertise may be needed to properly apply these upgrades.
Each of these approaches rates as at least somewhat effective against DDoS attacks,
insofar as these basic changes prove somewhat effective against further attacks.
A much smaller number of sites escalate their responses either by implementing
more aggressive (and costly) defenses at the edge — downgrading functionality or
changing Web application software — or by moving closer to the core of the network:
subscribing to expensive protection services, hosting content on large providers, or
changing hosting providers. The success of these defenses is more mixed than the
simple edge-based fi xes, perhaps because these are the defenses that are valid responses
to network attacks, which are much more diffi cult to fend off than application attacks.
Our results indicate that the number of attacks against each site increased for a
slight majority of participating sites:
• 16 percent reported many more attacks in 2010.
• 36 percent reported somewhat more attacks in 2010.
• 48 percent reported no change or fewer attacks in 2010.
ISPs — who are best positioned to defend sites against many types of DDoS — are often
unable or unwilling to defend their customers. This fi nding leads us to speculate that
many of the sites we surveyed are (or were, as many have been dropped by those
Précédent

- 161/431

Suivant