Interconnected Contests
145
providers) tier-three providers, who may lack a fi scal incentive to protect their customers. Tier-three Web-hosting providers sell their services for a small margin over costs —
the hours worth of system administration time necessary to fend off a DDoS attack is
more costly than the annual profi t for the average account. These providers evidently
do not see a reputation risk in failing to fend off a DDoS, and they fi nd it more profi table to end relationships with “ troublesome ” customers than to provide protection to
them.
The apparent effi cacy of upgrading servers and fi xing Web server software strongly
suggests that attacks are not all based on clogging network connectivity (where these
defenses would be ineffective) and point to application-level vulnerabilities. These
sorts of fi xes are only really helpful for either very small traffi c attacks or application
attacks, both of which can be reasonably dealt with by individual publishers at the
edge of the network.
Best Practices for Human Rights and Independent Media Sites Are Emerging
for DDoS Response
According to experts with whom we consulted, the responses that a site might take
to a DDoS attack include the following:
• Blackholing the IP address of the attacked site (i.e., taking the attacked site offl ine).
• Deploying additional network and server infrastructure for the attacked site.
• Downgrading the content and/or functionality of the attacked site to reduce resource
consumption.
• Filtering out attack traffi c.
• Using a service with a distributed architecture to scale and absorb attacks on demand.
These responses range from the simplest to implement (taking the site offl ine, which
is essentially giving up in the face of an attack) to complicated and diffi cult to
implement.
Blackholing the IP address of the attacked site fulfi lls the aims of the attacker by
making the site unavailable. But this response also makes the attack traffi c disappear
entirely from the Internet. In so doing, it protects the network hosting the site. This
is the approach taken by many ISPs that are faced with a large traffi c-based attack that
is either too big or too expensive for them to defend against.
An attacked site may deploy additional servers and bandwidth to protect itself. Our
survey results show that this is indeed the most popular method of protection. But
for all but the biggest sites, deploying additional infrastructure for a single site is cost
effective for small, application-based attacks only, because the peak traffi c of a large,
traffi c-based DDoS attack will be orders of magnitude larger than the peak legitimate
traffi c of a site.
Précédent

- 162/431

Suivant