146
Hal Roberts, Ethan Zuckerman, and John Palfrey
An alternative to increasing the server resources is to reduce the resource consumption of each page, allowing the server to handle more traffi c with the existing server
and network. There are some methods for reducing resource consumption that are
effective and have little cost, such as caching dynamic content to reduce database
queries. As attack size increases, though, an attacked site has to make changes that
have costly side effects, like disabling site functions that require expensive database
queries, reducing or eliminating images and streaming media, or creating an entirely
separate failover site with simpler and less-interactive content.
Another way to reduce resource consumption is to distinguish attacking traffi c from
legitimate user traffi c and fi lter out the attacking IP address. This approach is frequently used, and several of our meeting and interview participants reported success
with this method, but only when the number of attacking machines is small and relatively static. It is simple for a competent system administrator to fi nd and block a
hundred static IP addresses that are fl ooding a site with requests for a single page, but
that job becomes much, much more diffi cult when there are tens of thousands of IP
addresses that are rotating every couple of hours and actively trying to make their
traffi c look legitimate. In these cases, it is sometimes possible to fi lter attacking traffi c
based on a signature for the particular traffi c, but this approach can be very diffi cult
against a moderately skilled attacker even for a highly skilled defender. It is possible
to defend against a range of common attacks by using ModSecurity, an open-source
attack-fi ltering system. But this sort of fi ltering helps against generic attacks only, and
it uses up machine resources for the process of fi ltering and can therefore make the
site more vulnerable to traffi c-based attacks.
Finally, a site can protect itself by paying for a hosting or DDoS protection service
to serve the content of the Web site. There are many services capable of handling all
but the biggest attacks, and a few capable of handling the biggest observed attacks,
simply because they have suffi cient bandwidth and server resources to accept and
process the attack traffi c. The advantage of using such a service is that these services
have economies of scale both in learning how to defend against particular attacks and
in the necessary bandwidth and servers. When using such a service, the attacked site
needs to pay for the peak attack traffi c only while the attack is happening, rather than
paying for the entirety of the resources needed to handle peak attack traffi c.
These services, however, can command a very high markup on those resources.
Even without the high markup, simply paying for the bandwidth to handle the peak
attack traffi c can be prohibitively expensive, especially for an independent media site.
An attacked site may be able to hire a provider capable of handling millions of requests
per second but not be able to afford the resulting bandwidth charges. The economies
of scale work best for these sites if a large proportion of the site is not likely to be
attacked at the same time, which is important to keep in mind given the model we
found in interviews of a single local expert managing many sites from a given area
Hal Roberts, Ethan Zuckerman, and John Palfrey
An alternative to increasing the server resources is to reduce the resource consumption of each page, allowing the server to handle more traffi c with the existing server
and network. There are some methods for reducing resource consumption that are
effective and have little cost, such as caching dynamic content to reduce database
queries. As attack size increases, though, an attacked site has to make changes that
have costly side effects, like disabling site functions that require expensive database
queries, reducing or eliminating images and streaming media, or creating an entirely
separate failover site with simpler and less-interactive content.
Another way to reduce resource consumption is to distinguish attacking traffi c from
legitimate user traffi c and fi lter out the attacking IP address. This approach is frequently used, and several of our meeting and interview participants reported success
with this method, but only when the number of attacking machines is small and relatively static. It is simple for a competent system administrator to fi nd and block a
hundred static IP addresses that are fl ooding a site with requests for a single page, but
that job becomes much, much more diffi cult when there are tens of thousands of IP
addresses that are rotating every couple of hours and actively trying to make their
traffi c look legitimate. In these cases, it is sometimes possible to fi lter attacking traffi c
based on a signature for the particular traffi c, but this approach can be very diffi cult
against a moderately skilled attacker even for a highly skilled defender. It is possible
to defend against a range of common attacks by using ModSecurity, an open-source
attack-fi ltering system. But this sort of fi ltering helps against generic attacks only, and
it uses up machine resources for the process of fi ltering and can therefore make the
site more vulnerable to traffi c-based attacks.
Finally, a site can protect itself by paying for a hosting or DDoS protection service
to serve the content of the Web site. There are many services capable of handling all
but the biggest attacks, and a few capable of handling the biggest observed attacks,
simply because they have suffi cient bandwidth and server resources to accept and
process the attack traffi c. The advantage of using such a service is that these services
have economies of scale both in learning how to defend against particular attacks and
in the necessary bandwidth and servers. When using such a service, the attacked site
needs to pay for the peak attack traffi c only while the attack is happening, rather than
paying for the entirety of the resources needed to handle peak attack traffi c.
These services, however, can command a very high markup on those resources.
Even without the high markup, simply paying for the bandwidth to handle the peak
attack traffi c can be prohibitively expensive, especially for an independent media site.
An attacked site may be able to hire a provider capable of handling millions of requests
per second but not be able to afford the resulting bandwidth charges. The economies
of scale work best for these sites if a large proportion of the site is not likely to be
attacked at the same time, which is important to keep in mind given the model we
found in interviews of a single local expert managing many sites from a given area
