Menu

Call us on 03450 21 21 51

What is a DDoS attack and why should you be prepared for one this month?
The SRM Blog

What is a DDoS attack and why should you be prepared for one this month?

Ian Armstrong

Written by Ian Armstrong

19th November 2020

Share this article

DDoS attack

As we approach Black Friday and Cyber Monday, there is good news…and bad news.

First the good news. Retailers are preparing for some pretty intense activity around Friday 27th and Monday 30th November this year. About £6 billion worth of goods, it is estimated by Finder.com, will be bought in the UK over Black Friday and Cyber Monday 2020.

As we find ourselves in the midst of Lockdown 2.0, it is inevitable that the vast majority of purchases through the Black Friday weekend are likely to be made online. That is an awful lot of website traffic over just a few days and experts predict that this year may well break records. Unfortunately, it’s not the only record likely to be set this year.

Which brings us to the bad news, and the main subject of this article – the threat of a DDoS attack.

Why should you be prepared for a DDoS attack this November?

The surge in web traffic through e-commerce stores represents a significant opportunity for cybercriminals, who are expected to be more active than ever this month. And one of the most popular attack techniques likely to be seen is a Distributed Denial of Service (DDoS) attacks – meaning that hackers will deliberately bombard websites with high levels of artificial traffic. With many sites already stretched to their limits because of the increase in authentic users, the result of this heavy load is likely to be that the websites ultimately crash and becomes unable to accept transactions.

Imagine that: all those customers, ready and willing to spend, but unable to access your website. Sadly, the risk is very real.

Even before the Covid-19 pandemic accelerated the shift to online shopping, DDoS attacks have been on the rise. In 2019, Black Friday saw a 70% increase in DDoS attacks and Cyber Monday saw a rise of 109% compared to the average for the rest of the month. These were not limited to large companies but affected businesses of all sizes.

But it’s not just a question of the number of DDoS attacks; there has also been an increase in their size.

DDoS attacks can be gauged by Gbps, which measures bandwidth on a digital data transmission by billions of bits per second. Attacks of around 6 Gbps are more than sufficient to exceed the capacity of most websites, but over Black Friday and Cyber Monday 2019 there was a huge increase in the number of attacks with levels of up to 100 Gbps.

In fact, as far back as the first quarter of 2019, large-scale DDoS attacks had increased exponentially, with those exceeding 100Gbps growing by a phenomenal 967% compared to the same period of 2018. Even global corporations such as Airbnb, Netflix and PayPal have been found to be susceptible to DDoS attacks in the past.

Then along came the Covid-19 pandemic and the rapid increase in remote working. In this period the volume of DDoS attacks has continued on an upward trajectory. It therefore looks likely that Black Friday and Cyber Monday 2020 will set a new record for DDoS attacks, both in terms of volume and scale.

Although this is alarming news, it is not too late to make some changes to improve business resilience. To do this, however, you need to understand fully what you are up against.

Understanding a Distributed Denial of Service (DDoS) attack

A DDoS attack is now one of the most common types of cyber-attack; more common than phishing. Hackers typically use an army of connected devices, botnets, which are infected with malware. These botnets overload and exhaust your website’s server and exhaust it of its available bandwidth. The result is that the website is unable to operate, rendering it unavailable to users.

What is particularly concerning is that, in many instances, the attack does not actually breach security parameters and is not discovered until too late. Attacks may last for many hours, providing hackers with plenty of time to cause damage before the attack is discovered.

The motives for a DDoS can vary. In some cases, the cybercriminal is looking to disrupt a website in order to hold a company to ransom; in others, it might simply be a case of an individual looking to cause trouble out of pure mischief and a desire to “win” a victory against the defences of an organisation. This is not the only motivation, however. Recent surveys suggest that between 12% and 50% of businesses believed that a DDoS attack was initiated by their competition. While it is, of course, difficult to verify these types of claim, it is nevertheless disturbing to think that another organisation might look to cause damage to gain an unfair advantage.

Whatever the driver, a continuous DDoS attack can bring down clusters of sites and, if timed well, around a peak selling period, can have catastrophic consequences for the bottom line of the affected businesses. And, of course, it’s not just customers who are affected. A DDoS attack will deny access to employees, members or account holder, too.

What are the early signs of DDoS attack?

Before the system crashes completely, there are several indicators that a DDoS attack may be in progress. These usually indicate a compromised server, typically in the form of slow access to local and remote files, the inability to access websites, the loss of internet connection and a significant increase in the number of spam emails.

What steps can be taken to reduce the impact of a DDoS attack?

Unfortunately, no one is entirely immune to a DDoS attack. In fact, a DDoS attack is a realistic threat that can challenge organisations of any size. However, there are a number of steps that can be taken to reduce the likelihood of a DDoS attack and present a strong response in the event of such a threat.

Structured security protocols like PCI DSS compliance and Cyber Essentials will be beneficial, but not sufficient on their own. An additional Denial of Service plan which includes a range of mitigating strategies to secure your network infrastructure, is required. It may include multiple layers of protection, including the implementation of a Web Application Firewall (WAF), the use of a virtual private networks (VPN) in addition to anti-spam, content filtering and load balancing.

At this time of year, business continuity is of vital importance. A managed security service provides businesses of all sizes with expert cost-effective guidance on DDoS attack protection. Ultimately this will ensure that any DDoS attack is countered by a resilient and effective plan and can, ultimately, give retailers peace of mind in the days ahead.

Get in touch with the team at SRM today to find out how we can help you protect against DDoS attacks. Call us on 03450 21 21 51 or click here to fill out our contact form.