What Is a DDOS Attack and How Do We Respond

<  Blog Home
October 15 2018
October 15 2018
By

The internet is a lot like the wildwest—it operates on trust with very little oversight and no policing, everyone has to look out for themselves. Which makes it very easy for bad actors to anonymously disrupt a website if they want to. One of the most common and difficult types of attacks to respond to is a DDOS (Distributed Denial of Service). This type of attack isn't necessarily a security vulnerability, but it does cause a "Denial of Service" when so much traffic comes to your web server that it is not able to serve real visitors. And the attack is "Distributed" because the traffic looks like it is coming from random legitimate visitors (IP address spoofing). This type of attack can come from a bored teenager or a sophisticated criminal network that has a "botnet" (thousands of hacked computers that are harnessed to carry out the attack at a greater volume).

Prevention Options

Preventing sophisticated DDOS attacks is impossible. Because the internet is based on trust, there is no way to determine which traffic is legitimate and which is fake. There are only a few options, and none of them are great.

Block Traffic

You can easily block all traffic that fits a certain pattern that looks suspicious, but in the process you will also probably block some legitimate traffic. For example, many DDOS attacks pretend to be search engine bots (from Google, Bing, and every other service out there). So if you block these IP addresses or bot names, you are actually blocking Google's search indexing too.

Increase Server Power

Depending on the resources of the attacker, you can increase your server capacity so that it can handle the extra traffic and still serve real visitors. The hope here is that your attacker will exhaust their resources before you exhaust yours. Huge companies like Google are less vulnerable to small recreational attackers, but even their services get overwhelmed sometimes. So if an attacker has the resources, they can even take down the biggest targets.

Finding the Balance

Our strategy is to try to find a balance. We want to make sure our servers can handle spikes in traffic, but at some point it becomes necessary to also block suspsicious traffic. Unfortunately, that sometimes means temporarily blocking legitimate traffic including search engine bots. But we'd rather the majority of visitors are able to access your site (even if search engines can't refresh their index), versus no one having access because the server is overwhelmed by the DDOS attack.

We monitor these attacks and have to continually manually modify our response. Often times though, the attackers will keep sending small pings to our server, and as soon as they detect we've removed our ban on their bots, they immediately start attacking again. So it's ultimately a waiting game, we have to wait until they move on to another target.

We wish there was a better way to respond, but unfortunately there is not. We can work to keep the server up and ensure that the servers remain secure. But if someone wants to randomly attack your site or the server your site is running on, there is only so much that the internet protocols allow us to do.

Tags : ddos, server, bots,


Archives

June 10, 2022

Common Questions about Migrating Your Website from 1.0 to 2.0

Common Questions about Migrating Your Website from 1.0 to 2.0
Your website on the retro 1.0 version of our platform will continue to function until at least June 2023, and after that we will keep the old platform working as long as is necessary/reasonable to ...
June 06, 2022

Upgrade Your Old Website to Prevent Lawsuits and Improve Marketing

Upgrade Your Old Website to Prevent Lawsuits and Improve Marketing
Over the last few years, we have been working on the overly ambitious project of rebuilding our Website Builder and Content Management System based on modern coding standards, cutting edge design, ...
June 10, 2022

The New Gutensite Website is Live on Our New Platform!

The New Gutensite Website is Live on Our New Platform!
Did you notice we just launched a new version of our website? Go to https://gutensite.com to see what's new. Look around and imagine how your business could be helped if we transformed your website ...
October 06, 2021

ADA Compliance and Website Accessibility Standards

ADA Compliance and Website Accessibility Standards
Chadwick Meyer
In the last few months clients have had a growing paranoia about a growing number of ADA lawsuits (Americans with Disabilities Act) for website accessability. There have been reports of "serial ...
September , 2021

New IDX Widget Going Live for Everyone

Chadwick Meyer
As part of our ongoing efforts to improve our system and also stay up to date with the changing technology requirements of each MLS, we have created an entirely new IDX Widget that was released to ...

2022 Archives

Jan Feb Mar Apr
May Jun Jul Aug
Sep Oct Nov Dec

2021 Archives

Jan Feb Mar Apr
May Jun Jul Aug
Sep Oct Nov Dec

2020 Archives

Jan Feb Mar Apr
May Jun Jul Aug
Sep Oct Nov Dec

2019 Archives

Jan Feb Mar Apr
May Jun Jul Aug
Sep Oct Nov Dec

2018 Archives

Jan Feb Mar Apr
May Jun Jul Aug
Sep Oct Nov Dec

2017 Archives

Jan Feb Mar Apr
May Jun Jul Aug
Sep Oct Nov Dec

2016 Archives

Jan Feb Mar Apr
May Jun Jul Aug
Sep Oct Nov Dec

2015 Archives

Jan Feb Mar Apr
May Jun Jul Aug
Sep Oct Nov Dec

2014 Archives

Jan Feb Mar Apr
May Jun Jul Aug
Sep Oct Nov Dec

2013 Archives

Jan Feb Mar Apr
May Jun Jul Aug
Sep Oct Nov Dec

2012 Archives

Jan Feb Mar Apr
May Jun Jul Aug
Sep Oct Nov Dec

2011 Archives

Jan Feb Mar Apr
May Jun Jul Aug
Sep Oct Nov Dec

2010 Archives

Jan Feb Mar Apr
May Jun Jul Aug
Sep Oct Nov Dec

2009 Archives

Jan Feb Mar Apr
May Jun Jul Aug
Sep Oct Nov Dec

2008 Archives

Jan Feb Mar Apr
May Jun Jul Aug
Sep Oct Nov Dec