Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Network Security

Businesses Not Prepared for DDoS Attacks and DNS Failures, Study Shows

Most organizations aren’t prepared to prevent and respond to web infrastructure failures caused by distributed denial of service (DDoS) attacks and Domain Name System (DNS) failures. These conclusions came from two studies commissioned by VeriSign that show the urgent need for robust DDoS protection, reliable and secure DNS infrastructure, and advanced threat intelligence.

Most organizations aren’t prepared to prevent and respond to web infrastructure failures caused by distributed denial of service (DDoS) attacks and Domain Name System (DNS) failures. These conclusions came from two studies commissioned by VeriSign that show the urgent need for robust DDoS protection, reliable and secure DNS infrastructure, and advanced threat intelligence.

Verisign commissioned a market research report from Merrill Research to investigate the level of concern IT decision makers have with the growing threat of DDoS attacks in today’s ever evolving cyber landscape. An online survey of 225 IT decision-makers in the U.S. from large and medium-sized businesses revealed that 78 percent are extremely or very concerned about DDoS attacks, and more than two-thirds (67 percent) expect the frequency and strength of DDoS attacks to increase or stay the same over the next two years. Nearly nine in 10 respondents (87 percent) view DDoS protection as very important for maintaining availability of websites and services. Additionally, 7 in 10 (71 percent) respondents who reported a lack of DDoS protection said they plan on implementing a solution in the next 12 months.

Research Highlights:

• DDoS attacks are widespread: Nearly two-thirds (63 percent) of respondents who reported experiencing a DDoS attack in the past year said they sustained more than one attack. Eleven percent were hit six or more times.

• More sites will soon be protected: Of the respondents who currently lack DDoS protection, 71 percent plan to implement a solution in the next 12 months — 40 percent plan to outsource their DDoS protection, 31 percent plan to implement an in-house solution, and 29 percent are still undecided on their approach for protection.

• Leaving web infrastructures unprotected is too risky: More than half (53 percent) of the respondents said they experienced downtime in the past year, with DDoS attacks accounting for one-third (33 percent) of all downtime incidents.

• Downtime impacts customers and revenue: More than two-thirds (67 percent) said their downtime impacted customers and half (51 percent) reported they lost revenue. Considering 60 percent of the respondents rely on their websites for at least 25 percent of their annual revenue, downtime can have significant and lasting impacts.

• Threats extend beyond DDoS attacks: The study also found that nine in 10 respondents rate “access to threat and vulnerability data” as very important and nearly three-fourths (73 percent) are “concerned with DNS failures” — suggesting a significant need for ongoing threat intelligence and managed DNS services, in addition to DDoS protection and mitigation.

Advertisement. Scroll to continue reading.

• DNS Availability Lower for Internally Managed Sites – A separate study commissioned by Verisign sheds light on the need for solutions that ensure DNS availability — a crucial requirement for the reliable operation of websites, network services, and online communications. The study found that in the first quarter of 2011, DNS availability was a problem for even the highest ranked e-commerce sites.

Related Resource: Understanding Web Application Security – Defending the Enterprise’s New Porous Perimeter

Using proprietary technology, ThousandEyes, a company that provides application performance analytics, calculated the minimum availability, maximum availability, and average availability of the Alexa 1,000 websites in the first quarter of 2011 to illustrate the state of global DNS availability.

The research revealed some stark differences between sites with internally managed DNS and those that employ third-party managed DNS services. In particular, the study revealed that minimum DNS availability on average dropped to 90.13 percent for sites that host their own DNS, while sites using third-party managed DNS services averaged a minimum DNS availability rate of more than 98 percent. When examining minimum availability overall, the research showed that some sites with internally managed DNS had total outages, while sites with third-party DNS management never went below 50 percent availability. Similarly, average downtime for sites that host their own DNS is twice that of those that use a third party (99.7 percent versus 99.85 percent).

A separate study released by Arbor Networks earlier this year, showed that 2010 should be viewed as the year distributed denial of service (DDoS) attacks became mainstream. In its Sixth Annual Worldwide Infrastructure Security Report, Arbor Networks revealed that DDoS attack Size broke 100 Gbps for first time; up 1000% Since 2005. 2010 also witnessed a sharp escalation in the scale and frequency of DDoS attack activity on the Internet with many high profile attacks launched against popular Internet services and other well known targets. In addition to hitting the 100 Gbps attack barrier for the first time, application layer attacks hit an all-time high.

Written By

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Cody Barrow has been appointed as CEO of threat intelligence company EclecticIQ.

Shay Mowlem has been named CMO of runtime and application security company Contrast Security.

Attack detection firm Vectra AI has appointed Jeff Reed to the newly created role of Chief Product Officer.

More People On The Move

Expert Insights

Related Content

Identity & Access

Zero trust is not a replacement for identity and access management (IAM), but is the extension of IAM principles from people to everyone and...

Artificial Intelligence

ChatGPT is increasingly integrated into cybersecurity products and services as the industry is testing its capabilities and limitations.

Cybersecurity Funding

Network security provider Corsa Security last week announced that it has raised $10 million from Roadmap Capital. To date, the company has raised $50...

Compliance

Government agencies in the United States have made progress in the implementation of the DMARC standard in response to a Department of Homeland Security...

Network Security

Attack surface management is nothing short of a complete methodology for providing effective cybersecurity. It doesn’t seek to protect everything, but concentrates on areas...

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Network Security

A zero-day vulnerability named HTTP/2 Rapid Reset has been exploited to launch some of the largest DDoS attacks in history.