DDoS Attack – Preparation, Response, Mitigation

Data Management and Security (Hardware) Hardware DDoS Attack - Preparation, Response, Mitigation

Distributed Denial-of-Service (DDoS) attacks are evolving threats designed to disrupt service availability. This document outlines FLEX’s comprehensive plan for preparing for, responding to, and mitigating DDoS attacks, ensuring the resilience of the www.flexcutech.com system.

1. Preparation Checklist

Proactive measures are crucial for minimizing the impact of a DDoS attack. Implement the following steps to strengthen your system’s defenses:

  • Reduce Attack Surface:
    • Limit Internet-accessible resources and hosts.
    • Avoid running multiple critical services (e.g., DNS, WWW, VPN) on a single Internet-accessible host.
  • Reduce Attack Vectors:
    • Eliminate vulnerabilities in operating systems, software, and hardware through regular patching and secure configurations.
  • Establish External Contacts:
    • Contact ISPs (e.g., VIAWEST, XO, COMCAST) to discuss available DDoS mitigation options (both paid and free).
    • Establish clear communication channels with:
      • ISP
      • Law Enforcement
      • Managed Services Team
      • Network Operations Team
      • IT Security Team
    • Identify key personnel to be contacted during an attack and define communication processes.
  • Internal Coordination:
    • Set up and distribute details for a conference bridge to facilitate rapid communication among all involved parties during an incident.
  • Infrastructure Documentation:
    • Document your IT infrastructure thoroughly, including:
      • Business owners
      • IP addresses (public-facing and internal)
      • Circuit IDs
      • Services running on each IP address
  • Performance Baseline:
    • Determine a baseline of normal network performance to enable faster and more accurate identification of attack deviations.
  • Critical Service Identification & Failover:
    • Identify critical services that must remain operational during an attack.
    • Implement failover mechanisms for these essential services.
  • System Hardening:
    • Harden the configurations of network devices, operating systems, and applications that are potential targets for DDoS attacks.
  • DNS Time-to-Live (TTL) Settings:
    • Review DNS TTL settings for systems that may be attacked.
    • Lower TTLs if necessary to facilitate quick DNS redirection in case original IP addresses are compromised.

2. Response Procedures

When a DDoS attack is detected, follow these immediate response steps:

  • Executive Notification:
    • Promptly notify company executives about the ongoing attack.
  • Law Enforcement Contact:
    • Contact law enforcement if directed by executive-level authority.
  • Attacker Identification (if possible):
    • Attempt to identify the owners of the attacking IP addresses to potentially track down the primary attacking system.
    • Notify the ISP that owns the bot’s IP address.
  • Vendor Engagement:
    • Contact vendors of affected systems and equipment as needed, to assist with DDoS traffic management or evidence collection.

3. Mitigation Checklist

Implement the following mitigation strategies to counteract the DDoS attack and restore service:

  • Traffic Throttling/Blocking:
    • Attempt to throttle or block DDoS traffic as close to the network’s cloud as possible (e.g., via router, firewall, load balancer).
  • Process Termination:
    • Terminate unwanted or unneeded connections and processes on servers and routers.
  • Blackholing:
    • Blackhole DDoS traffic targeting the original IP addresses.
  • Hardware Augmentation (if possible):
    • If feasible, add network or server hardware to handle the increased DDoS load.
  • Traffic Scrubbing:
    • If possible, route traffic through a traffic-scrubbing service or product using DNS or routing changes.
  • Phased Defense Adjustments:
    • Adjust defense changes one at a time.
    • Document and observe the impact of each change.
  • Egress Filtering:
    • Configure egress (outbound) filters to block traffic that systems might send in response to DDoS traffic, preventing unnecessary load on the network.