MichaelPeters.org

  • CRM
  • PMP
  • 0
  • 1
  • 2

MichaelPeters.org - Your Personal CXO, LLC

  • Your Personal CXO
  • The Policy Machine
  • Keynote
  • Company Store
  • Podcasting
  • HORSE Wiki
  • About Michael

Security Overlooked: Weathering the DDoS Storm

0

By Michael Peters on January 28th, 2013

Last year was a very high profile year for companies being attacked with distributed denial of service (DDoS) and this year doesn’t look any better. While there are some network layer based products, services and techniques available to companies, many of these are missing part of the solution.

The problem is that network layer approaches are really only applicable to network connections and perimeter equipment. The reality is that an exponential increase in attacks is targeting the application layer, particularly ones that require utilizing back-end database services. This clever tactic specifically targets web pages that make database queries such as an account login page for customers, as an example. The end results are bogged down servers that cannot keep up with the attack, let alone legitimate customers.

Tune and analyze

This type of attack typically goes unnoticed to most system and security administrators unfortunately. There are two approaches that I’d recommend utilizing to help weather the DDoS storm when it arrives.  First, performance tuning web servers, database servers and web applications is your first line of defense. If you consider that a denial of service attack only depletes the system resources you have making it impossible to serve legitimate customers, it makes perfect sense that tuning your operations for maximum performance will help reduce the threats DDoS pose to our companies.

The second tactic I’d recommend is routinely conducting web and database log analytic analysis. This is a task not only for web administrators, but security administrators alike. When you find log file anomalies indicating excessive connection requests by just a few source addresses or certain web pages with an inordinate amount of usage, these are likely signs of cyber-attacks and should be investigated.

Our take-away is that effective mitigation means diverse mitigation techniques involving governance processes, technology and vigilance by not only the security team, but the web administration team as well.

Stay secure my friends!

If you are interested in contacting us for more information about the content and services offered by Your Personal CXO, LLC or for media interview inquiries or aggregation requests, please use the following contact methods:

By phone: 1-762-822-4174
By email: retainme@yourpersonalcxo.com

Share this:

  • Email
  • Print
  • Digg
  • Google +1
  • LinkedIn
  • Twitter
  • Tumblr
  • Pinterest
  • Reddit
  • StumbleUpon
  • Facebook
  • CXO, Your Personal CISO
  • Search

  • Your Personal CXO

  • The Security Trifecta

    Hire the experts to implement The Security Trifecta in your organization. Click for more information!

  • Louisville Metro InfoSec

    The Louisville Metro InfoSec is the premier ISSA information security conference!

  • External Services

  • Thousands of other great people can't be wrong! Enter your email address to subscribe to this blog. -

  • Affiliates

  • RSS SBN RSS

    • SBN Sponsor Post
    • Untitled
    • Microsoft Rolls Out A Bug Bounty Program With A New Twist
    • IPv6: Looking Back on Year One
    • Can you afford not to keep up-to-date with business legislation (and end up smelling like a person after a 24 hour sea fishing trip)?
  • RSS The Register

    • BT boss QUITS telecoms giant for front-bench gov job
    • NASA probe eases through Saturn's ring to grab Earth snapshot
    • Ex-Systemax veep cuffed, charged with $230m fraud
    • Roving IT contractors and private landlords are my heroes - here's why
    • Wi-Fi Alliance takes grid place, revs engine in race to 802.11ac
  • Categories

    • Books
    • CXO
    • Featured
    • HORSE Project
    • HORSE Project V1
    • Kickback Cafe
    • Law
    • Lazarus Alliance
    • Life Learner
    • Obsolescence
    • Projects
    • Remember
    • Securing the C Level
    • Syndication
    • The Security Trifecta
    • Uncategorized
    • Your Personal CISO
  • Archives

    • March 2013
    • February 2013
    • January 2013
    • December 2012
    • November 2012
    • October 2012
    • September 2012
    • August 2012
    • July 2012
    • June 2012
    • May 2012
    • April 2012
    • March 2012
    • December 2011
    • November 2011
    • October 2011
    • September 2011
    • August 2011
    • July 2011
    • June 2011
    • May 2011
    • April 2011
    • March 2011
    • February 2011
    • January 2011
    • December 2010
    • November 2010
    • September 2010
    • August 2010
    • July 2010
    • June 2010
    • May 2010
    • April 2010
    • March 2010
    • February 2010
    • January 2010
    • December 2009
    • November 2009
    • October 2009
    • September 2009
    • August 2009
    • July 2009
    • June 2009
    • May 2009
    • April 2009
    • March 2009
    • February 2009
    • January 2009
    • December 2008
    • November 2008
    • October 2008
    • September 2008
    • August 2008
    • July 2008
    • May 2008
    • April 2008
    • January 2008
    • December 2007
    • July 2007
    • June 2007
    • May 2007
  • Get the app!

    Your Personal CXO now on Android!

  • Get the app!

    The HORSE Project now on Android!

  • Your Personal CXO
  • The Policy Machine
  • Keynote
  • Company Store
  • Podcasting
  • HORSE Wiki
  • About Michael

More on Your Personal CXO, LLC

  • EXTERNAL

    • AppHappening
    • CheckSavvy
    • Dynamic Clinical Systems
    • eLance
    • HORSE Project
    • Maprehend
    • Quest for Tech
  • Meta

    • Register
    • Log in
    • Entries RSS
  • Recent Posts

    • The Policy Machine
    • Top 1% Most Viewed LinkedIn Profile
    • Reasonable Duty of Care: Data Security and Privacy
    • Security Overlooked: Weathering the DDoS Storm
    • Please Vote for this blog!
  • Top Links

    • clouds (70)
    • No Title Given (57)
    • mba-mdp (47)
    • site (30)
    • peters-wgu-sbit-infosec (25)
    • CISSP-MDP-2013 (23)
    • An Introduction (21)
    • http://michaelpeters.org/?page_id=336 (21)
    • LinkedIn.com (19)
    • CMBA-MichaelPeters-2007 (17)

Copyright © 2013 MichaelPeters.org - MICHAELPETERS.ORG - Your Personal CXO, LLC

 
loading Cancel
Post was not sent - check your email addresses!
Email check failed, please try again
Sorry, your blog cannot share posts by email.