ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Preventing DDoS attacks

Andrey Slastenov at Gcore describes how cyber-criminals are evolving their tactics for more potent DDoS attacks

 

The evolving nature of Distributed Denial of Service (DDoS) attacks is causing growing concern in the cyber-security realm. Threats are increasing in number and growing more complex and intense, necessitating more advanced security preparations for businesses.

 

This article examines the factors fuelling the rise of DDoS attacks, industry-specific vulnerabilities, and evolving tactics of cyber-criminals based on insights from Gcore’s expert analysis.

 

Why are DDoS attacks increasing?

The growth of IoT devices, easy access to hacking tools, and commercialisation of DDoS attacks (DDoS-as-a-service) have all contributed to the surge in DDoS attacks. The situation is further complicated by the growing number of motives behind these attacks, which now include corporate competition and political agendas in addition to simple mischief.

 

As businesses deal with these obstacles, understanding the evolving techniques and causes behind these cyber-attacks becomes critical for successful security planning.

 

DDoS trends

According to the Gcore Radar report from Q1 to Q2 2023 there have been several significant shifts in the DDoS landscape:

  • High-volume attacks: There’s been an alarming annual increase in the volume of DDoS attacks, making robust mitigation strategies essential for businesses: from 300 Gbps in 2021, it soared to 650 Gbps in 2022 and then to 800 Gbps in the first half of 2023.
  • Types of attacks: UDP flood attacks dominate, making up 52% of the total attacks we observed, followed by SYN flood and TCP flood attacks with 24% and 19%, respectively.
  • Industry focus: Gcore’s data identifies unique susceptibilities in gaming, telecom, and financial sectors:
    • The gaming industry is particularly prone to attacks due to its real-time services, leading to substantial financial losses and loss of clients.
    • Attacks on the telecom sector can trigger widespread outages affecting the telecom companies and a broad spectrum of other industries and consumers.
    • The financial sector, encompassing banks and financial technology (FinTech) companies, remains a high-value target due to its growing digital presence.
  •  Attack complexity: Attackers often now use adaptive strategies, like combining high-volume UDP attacks with numerous TCP packets and shifting from targeting the application layer to using small, high-volume packets.

 

The irony of success: Gcore under attack

Even though our aim to is help businesses understand cyber-security vulnerabilities, we are not immune to being attacked. 

 

Following the publication of our recent Radar report, our infrastructure and clients were quickly targeted by 854 diverse attacks of varying intensity and complexity within a week, the most potent peaking at 750 Gbps. The longest of these assaults stretched over 14 hours, and the most powerful reached an intensity of about 750 Gbps. Despite the onslaught, we repelled each attack due to the resilience of our security.

 

This surge in attacks post-report highlights the ongoing tug-of-war between cyber-security defences and attackers. Our real-world experience of defending against these cyber-criminals has added a layer of urgency to our protection against DDoS attacks. 

 

Fending off the DDoS menace

Understanding the changing landscape of DDoS attacks is critical, but so is taking action. A successful defensive plan for any organisation should combine evaluation, technical countermeasures, and continual monitoring to increase security.

 

Let’s look at the main points that will help businesses to harden their security posture.

 

Assessment and planning

Start with a security audit to find infrastructure weaknesses. After identifying these, create a comprehensive security policy with countermeasures and best practices.

 

Technical measures

Incorporate a multi-layered security approach combining physical, network, and software measures:

  • Regularly update software and apply secure patches as needed. 
  • Implement endpoint security measures, such as antivirus and antimalware solutions.
  • Employ firewalls and intrusion detection systems
  • Utilise robust encryption algorithms to safeguard sensitive data during storage and transmission.
  • Restrict physical access to servers and network components.
  • Adopt a zero-trust model that requires authentication at every network layer rather than just at the entry points.

Management and monitoring

Consider implementing an auditing or security information and event management (SIEM) system for real-time monitoring. That way, you can notice traffic spikes and take action immediately.

 

Education, analytics, and intelligence

Educate your staff on fundamental security principles and regularly simulate phishing attacks to test their awareness. A well-trained workforce is essential for effective cyber-security. Train your security team to spot the early warning signs of compromise.

Collaboration and partnerships

Connect with professional networks like Information Sharing and Analysis Centers (ISACs) to stay abreast of emerging threats and solutions and learn about attacks that could potentially target your organisation. Partnering with internet service providers can offer added layers of protection.

 

Consider a third-party IT solution

In addition to extensive knowledge of the subject, developing safe and robust infrastructure from scratch necessitates large sums and takes time. Consider adopting third-party security solutions if you lack the resources to construct your secure infrastructure.

 

A robust framework against DDoS

While these countermeasures provide a robust framework for enhancing your cyber-security posture against DDoS attacks, the evolving nature of threats requires specialised expertise, continuous monitoring, time to implement, and investments.

 


 

Andrey Slastenov is Head of Security at Gcore

 

Main image courtesy of iStockPhoto.com


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543