Attack mitigation
Understand how DDoS Protection detects and mitigates attacks on every workload, the attack types it covers, and how to see and escalate an attack.
Attack traffic rarely looks different from real traffic one packet at a time. What gives it away is the pattern: a flow that grows far past its normal shape, packets that break a protocol, or connections opened and never finished. A defense therefore watches every flow continuously, recognizes those patterns, and discards the matching traffic before the service has to handle it.
On Azion, DDoS Protection is that defense for every workload. It is a Platform feature, always on, with nothing to create and nothing to configure. For where it acts on a request, ahead of the workload’s firewall, refer to How Workloads works. The sections below cover detection, mitigation, the attack types and techniques involved, the Security Response Team, and where attack records appear.
Detection
DDoS Protection detects an attack by inspecting the network flow of incoming traffic continuously, whether or not an attack is under way. Detection runs on Azion’s distributed infrastructure, so it sees traffic for a workload before that traffic reaches the workload.
Two families of algorithms do the inspection. Traffic analysis and signature algorithms recognize the traffic of known attacks and block it. Deep Packet Inspection (DPI) and artificial intelligence (AI) algorithms look for abnormal traffic behavior instead, which reduces false positives: traffic that is unusual but legitimate is less likely to be blocked. Azion’s software-defined networking (SDN) practices add real-time packet analysis and traffic anomaly detection, which also catch attacks such as Border Gateway Protocol (BGP) hijacking.
Detection also follows each application layer of the resources Azion delivers through Firewall and WAF. The algorithms are built for automated mitigation, so a detected attack is mitigated without anyone acting on an alert. Azion states that DDoS Protection detects and mitigates attacks in under 3 seconds on average. That figure is an average across attacks, not a ceiling for each one.
Mitigation
DDoS Protection mitigates attacks at four layers of the OSI model: the network layer (3), the transport layer (4), the presentation layer (6), and the application layer (7). Traffic identified as an attack is blocked, and the rest continues to the workload. Azion carries out the mitigation, and it does not add latency to the traffic that continues.
Azion’s distributed infrastructure connects to distributed scrubbing centers, so attack traffic is mitigated as close as possible to where it originates. Azion takes part in the Mutually Agreed Norms for Routing Security (MANRS) initiative of the Internet Society. It applies strict AS-path filters and verifies both customer and internal network advertisements, which prevents IP spoofing.
The same protection reaches more than HTTP. DDoS Protection also protects your Domain Name System (DNS) service. For how Azion serves DNS, refer to Edge DNS. Other TCP and UDP applications, once encapsulated in HTTP, receive the same level of protection through a reverse proxy.
Because mitigation needs no configuration, a workload is protected from the moment it exists, and there is nothing for you to tune. The cost is that the automatic defense is the same for every workload. For detection and mitigation targeted at a specific attack, you write custom rules on a firewall bound to the workload. For layer 7 attacks, WAF on that firewall strengthens the protection further.
Attack types
DDoS attacks fall into two classes:
- Volume-based attacks, also called flood attacks, create large amounts of traffic to overload a system. They use amplification, or requests from malware and worms, and a botnet can coordinate them.
- Protocol attacks, also called state exhaustion attacks, exploit weaknesses in network resources. They overload the processing of critical services and infrastructure, such as security and load balancing.
The attacks Azion mitigates include the following. The list is not exhaustive:
- Bogons
- Botnet attacks
- Brute force attacks
- CLDAP amplification
- Connection flood attacks
- DNS flood, including well-formed DNS queries
- HTTP floods, including well-formed HTTP
POSTandGETURL requests - HTTP slow reads
- ICMP flood
- IGMP flood
- IP bogons
- IP fragmentation
- Low and slow attacks
- Malformed ICMP flood, also called ping of death
- Mixed floods, such as TCP plus UDP and ICMP plus UDP
- Nuke
- NTP amplification
- OWASP Top 10
- Reflected ICMP and UDP
- SSDP amplification
- Slowloris
- Smurf
- Spoofing
- TCP ACK flood
- TCP ACK-PSH flood
- TCP SYN-ACK flood
- TCP FIN flood
- TCP out-of-state flood
- TCP RESET flood
- TCP SYN flood
- TCP fragmentation
- TCP invalid
- Teardrop
- UDP flood
- Zero-day attacks
The detection and mitigation techniques Azion employs include the following:
- Allowlists, blocklists, and greylists.
- Blocking, redirecting, or dropping requests by HTTP headers and geolocation.
- Blocking, redirecting, or dropping requests by reputation and network lists.
- Lists of botnets, cloud providers, malware, and proxies.
- Bot mitigation and management techniques.
- Challenge-response techniques.
- CAPTCHA and reCAPTCHA to identify human users.
- Cookie tampering.
- Dynamic IP reputation, fingerprints, and IP address plus user agent.
- Fingerprinting.
- HTTP redirect.
- Discarding malformed packets.
- Restricting origin access to Azion IP addresses only.
- Pattern analysis and anomaly detection.
- Score-based blocking.
- Security tokens, such as JWT.
- Session timeout.
- Signature-based and fingerprint-based blocking.
- Simple rate limiting, which is local, and advanced rate limiting, which is global and contextual.
- Standby rules, used in response to incidents as they happen.
- Techniques that prevent brute force attacks.
Security Response Team
Azion prioritizes developing algorithms that detect and block attacks automatically. Once a threat is identified, the Azion Security Response Team (SRT) tracks it end to end. The SRT can apply custom rules on Firewall to mitigate sophisticated attacks at the network, transport, presentation, and application layers.
You can engage the SRT during an attack, after one, or before one to build custom rules in advance. During or after an attack, the SRT helps track the incident, find its root cause, and put solutions in place with your team. Afterward, it gives you access to post-event analysis and investigations.
The SRT is contracted in addition to an Enterprise or Mission-Critical support plan. To engage it, contact the Azion sales team. For the support plans and the bounds of DDoS Protection, refer to Workloads limits.
Attack visibility
DDoS Protection mitigates attacks without any action from you, so the records of an attack are how you learn that one happened.
Azion Console and the Azion API show the volume of attacks against your applications. For attack records and monitoring, use Real-Time Events or Real-Time Metrics. To keep the records in your own systems, Data Stream connectors send events to Security Information and Event Management (SIEM) and big data services.