Hiding in Google’s Cloud From DDoS Cyber Attacks

Written by Pronetic

Pronetic is a leading provider of core IT support for ISO 27001, Cyber Essentials and Cyber Essentials Plus compliance.

March 4, 2016

In the world of cyber crime, one method that is on the increase is the DDoS or ‘Distributed Denial of Service’ attack in which the perpetrator uses multiple compromised systems (that are often infected with a Trojan virus) to launch a single attack on one system.

The result is to overwhelm that system rendering it unavailable. You may have read of an attack recently that used a Pingback feature loophole to leverage 26,000 WordPress websites to launch a DDoS.

Similar high profile attacks have been launched on Xbox Live and PlayStation Network gaming and one of the main reasons why these attacks have become so popular among cyber criminals is that they can inflict large scale damage for minimal cost, while minimising the risk of being detected. It is estimates that a DDoS attack can cost the criminal around £30 to execute (presumably excluding labour costs) and it can be ordered anonymously.

For the business that is the focus of the attack the results can not only be the temporary disruption, but the fallout from that disruption which can include lost customers, bad press and damage to reputation.

In monetary terms estimates of the average cost of this kind of attack to a business is around the £300,000 mark.

Google To The Rescue – (Mainly For News Sites)

In the light of the increasing risks of DDoS attacks, those who run news, human rights or elections sites which host “free expression” content can gain some comfort from the fact that Google is now offering protection in the safety of its Cloud as part of what it is calling “Project Shield”. The free service is inviting applications through its website https://projectshield.withgoogle.com/public/ .

According to Google’s Project Shield, if the online application is approved the successful webmaster will be emailed the configuration instructions, and provided they have administrative privileges for the website, and they can modify DNS records, protection for DDoS attacks for their website can be set up in as little as 10 minutes.

How It Works

Google’s Project Shield uses a technology known as “reverse proxy” to route a website’s traffic through Google’s infrastructure (Google Cloud Platform), whereby “illegitimate traffic” can be stopped from reaching the server.

Google suggests that the service is akin to “a train conductor only letting ticketed passengers aboard”.

Although it is unlikely to noticeably affect a website’s performance, users from countries where Google’s IP addresses are blocked will not be able to access the content served through Project Shield.

Next stop … a paid service from Google … for regular business users?

You May Also Like…

0 Comments

Why Choose Pronetic

We Are ISO 27001 & Cyber Essentials Plus Certified

Be reassured that we have been externally audited. You can have complete peace of mind that the team managing your IT systems and safeguarding your data are independently vetted annually.

Seamless & Comprehensive IT Support

Our investment in people, tools and processes, continuously improved, ensures that we don’t just deliver exceptional I.T. support but include your compliance to Cyber Essentials or ISO 27001 “baked-in”. Yes, that means no more annual headaches and stress when your certification comes round.

Expert Support Money Back Guarantee

We're confident in the value we deliver. That's why we offer a 90-day, no-quibble money-back guarantee. If, for any reason, you're not completely satisfied with our IT support services, we'll provide a full refund and cancel your contract without any hassle.

Book Your Free IT Strategy Call Now!

Simply Fill In The Form Below To Receive Your Free IT Strategy Call:

By submitting this form, you consent to us using your personal information to contact you. For more information please see our privacy policy.