Knowledge Center
Your DDoS detection, protection and mitigation resource
DDoS attacks are constantly evolving so it's important to stay up-to-date on the latest trends, tools and techniques. Everything you need to know about how Prolexic approaches DDoS monitoring and mitigation is here in our Knowledge Center. See how other organizations are using our solutions by reading customer DDoS mitigation reports, learn from our DDoS protection experts with our DDoS protection planning white papers, track trends with our quarterly DDoS Attack Reports, and stay up to date on the latest DDoS alerts with our DDoS Threat Advisories.
ARCHIVES
Collateral
Read what makes Prolexic not just different, but also superior to all other providers of DDoS mitigation services
-
Prolexic Corporate Overview
English English - A4 Japanese - 日本語 Arabic - عربي Traditional Chinese - 中文 Spanish – Español Portuguese - português -
Service Overview: Monitoring: PLXfbm (Flow-Based Monitoring)
English English - A4 Spanish – Español Portuguese - português -
Service Overview: Monitoring: PLXabm (Application-Based Monitoring)
English English - A4 Spanish – Español Portuguese - português -
Service Overview: Mitigation: PLXrouted (Activation via route advertisement)
English English - A4 Spanish – Español Portuguese - português Traditional Chinese - 中文 Japanese - 日本語 -
Service Overview: Mitigation: PLXproxy (Activation via DNS redirect)
English English - A4 Spanish – Español Portuguese - português Traditional Chinese - 中文 Japanese - 日本語 -
Service Overview: Mitigation: PLXconnect
English Spanish – Español Portuguese - português Traditional Chinese - 中文 Japanese - 日本語
Darin Grey, Chief Technology Officer
Swiss Watch International
(worldofwatches.com)
Attack Reports
Quarterly attack reports are based on data collected during attacks against Prolexic's global customer base. As the world's leading DDoS mitigation provider, Prolexic is ideally positioned to collect valuable data on the origins, tactics, types, and targets of these attacks and identify emerging trends. Through data forensics and post attack analysis, Prolexic is able to build a global view of DDoS attacks.
Latest Attack Report
-
Q1 2013 – Giant attacks overwhelming appliances, ISPs, carriers, content delivery networks
Average attack bandwidth totaled 48.25 Gbps in Q1 2013, a 718 percent increase over last quarter, with an average packet-per-second rate of 32.4 Mpps.
Previous Attack Reports
-
Q4 2012 – Finance, e-Commerce and SaaS hit with 50+ Gbps attacks
Global DDoS Attack Report reveals the increasing scale and diversity of DDoS attacks in Q4 2012. And why it’s so hard to take down botnets like Itsoknoproblembro. -
Q3 2012 – Extremely large DDoS attacks become the new norm
Prolexic mitigated seven DDoS attacks with an average bitrate in excess of 20 Gbps. The United States joined China as the most prolific sources of DDoS denial of service attacks. -
Q2 2012 – Perpetrators attempt to maximize botnet longevity
Prolexic sees shorter denial of service DDoS attacks hit businesses of all types as hackers try to maximize botnet longevity and revenue while minimizing the risk of discovery. -
Q1 2012 - Financial services firms get hammered
Prolexic logged a significant increase in attack traffic directed at financial services clients. -
Q4 2011 - Attacks become more concentrated and damaging
Prolexic recorded a dramatic rise in packet-per-second volume this quarter and significant attack activity against e-Commerce businesses. -
Q3 2011 - DDoS attackers change strategies
Prolexic saw changing tactics where attackers were starting to target the DDoS mitigation infrastructure directly, specifically routers, most of which do not have the capacity to process high packets-per-second attacks.
Alan Conder, Chief Executive Officer
IPG International Limited
Case Studies
Airline/Hospitality
-
SpaFinder
Prolexic quickly stops a combination Layer 4 and Layer 7 DDoS attack after a hosting provider's mitigation capabilities fall short.
e-Commerce
-
PayPro Global
A Layer 7 DDoS attack by a disgruntled customer takes down a software e-commerce site. After 16 hours offline – and substantial loss of revenues – Prolexic gets PayPro online within minutes. -
World of Watches
Prolexic mitigates DDoS attack and keeps revenues ticking after bandwidth flood attack. -
Parts Geek
Prolexic stops DDoS Denial of Service campaign against popular e-Commerce web site after others fail. -
BidCactus
Hackers try to extort an auction site with a lethal Layer 3 DDoS attack. Prolexic restores the site in minutes and sends them packing. -
e-Commerce Printing
Prolexic mitigates two-week Layer 7 campaign against printed promotion items retailer. -
“Daily Deal” web site
When others couldn’t mitigate the latest DDoS attack this United Arab Emirates-based daily deal site, called Prolexic. Problem solved in 2 hours. -
Jewelry Designer
An encrypted Layer 7 attack took down the web site of a premier jewelry company for nearly three days until Prolexic brought it back online in less than an hour. -
Fragrance Retailer
A Layer 7 DDoS attack takes down the web site of a leading global retailer of women’s fragrances and beauty products. After 72 hours offline Prolexic gets the site back up within 5 minutes.
Financial Services
-
University Federal Credit Union
DDoS Attacks Against University Federal Credit Union End with Prolexic -
Henyep Capital Markets
Prolexic keeps Henyep accessible and trading through multiple SYN, GET and ICMP flood attacks and ransom demands. -
Entropay
Prolexic protects a leading provider of prepaid virtual Visa cards against DDoS attacks. -
Global eSolutions
A leading Trading Platform Provider chooses Prolexic for DDoS Protection. -
Online Options Trading
Prolexic helps financial services firm avoid extortion attempt by keeping web site available during vicious Layer 7 DDoS attack.
Media/Telecom
-
Clickpoint
Clickpoint! Media ensures reliability, predictability and customer ROI with Prolexic’s PLXproxy service -
AmericanEagle
Prolexic protects online revenues for Americaneagle.com and its high profile customers. -
SEEK
Prolexic ensures uptime for Seek.com.au and for millions of Australia’s job seekers. -
Spanish Media
Attack on Spanish-Language News site is abandoned when traffic routes to Prolexic. -
Krebs on Security
Prolexic fends off Pandora DNS amplification attacks for popular cyber security blog. -
Blogging Site
Prolexic defends blogging Web site against six-month DDoS attack campaign. -
VirtualRoad
Prolexic mitigates politically motivated Layer 7 attacks against web hosting company’s clients. -
RealVision
When hackers see this on-line media site’s IP addresses change to Prolexic they abandon DDoS attack. -
Yola
Prolexic mitigates Layer 4 UDP Flood against this web site hosting and building company, and now protects 6 million web sites against DDoS attacks. -
Content Rating Agency
A 9 million packets per second DDoS attack brings down web site before Prolexic steps in.
Non-Profit
-
Foundation Source
Prolexic mitigates a strong and widely distributed GET Flood after Sunday night emergency call.
Online Gaming
-
Betstar
Betstar Bets on Prolexic to keep online betting site incident-free -
Online Gaming Provider
Prolexic mitigates 9 Gbps DDoS attacks against Singapore-based online gaming provider with no interruption to service for its 500,000 concurrent users.
Public Sector and Government
-
Junta Central Electoral
Hacktivist group threatens to disrupt country’s election process, Prolexic successfully mitigates DDoS denial of service attack launched against their website on Election Day.
SaaS/Cloud
-
IPG Holdings
Prolexic mitigates Layer 7 GET floods targeting their payment processing platform.
Utilities
-
U.S. Metropolitan Utility
Prolexic defended this utility, whose automated bill payment system, website and external email were brought down by a cyber attacker.
Threat Advisories
Prolexic Threat Advisories provide insight into specific threats and attack signatures, while providing remediation and mitigation rules, as well as other technical steps you can take to defend against them. While some Threat Reports are published and made available free of charge, subscribers to this service receive early and unrestricted access to all Reports.
Latest Threat Advisories
-
Itsoknoproblembro (High)
This threat advisory includes profiles of 11 different attack signatures, with detailed SNORT rules for DDoS mitigation; detection rules to identify infected web servers (bRobots), and a free log analysis tool (BroLog.py) that can be used to pinpoint which scripts were accessed, by what IP address and for what DDoS targets, to aid sanitization efforts.
Previous Threat Advisories
-
Itsoknoproblembro (High)
-
Dirt Jumper Vulnerability Disclosure Report
-
Pandora[Medium Risk]
-
HULK [Medium Risk]
-
DDoS Booter Shell Scripts [High Risk]
-
High Orbit Ion Canon v2.1.003 [Medium Risk]
-
Dirt Jumper v3 [Medium Risk]
-
SNMP Amplification DDoS [High Risk]
-
Killapache.pl 1.0 [High Risk]
-
#RefRef ©Anonymous 2011 [Low Risk]
Senior Vice President, Top 20 Global Bank
White Papers
Prolexic publishes white papers for both business and technical audiences. Our Executive Suite Series papers are ideal for C-level executives (CEO, COO, CFO, CSO) that want to get up-to-speed quickly on DDoS threats, the business implications of DDoS attacks, and how to effectively defend against them. Our Technical Series papers provide a more in-depth look at DDoS mitigation and threats from an IT perspective. Technical Series papers are ideal for CIOs as well as IT and security managers.
Executive Suite Series White Papers
-
White Paper – The Broad Impact of DDoS: It’s More Than Just an IT Issue
Learn about the far-reaching affects of a DDoS attack, how to minimize the impact across your enterprise by developing a DDoS mitigation playbook, and how to evaluate DDoS mitigation service providers. -
White Paper – Planning for and Validating a DDoS Defense Strategy
Learn how to test your mitigation strategy and build an effective “play book” against DDoS attacks. -
White Paper - Strategies for Surviving a Cyber Attack this Holiday Season
It's your most lucrative season of the year – and a favorite of cyberattackers, too. In this whitepaper, learn how you can protect your business this season and thwart attacks that hurt your revenue and your reputation. -
DDoS Denial of Service Protection and the Cloud
Take advantage of cloud agility and time to market while remaining safe from DDoS attacks. Read how you can protect your cloud-based infrastructure and applications by using a cloud-based DDoS mitigation service. -
White Paper – Four Reasons Why DDoS Attackers Strike
This white paper explores why DDoS attackers strike and provides guidance on how to recognize the warning signs that a web site may be particularly vulnerable to attack. -
White Paper - Plan vs. Panic Making a DDoS Mitigation "Play Book" Part of Your Incident Response Plan
This white paper explores how to build a "play book" and why it is the foundation for an effective, controlled response in the event of a DDoS attack. -
White Paper - 'Tis the Season for DDoS Attacks
This white paper will help you plan for and deploy DDoS protection and tell you what you need to know to protect your e-Commerce business this holiday season. -
White Paper - The Executive's Guide to DDoS
This white paper will explore and define what a DDoS attack is, what impact it can have on a business, and how best to mitigate and prevent. -
White Paper – Human Security Mitigation vs. Automated Mitigation
This paper will explore the benefits of a DDoS mitigation approach that relies on real-time human interaction during an attack versus the use of automated (“black box”) mitigation and traffic analysis tools.
DrDoS Series
-
DrDoS Series Overview – Distributed Reflection Denial of Service (DrDoS) Attacks
An introduction to DrDoS attacks, an often overlooked DDoS attack method, and the potential security vulnerabilities that can expose you to DrDoS attacks. Each white paper in the series will include real-world case studies observed by PLXsert.
-
DrDoS Series White Paper – DNS Reflection Attacks
DNS server and IT administrators, get prepared by learning how cyber attackers use domain name (DNS) servers to reflect and amplify DDoS attacks to hit their ultimate target.
-
DrDoS Series White Paper – SNMP, NTP & CHARGEN Attacks
The network protocols SNMP, NTP and CHARGEN are being leveraged by cyber attackers. Even printers are at risk! Find out how to minimize your exposure and mitigate these attacks.
Technical Series White Papers
-
White Paper - Risk Rating Analysis of DDoS Attacks: How the integration of the MIDAS Scoring System with NIST CVSSv2 can improve DDoS risk assessment
This white paper outlines how to adapt the MIDAS scoring system and blend those results with the NIST CVSSv2 calculator for a more accurate risk rating analysis of DDoS threats.
-
White Paper - Firewalls: Limitations When Applied to DDoS Protection
What role does your firewall play in your DDoS mitigation strategy? This white paper helps you understand and define what your firewall can and cannot do for you.
-
White Paper - Twelve Questions to Ask a DDoS Mitigation Provider
Arm yourself with 12 powerful questions to ask any DDoS mitigation provider and ensure you’re getting the right protection for your business. -
White Paper - How to Defend Against DDoS Attacks: Strategies for the Network, Transport, and Application Layers
This white paper will explore a sampling of DDoS attack types and discuss the various strategies used to defend against them. It will also discuss the benefits of investing in dedicated DDoS mitigation services as a first line of defense to both discourage cyber threats and provide fast, reliable, and real-time mitigation when an attack occurs.
DDoS Dispatch
The DDoS Dispatch features all you need to know about current and future threats, as well as information on the latest protection techniques, events and trade shows, and other resources that can help you and your company.
Denise Vella, Information Security Officer
Ixaris Systems (EntroPay)
RECENT
PUBLICATIONS
-
Case Studies
-
University Federal Credit Union
DDoS Attacks Against University Federal Credit Union End with Prolexic -
White Papers
White Paper – The Broad Impact of DDoS: It’s More Than Just an IT Issue
Learn about the far-reaching affects of a DDoS attack, how to minimize the impact across your enterprise by developing a DDoS mitigation playbook, and how to evaluate DDoS mitigation service providers.
-
Attack Reports
Q1 2013 – Giant attacks overwhelming appliances, ISPs, carriers, content delivery networks
Average attack bandwidth totaled 48.25 Gbps in Q1 2013, a 718 percent increase over last quarter, with an average packet-per-second rate of 32.4 Mpps. -
Threat Advisories
Itsoknoproblembro (High)
The multi-tiered itsoknoproblembro DDoS toolkit is a critical threat that has been identified in a spate of damaging attacks against the banking, hosting and energy industries -
DDoS Dispatch
DDoS Dispatch Version 6DDoS Dispatch is published quarterly and provides news, interviews and best practice advice to prevent and mitigate DoS and DDoS attacks.