NEWS & EVENTS

Prolexic Mitigates DDoS Attack Against U.S. Utility Company

March 07, 2013

 

Attackers now targeting network infrastructures that cause collateral damage

HOLLYWOOD, FL – (March 7, 2013) – Prolexic, the global leader in Distributed Denial of Service (DDoS) protection services, announced today that it mitigated an attack against a U.S. metropolitan utility company earlier this month. The utility, which provides services to an estimated more than 1 million customers, has engaged Prolexic to provide DDoS protection services.

The utility company’s website, online payment system and automated pay-by-phone billing system were brought down for 48 hours by a combination Layer 4 DDoS attack. During that time, customers could not pay bills online or by phone. In addition, employees could not receive external e-mails.

“Utilities is another vertical market that is likely to be victimized in the coming months as attackers look beyond daily targets like e-Commerce and financial services,” says Stuart Scholly, president at Prolexic. “Attackers are targeting network infrastructures to cause collateral damage to other shared resources, so organizations must think about their different areas of vulnerability beyond website URLs.”

The DDoS attack, which Prolexic identified as originating in the U.S., was highly sophisticated and particularly difficult for the utility company’s IT department to detect and mitigate because the attack directly targeted the back-end IP addresses of the utility’s Internet-facing network. On the second day of the attack, Prolexic was engaged by the utility to take emergency action to mitigate the distributed denial of service attack.

Prolexic’s DDoS mitigation engineers quickly determined that the attackers were targeting backend IPs directly. They developed and launched a specially crafted routed DDoS defense that immediately began to reduce the strength of the hackers’ sophisticated attack on the back-end IPs. Prolexic mitigation engineers continued to fight the distributed denial of service attack and quickly adjusted defense strategies as the attackers changed their attack signatures. The Layer 4 attack peaked at 3.3 Gbps and 5.7Mpps (packets-per-second).

“Once traffic was on-ramped to Prolexic, the DDoS attack was mitigated in a matter of minutes and all services were restored to our website and automated pay-by-phone system,” said a representative of the utility company. “Prolexic quickly ended what could have been a devastating blow to our customer service and our reputation for reliable service.”

“Prolexic considers every DDoS attack to be zero-day and we have designed our mitigation infrastructure so we can respond accordingly,” said Scholly. “As a result, clients can be confident that Prolexic’s proxy or routed solutions can provide 100 percent protection against all distributed denial of service attacks.”

The case study about this utility is available to the public, free of charge, at www.prolexic.com/utility-case-study.

About Prolexic

Prolexic is the world’s largest, most trusted Distributed Denial of Service (DDoS) mitigation provider. Able to absorb the largest and most complex attacks ever launched, Prolexic restores mission-critical Internet-facing infrastructures for global enterprises and government agencies within minutes. Ten of the world’s largest banks and the leading companies in e-Commerce, SaaS, payment processing, travel/hospitality, gaming and other at-risk industries rely on Prolexic to protect their businesses. Founded in 2003 as the world’s first in-the-cloud DDoS mitigation platform, Prolexic is headquartered in Hollywood, Florida and has scrubbing centers located in the Americas, Europe and Asia. To learn more about how Prolexic can stop DDoS attacks and protect your business, please visit www.prolexic.com, follow us on LinkedIn, Facebook, Google+, YouTube, and @Prolexic on Twitter.

###

Contact:

Michael E. Donner
SVP, Chief Marketing Officer
Prolexic
media@prolexic.com
+1 (954) 620 6017

Announcements
  • Q1 2015 State of the Internet - Security Report

    Number of DDoS attacks double vs. Q1 2014

    LEARN MORE >>
  • The Cost of Denial-of-Services Attacks

    Free report from The Ponemon Institute

    LEARN MORE >>
  • Web Application Firewalls: The TCO Question

    Analyst white paper

    LEARN MORE >>
  • Threat: Joomla Reflection DDoS-for-Hire

    Compromised Joomla servers used for DDoS GET floods

    LEARN MORE >>
  • Frost & Sullivan Stratecast Report

    “Going to the Edge with Security”

    LEARN MORE >>
  • Threat: MS SQL Reflection Attacks

    DDoS attack abuses MC-SQLR in SQL Server instances

    LEARN MORE >>
  • Q4 2014 State of the Internet - Security Report

    Number of DDoS attacks nearly doubles in a year

    LEARN MORE >>