NEWS & EVENTS
Prolexic Mitigates DDoS Attack Against U.S. Utility Company
March 07, 2013
Attackers now targeting network infrastructures that cause collateral damage
HOLLYWOOD, FL – (March 7, 2013) – Prolexic, the global leader in Distributed Denial of Service (DDoS) protection services, announced today that it mitigated an attack against a U.S. metropolitan utility company earlier this month. The utility, which provides services to an estimated more than 1 million customers, has engaged Prolexic to provide DDoS protection services.
The utility company’s website, online payment system and automated pay-by-phone billing system were brought down for 48 hours by a combination Layer 4 DDoS attack. During that time, customers could not pay bills online or by phone. In addition, employees could not receive external e-mails.
“Utilities is another vertical market that is likely to be victimized in the coming months as attackers look beyond daily targets like e-Commerce and financial services,” says Stuart Scholly, president at Prolexic. “Attackers are targeting network infrastructures to cause collateral damage to other shared resources, so organizations must think about their different areas of vulnerability beyond website URLs.”
The DDoS attack, which Prolexic identified as originating in the U.S., was highly sophisticated and particularly difficult for the utility company’s IT department to detect and mitigate because the attack directly targeted the back-end IP addresses of the utility’s Internet-facing network. On the second day of the attack, Prolexic was engaged by the utility to take emergency action to mitigate the distributed denial of service attack.
Prolexic’s DDoS mitigation engineers quickly determined that the attackers were targeting backend IPs directly. They developed and launched a specially crafted routed DDoS defense that immediately began to reduce the strength of the hackers’ sophisticated attack on the back-end IPs. Prolexic mitigation engineers continued to fight the distributed denial of service attack and quickly adjusted defense strategies as the attackers changed their attack signatures. The Layer 4 attack peaked at 3.3 Gbps and 5.7Mpps (packets-per-second).
“Once traffic was on-ramped to Prolexic, the DDoS attack was mitigated in a matter of minutes and all services were restored to our website and automated pay-by-phone system,” said a representative of the utility company. “Prolexic quickly ended what could have been a devastating blow to our customer service and our reputation for reliable service.”
“Prolexic considers every DDoS attack to be zero-day and we have designed our mitigation infrastructure so we can respond accordingly,” said Scholly. “As a result, clients can be confident that Prolexic’s proxy or routed solutions can provide 100 percent protection against all distributed denial of service attacks.”
The case study about this utility is available to the public, free of charge, at www.prolexic.com/utility-case-study.
Prolexic is the world’s largest, most trusted Distributed Denial of Service (DDoS) mitigation provider. Able to absorb the largest and most complex attacks ever launched, Prolexic restores mission-critical Internet-facing infrastructures for global enterprises and government agencies within minutes. Ten of the world’s largest banks and the leading companies in e-Commerce, SaaS, payment processing, travel/hospitality, gaming and other at-risk industries rely on Prolexic to protect their businesses. Founded in 2003 as the world’s first in-the-cloud DDoS mitigation platform, Prolexic is headquartered in Hollywood, Florida and has scrubbing centers located in the Americas, Europe and Asia. To learn more about how Prolexic can stop DDoS attacks and protect your business, please visit www.prolexic.com, follow us on LinkedIn, Facebook, Google+, YouTube, and @Prolexic on Twitter.
Michael E. Donner
SVP, Chief Marketing Officer
+1 (954) 620 6017
The Cost of Denial-of-Services Attacks
Free report from The Ponemon InstituteLEARN MORE >>
Web Application Firewalls: The TCO Question
Analyst white paperLEARN MORE >>
Threat: Joomla Reflection DDoS-for-Hire
Compromised Joomla servers used for DDoS GET floodsLEARN MORE >>
Frost & Sullivan Stratecast Report
“Going to the Edge with Security”LEARN MORE >>
Threat: MS SQL Reflection Attacks
DDoS attack abuses MC-SQLR in SQL Server instancesLEARN MORE >>
Q4 2014 State of the Internet - Security Report
Number of DDoS attacks nearly doubles in a yearLEARN MORE >>