https://www.techtarget.com/searchnetworking/answer/3-approaches-for-how-to-prevent-DDoS-attacks-on-networks
Denial of service, or DoS, attacks emerged in the early days of the web and commercialization of the internet. These attacks literally deny service and make a resource scarce; in many cases, attackers simply ping a network or server to busy it out.
On the defense, enterprises and service providers responded by blocklisting devices where the attacks originated. As the cat-and-mouse games became more sophisticated, attackers started to use thousands of bots to create what are now called distributed DoS (DDoS) attacks.
For example, one attack used several hundred thousand bots in a rotation spread across a bot army of more than 3 million devices to attack a nation-state and shut down a government service. That attack generated over 500 Gbps of traffic.
How can an enterprise respond? The following three approaches detail how to prevent or respond to DDoS attacks on networks:
Which approach is best to respond to or prevent DDoS attacks on networks? As usual in this complex world, it depends. However, few companies beyond large e-commerce providers have the capability to properly implement a DIY approach. Small e-commerce providers should use a CDN, and most midsize firms would do well with some combination of options one and three.
A combination could involve e-commerce on a CDN, with DDoS mitigation needed for enterprise internet access and VPN services. Some providers can do both and simplify contract management.
14 Sep 2020