January 5, 2016 By Douglas Bonderud 2 min read

It all started on Dec. 26: Cloud hosting provider Linode reported a series of DDoS attacks affecting its Linode Manager and website, according to SecurityWeek. Infrastructure was also targeted, but in a few hours, the company’s IT teams had everything under control.

Until the next day. So began a 10-day series of continuing attacks that left most of Linode’s services slow or unresponsive. The company has since resolved these issues, but is it possible to mitigate this kind of DDoS damage going forward, or are cloud providers forever at the mercy of denial-based storms?

Common Theme

The distributed denial-of-service (DDoS) attack is a common vector for cybercriminals since it’s often the easiest means to an end: Malicious actors compromise a large number of devices, then have them all attempt simultaneous, high-traffic connections. Targeted servers may slow to a crawl as CPUs attempt to keep up or fail altogether if overwhelmed.

In some cases, the threat of DDoS attacks are used to compel action or demonstrate security weakness. For example, the hacking group Phantom Squad threatened to take down the PSN and Xbox Live gaming networks on Christmas to showcase poor IT security practices. While there were some minor service hiccups during the holidays, it seems the group was either unsuccessful or simply chose a new target. Linode, unfortunately, did not fare so well.

A Poor Present

As noted by SC Magazine, the Christmas attacks on Linode caused “service interruptions at DNS infrastructure and data center locations in the U.S. and the U.K., including Dallas, London, Atlanta, Frankfurt, Newark, N.J., Tokyo, Singapore and Fremont, Calif.” What’s more, they occurred just after maintenance on Xen Linode host servers and came with no warning. No group has stepped forward to claim responsibility or demand any kind of action from the cloud provider.

Instead, the company was hit by attack after attack and was criticized for a lack of response to the issue at hand. By New Year’s Eve, Linode network engineer Alex Forster posted a detailed article about the hack, noting that in six days, the company had endured 30 different attacks that switched vectors each time Linode closed a security hole. According to The Register, as of Jan. 4, the cloud provider was finally back on track, with only one server in Atlanta listing a partial outage.

Takeaways From the DDoS Attacks

For cloud providers, the Linode attack is an uncomfortable reminder that the massive attack surface presented by servers and infrastructure makes cloud offerings a tempting target for DDoS attacks. Sheer request volume can quickly overwhelm even high-traffic servers, and the results are often unpredictable. As problems spread from the back end to specific tenants, they spill over into other client instances, turning a complex situation into complete chaos.

Best bet? Linode offers a good example: Hunker down and start closing holes. While this is no guarantee that attackers will shut things down and walk away, it’s often the quickest and most effective way to mitigate the impact of distributed attacks. As Forster’s blog post demonstrated, however, companies can’t afford to ignore their public face even when fighting private battles. Whenever possible, it’s important to provide a kind of play-by-play — an active report on what’s happening and what’s being done to counter the issue.

Short and sweet? No company is immune to DDoS attacks, and in the cloud, these storms have far-reaching impacts.

More from

Autonomous security for cloud in AWS: Harnessing the power of AI for a secure future

3 min read - As the digital world evolves, businesses increasingly rely on cloud solutions to store data, run operations and manage applications. However, with this growth comes the challenge of ensuring that cloud environments remain secure and compliant with ever-changing regulations. This is where the idea of autonomous security for cloud (ASC) comes into play.Security and compliance aren't just technical buzzwords; they are crucial for businesses of all sizes. With data breaches and cyber threats on the rise, having systems that ensure your…

Adversarial advantage: Using nation-state threat analysis to strengthen U.S. cybersecurity

4 min read - Nation-state adversaries are changing their approach, pivoting from data destruction to prioritizing stealth and espionage. According to the Microsoft 2023 Digital Defense Report, "nation-state attackers are increasing their investments and launching more sophisticated cyberattacks to evade detection and achieve strategic priorities."These actors pose a critical threat to United States infrastructure and protected data, and compromising either resource could put citizens at risk.Thankfully, there's an upside to these malicious efforts: information. By analyzing nation-state tactics, government agencies and private enterprises are…

6 Principles of Operational Technology Cybersecurity released by joint NSA initiative

4 min read - Today’s critical infrastructure organizations rely on operational technology (OT) to help control and manage the systems and processes required to keep critical services to the public running. However, due to the highly integrated nature of OT deployments, cybersecurity has become a primary concern.On October 2, 2024, the NSA (National Security Agency) released a new CSI titled “Principles of Operational Technology Cybersecurity.” This new guide was created in collaboration with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD SCSC) to…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today