Solved

Is it industry practice for CDN/ISP to do DDoS & Cyber drills or exercises

Posted on 2016-10-12
3
77 Views
Last Modified: 2016-10-13
Both of CDN providers (one of them is Akamai) that offers DDoS protection service told
me they don't offer DDoS drills where we simulate an attack situation & started calling
out relevant parties.

Unless the contact persons in the two CDNs / ISPs gave me the wrong info, I believe
they don't offer such a service.

However, our audit pointed out that if such a regular drills are not being practiced
(say yearly), in the event of such attacks, the escalation & callouts will go haywire,
just like DR (Disaster Recovery) drills.  Audit told me this is regulatory requirement

My view is DR is a much more complex situation as during disasters, it's chaotic
& involves massive manpower redeployment.  Besides both CDN/ISPs has a call
tree documented.

I'm inclined to believe it's not the industry practice to do such DDoS drills as both
CDN providers don't offer them or am I mistaken?  Wud like to know how other
people out there practice it esp in financial/banking, healthcare & stock exchanges
0
Comment
Question by:sunhux
3 Comments
 

Author Comment

by:sunhux
ID: 41840285
One of the 2 ISP uses  Arbor Peakflow so I'm not sure if this product could
help facilitate drills/exercises.



http://www.bankinfosecurity.com/interviews/simulated-attacks-will-test-responses-i-2063
https://www.corero.com/blog/categories/Banking-DDoS-Protection.html

Above links appear to indicate such drills are crucial but why then the 2 ISPs/CDN do
not offer it?
0
 
LVL 62

Accepted Solution

by:
btan earned 400 total points
ID: 41840547
These provider need to let customer know the contact and how the severity of the event or attack can be escalated with a stipulated period based on the severity. The drill aspects is not a contractual default unless you asked for it and a formal exercise run through e.g. tabletop or execution based need to be deliberated early before awarding them. By default, these are not in the offering. Ask yourself that if the drill can be realised easily as the high Gbps is not easily generated.

Indeed exercise is required and there s value of it but you need to know the objective for the exercise - is it to exercise the incident handling protocol (exercise the CERT team),
- is it to verify the high Gbps handling capability (exercise the tiering to scale up as attack get worse),
- is it to validate the parties and information sharing timeliness (media and crisis comms involved) or
- is it to have all these mentioned run through for a maturity aspects (level up assessment wrt e.g. basic-standard, measured-up or  well-adapted benchmarks).  

It can be table top or actual simulation in a contained environment (snapshot) or an actual attack (which is unlikely because you be impacting the internet and other users causing false alarm to ISP and public). The exercise should not be only CDN but it need to be more holistic that can impact your online asset to cover L7 and L3/4 DDoS attack at minimal; and better still have use cases to drill further pertaining to supply chain compromised, malware infested CDN infrastructure, insider threat due to CDN provider/sub-contractor, unauthorised access and data leakage due to lapse of customer or provider oversight etc ...

Do check out the ENISA cyber exercise to get a better understanding what a "drills" should be
https://www.enisa.europa.eu/publications/exercise-survey2012/at_download/fullReport
0
 
LVL 24

Assisted Solution

by:Dr. Klahn
Dr. Klahn earned 100 total points
ID: 41840774
I'm inclined to believe it's not the industry practice to do such DDoS drills as both
CDN providers don't offer them or am I mistaken?


That is correct for the majority of ISPs.  My feeling is that there are two reasons:

  • The cost.  Management views this as an unnecessary cost.
  • The embarassment.  The first few times this is done, the results will be abysmal, showing every shortcoming and security hole.  Everyone in the industry will know about it within 24 hours and trumpet ISP x's failings to their own customers.
0

Featured Post

New My Cloud Pro Series - organize everything!

With space to keep virtually everything, the My Cloud Pro Series offers your team the network storage to edit, save and share production files from anywhere with an internet connection. Compatible with both Mac and PC, you're able to protect your content regardless of OS.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Big data transfers via information superhighways require special attention and protection. Learn more about the IT-regulations of the country where your server is located. Analyze cloud providers and their encryption systems for safe data transit. S…
In 2017, ransomware will become so virulent and widespread that if you aren’t a victim yourself, you will know someone who is.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now