A security administrator is investigating a series of Denial-of-Service (DoS) attacks targeting the company's public-facing web servers. The attacks are characterized by a flood of legitimate-looking HTTP requests originating from a large number of compromised machines distributed globally. Which type of attack is being described, and what is the most effective mitigation strategy?
- ACross-Site Scripting (XSS); Content Security Policy (CSP).
- BDistributed Denial of Service (DDoS); DDoS mitigation service.
- CSQL Injection; Input validation and parameterized queries.
- DPhishing; User awareness training and email filtering.
Show answer & explanationAnswer & explanation
Correct answer: B. Distributed Denial of Service (DDoS); DDoS mitigation service.
The description 'flood of legitimate-looking HTTP requests originating from a large number of compromised machines distributed globally' is the classic definition of a Distributed Denial of Service (DDoS) attack. The most effective mitigation strategy for large-scale DDoS attacks is typically to employ a specialized DDoS mitigation service that can absorb and filter the malicious traffic.
Why the other options are wrong
- A. XSS targets client-side scripts, not server availability, and CSP is a mitigation for it.
- C. SQL Injection targets database vulnerabilities, not network availability, and input validation is its mitigation.
- D. Phishing is a social engineering attack, not a DoS, and is mitigated by training and email filtering.
Distributed Denial of Service (DDoS)
A DDoS attack is a malicious attempt to disrupt the normal traffic of a targeted server, service, or network by overwhelming the target or its surrounding infrastructure with a flood of Internet traffic from multiple compromised computer systems.
- Uses multiple compromised 'bot' machines
- Aims to exhaust target resources
- Mitigated by specialized DDoS protection services
Memory trick: DDoS is a distributed flood, needing a distributed defense.