on 12-Dec-2013 15:02
“Is it possible to quantify your own security posture as it relates to denial-of-service? “
That’s the question a customer of ours has been asking themselves, and they came up with plan to measure exactly that. They’re going to DDoS their own production systems. I absolutely love this plan, and admire the architects for their foresight.
When done properly, a self-DDoS test can help you test the following:
The customer is particularly interested in the third point. While most denial-of-service attacks today are not volumetric to the point that they fill the ingress pipe, it happens often enough that you must have an external DDoS scrubber as an insurance policy at least. Often you can purchase this service through your bandwidth provider, but if you think about it, do you know what you are really getting? A Self-DDoS test can find out.
Not only is a DDoS test going to provide metrics and show where you network and application weak spots are, it could be a fun exercise if you like to geek out on breaking stuff (and then making it better).
Here are some tips for conducting your own DDoS self-test:
And lastly, be sure to let me know how it went. I’m always interested in True DDoS Stories.
Connect with David: | Connect with F5: |
|