DDoS Protection Metrics

Lecture



Many vendors make extensive marketing claims about mitigation capabilities, but when it comes to contractual performance commitments, the claims evaporate. It is fair to say that your DDoS protection is only as good as your SLA.

Use these six questions to assess how good your DDoS protection is. Each SLA metric has a specific technical test and a specific business purpose. The absence of one (or more) of these key performance indicators from your SLA document should call into question your vendor's confidence in its own services and, ultimately, the vendor's ability to protect your organization from DDoS attacks.

DDoS protection metrics:

Time-to-Detect - How soon can you detect attacks?

The first step in stopping a DDoS attack is recognizing that an attack is taking place. Many vendors make bold claims about mitigation times, but the question is: counted from what moment? The sooner an attack can be identified, the faster it can be stopped. With a service level agreement for Time-to-Detect, your DDoS protection provider defines how quickly it will detect an attack. If Time-to-Detect is omitted, you risk that a DDoS attack may begin before anyone even notices it.

Time to Alert - How quickly will you let me know?

When something bad happens, you want to be the first to know. A Time to Alert service level agreement is crucial for ensuring immediate notification in the event of an attack. The absence of this metric means that your protection provider is not committing to notify you of an attack immediately, and puts the burden on you, your customers, or, worse, your boss to find out on your own.

Time to Divert - How quickly do you redirect traffic?

For on-demand DDoS protection deployments, the time it takes the system to initiate diversion is a decisive step toward fast mitigation. Any delay in switching over can lead to unnecessary downtime. A Time to Divert service level agreement defines how quickly your protection provider will initiate diversion after an attack is detected. The absence of this metric from your service level agreement probably means that the DDoS protection provider lacks the technology or processes to ensure fast diversion, which leaves you vulnerable for longer periods of time.

Time-to-Mitigate How quickly will you stop the attack?

After an attack has been detected and diverted to the DDoS mitigation provider, the next question arises: how long will it take to mitigate the attack? The Time-to-Mitigate metric measures the speed at which DDoS mitigation vendors mitigate various types of attacks, based on the attack's characteristics. Although most providers offer this commitment, many still do not. This is a key metric, and an unwillingness to commit to a mitigation time should raise serious doubts about their ability to stop attacks.

Consistency of Mitigation How do you measure the quality of protection?

Shakespeare said that "a rose by any other name would smell as sweet." Unfortunately, this is not the case when it comes to DDoS protection. Beyond the time needed to protect against an attack, the key point is the quality of the protection. The "Consistency of Mitigation" metric provides a basis for calculating mitigation effectiveness and the amount of bad traffic let through. A high-level mitigation threshold will let through less than 5% of attack traffic. The absence of a mitigation consistency commitment in the service level agreement effectively makes the commitments on mitigation times meaningless, since providers can pass virtually everything for "mitigation" and claim compliance with the mitigation SLAs.

Service Availability How reliable is your service?

Finally, when you are under attack, you want to be sure that your mitigation service will be available to take over. The Service Availability metric defines the service's uptime requirements and how much downtime will be allowed on an annual basis. A high-quality service will provide at least 99.999% uptime, which means only about 5 minutes of allowed downtime per year. If your service level agreement does not include a commitment to service availability, it should make you wonder whether the service will be there at the right moment.

DDoS Protection Metrics

These six performance indicators are crucial for guaranteeing the effectiveness of your DDoS protection.

Comments

To leave a comment

If you have any suggestion, idea, thanks or comment, feel free to write. We really value feedback and are glad to hear your opinion.
To reply

Lectures and tutorial on "Information security, Malicious, and information security"

Terms: Information security, Malicious, and information security