https://www.americancityandcounty.com/wp-content/themes/acc_child/assets/images/logo/footer-logo.png
  • Home
  • Co-op Solutions
  • Hybrid Work
  • Commentaries
  • News
  • In-Depth
  • Multimedia
    • Back
    • Podcast
    • Latest videos
    • Product Guides
  • Resources & Events
    • Back
    • Resources
    • Webinars
    • White Papers
    • IWCE 2022
    • How to Contribute
    • Municipal Cost Index – Archive
    • Equipment Watch Page
    • American City & County Awards
  • About Us
    • Back
    • About Us
    • Contact Us
    • Advertise
    • Cookie Policy
    • Privacy Statement
    • Terms of Service
American City and County
  • NEWSLETTER
  • Home
  • Co-op Solutions
  • Hybrid Work
  • Commentaries
  • News
  • In-Depth
  • Multimedia
    • Back
    • Podcasts
    • Latest videos
    • Product Guides
  • Resources/Events
    • Back
    • Webinars
    • White Papers/eBooks
    • IWCE Expo
    • Calendar of Events
    • How to Contribute
    • American City & County Awards
    • Municipal Cost Index
    • Equipment Watch Page
  • About Us
    • Back
    • About Us
    • Contact Us
    • Advertise
    • Cookie Policy
    • Privacy Stament
    • Terms of Service
  • newsletter
  • Administration
  • Economy & Finance
  • Procurement
  • Public Safety
  • Public Works & Utilities
  • Smart Cities & Technology
  • Magazine
acc.com

Smart Cities & Technology


Article

How government can defend against advanced DDoS attacks

How government can defend against advanced DDoS attacks

Sahba Kazerooni, managing director of Toronto, Ontario-based Security Compass, talks about the dangers of cyber attacks to government agencies.
  • Written by Sahba Kazerooni
  • 14th April 2015

Distributed denial-of-service (DDoS) attacks on public-facing government and business websites are a well-known phenomenon. The problem, however, is that over the last few years the security community has noticed a growing criminalization of DDoS. These attacks are no longer carried out just by pranksters and activists. Organized cyber-criminals and state-linked hacker groups now increasingly use them as a way to steal money and/or data, spy on the network or destabilize key operations.

According to an Incapsula security firm survey, in 46 percent of cases, the attacks are also used to extort money from victims. The attacks are also becoming more powerful and adaptive to IT defenses, which makes them much harder to stop than in years past.

Over the next few years, the DDoS attack could become a more serious risk for local government agencies, so IT teams and administrators should begin taking steps now to improve their defenses.

Know Your Attack Surface — DDoS attacks won’t necessarily be limited to a non-essential public-facing website. Attackers are getting smarter, and they are using DDoS as a weapon to disrupt operations. These operations can include everything from government payroll services and e-mail to critical networks that electric, gas and water utilities use. Hospitals, emergency responders and transportation systems are also vulnerable. It’s essential that governments know exactly what their online footprint is and have a contingency plan in place for high-risk attacks.

Know Whom to Call — DDoS attacks are more powerful than in years past. Rent-a-bot services on the black market and new amplification techniques that target the application layer of the network magnify the impact of the attacks. It would be extremely difficult for government IT teams to thwart today’s 20-400 gigabits-per-second attacks using their own in-house defenses. Therefore, it’s important to have 24/7 access to a trusted outside DDoS mitigation service that specializes in handling large attacks.

Train for Secondary Attacks — DDoS is frequently used as a smokescreen for more serious attacks like data theft and malware infections. Agencies need to train their IT staff to look out for secondary attacks during a DDoS event. Staff should look for monitoring system alerts, unusual activity on the network or phishing emails.

Simulated Attacks — A sound DDoS mitigation strategy consists of not just anti-DDoS technology, but also people and processes, all of which must come together in harmony during an attack. Government agencies may want to consider simulating DDoS attacks in a controlled environment. That way, the agencies can have an opportunity to fine-tune the components of their increasingly complex security solutions.

About the Author:

Sahba Kazerooni is managing director of Toronto, Ontario-based Security Compass. The cybersecurity firm specializes in DDoS testing and software security for a range of industries, including critical infrastructure, government, finance, technology, health and retail.

Tags: GPN - Security Public Safety Smart Cities & Technology Article

Most Recent


  • artificial intelligence
    Artificial intelligence for cities and counties
    It appears that artificial intelligence (AI) is everything, everywhere and in every product the vendor community would have us buy. However, despite the hype, few dismiss it as just another high-tech fad. Indeed, some believe it is the third (or fourth) wave, depending on how one is counting in the ever-evolving digital age. As early […]
  • Report: Modern construction techniques, building codes protected structures that survived Lahaina fire
    More than a month after wildfire ripped through the historic community of Lahaina, Hawaii, emergency responders continue working to get a more comprehensive picture of what triggered the tragedy. The death toll remains at 115 people. A recent report from the Insurance Institute for Business and Home Safety’s research division unpacks why the fire was […]
  • dashboards
    Dashboards and software help simplify financial funding and reporting for cities and counties
    Governments are streamlining management of federal funds through technology, says Mike Bell, CEO of Envisio, which provides public dashboards, analytics and performance management software. About 150 local government, education and nonprofit organizations use his firm’s solutions to manage their strategic plans, improve performance and report on results. Envisio is helping local government agencies to satisfy […]
  • asthma
    The top 10 Asthma Capitals for 2023
    September is Asthma Peak Month thanks to ragweed pollen peaking, higher mold counts, the start of cold and flu season, and kids headed back to school. The Asthma and Allergy Foundation of America (AAFA) has released its 2023 Asthma Capitals report, which analyses data from the 100 most populated cities and reveals the most challenging […]

Leave a comment Cancel reply

-or-

Log in with your American City and County account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • North Texas alliance partners with Marketplace.city on smart government solutions
  • Harris County deploys next-generation security in 150 public buildings
  • Prioritizing rapid restore leads to stronger ransomware attack recovery
  • Today’s infrastructure needs greater than roads and bridges - It’s time to face our digital connectiveness

White papers


7 Resources to Level-up Your Federal Grants Administration and Compliance

5th September 2023

Elevator Phone Line Replacement Strategy | A Guide to Reliable, Code-Compliant Solutions

29th August 2023

2023 State of Public Sourcing Report: The Bright Future of Public Procurement

23rd August 2023
view all

Webinars


Grant Preparedness: Unlocking Funding Opportunities for Your Success

10th August 2023

2023 State of Public Sourcing: Taking Local Governments into a Bright Future

1st August 2023

Stop Playing with Fire: How to Manage Infrastructure Asset Risk So You Know You’re Covered

20th June 2023
view all

PODCAST


Young Leaders Episode 4 – Cyril Jefferson – City Councilman, High Point, North Carolina

13th October 2020

Young Leaders Episode 3 – Shannon Hardin – City Council President, Columbus, Ohio

27th July 2020

Young Leaders Episode 2 – Christian Williams – Development Services Planner, Goodyear, Ariz.

1st July 2020
view all

GALLERIES


Gallery: Hottest temperatures recorded in American cities during July

12th September 2023

The top 10 Asthma Capitals for 2023

7th September 2023

U.S. cities with the cleanest air from latest “State of the Air” report

5th September 2023
view all

Twitter


Newsletters

Sign up for American City & County’s newsletters to receive regular news and information updates about local governments.

Resale Insights Dashboard

The Resale Insights Dashboard provides model-level data for the entire used equipment market to help you save time and money.

Municipal Cost Index

Updated monthly since 1978, our exclusive Municipal Cost Index shows the effects of inflation on the cost of providing municipal services

Media Kit and Advertising

Want to reach our digital audience? Learn more here.

DISCOVER MORE FROM INFORMA TECH

  • IWCE’s Urgent Communications
  • IWCE Expo

WORKING WITH US

  • About Us
  • Contact Us

FOLLOW American City and County ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.