Gartner Blog Network


Availability, Security and Why is DoS Fun?

by Anton Chuvakin  |  April 26, 2012  |  3 Comments

In his 2006 piece “Beyond Denial of Service: Is Availability a Security Issue?”, Eric Maiwald (from our SRMS team) stated:  “Managing the availability of systems, applications, data, and networks is just as much a part of risk management as is the managing of integrity and confidentiality. Yet, in many organizations, availability is not considered a security issue.”

Indeed, the “A” leg of the “C-I-A” (Confidentiality, Integrity, Availability) triad is the one unlike the other two (but then again, any of the three is not like the other two, if you ask me). A lot of folks still relate better to “C” than to “A” (or “I”) and think that security is largely about secrecy. To muddy the waters further, people might doubt that security team has to care about IT availability, but they do not doubt that their organizations face IT availability risks

In any case, let me focus on one particular threat to availability: Denial of Service attacks. It so happens that this quarter I am working on a research project related to denial of service attacks as well as DoS defense architectures.

The more I dive into the subject, the more little peculiarities I notice:

  • The area of anti-DoS (really, “anti-DDoS” in most case) is “certified compliance free” – organizations choose to do something about it since it affects their business in the most visible and material way.
  • On a related note, the cost of a “breach” or a persistent penetration is often a subject of some painful debate; DoS costs, on the other hand, are MUCH easier to gather. It makes this domain of security a curious test bed for economic metrics.
  • It is also an area where cloud computing (and distributed computing in general) seems like a net-positive  force for security, and not a security “challenge”
  • I also find it funny that one of the latest DoS “innovations” is essentially voluntary DoS – an attacker convinces people to download the tool and run an attack on a particular target that they collectively “hate” (“hive mind” mode notwithstanding).  This reminds us all that we can patch Windows, but we cannot patch stupid.

In any case, I will be sharing what I learn about this area in further blog posts – and a full report due later this year.

Finally, if you do anything interesting in the area of DoS mitigation – and I don’t just mean “make and sell tools”, maybe your network is architected in an interesting DoS-resilient way or you just survived a fun DoS attack – think about giving me a call/email or even a comment below. It will help the others secure their networks and systems using the lessons you learned!

Category: denial-of-service  security  

Tags: denial-of-service  dos  security  

Anton Chuvakin
Research VP and Distinguished Analyst
5+ years with Gartner
17 years IT industry

Anton Chuvakin is a Research VP and Distinguished Analyst at Gartner's GTP Security and Risk Management group. Before Mr. Chuvakin joined Gartner, his job responsibilities included security product management, evangelist… Read Full Bio


Thoughts on Availability, Security and Why is DoS Fun?


  1. […] here: Availability, Security and Why is DoS Fun? This entry was posted in IT Security and tagged it security by pro. Bookmark the […]

  2. […] Anton Chuvakin is a research director at Gartner's IT1 Security and Risk Management group. Before Mr. Chuvakin joined Gartner, his job responsibilities included security product management, evangelist… Read Full Bio Coverage Areas: ← Availability, Security and Why is DoS Fun? […]

  3. […] Availability, Security and Why is DoS Fun? […]



Comments are closed

Comments or opinions expressed on this blog are those of the individual contributors only, and do not necessarily represent the views of Gartner, Inc. or its management. Readers may copy and redistribute blog postings on other blogs, or otherwise for private, non-commercial or journalistic purposes, with attribution to Gartner. This content may not be used for any other purposes in any other formats or media. The content on this blog is provided on an "as-is" basis. Gartner shall not be liable for any damages whatsoever arising out of the content or use of this blog.