DDoS attack – what next?
When facing a DDoS attack, the main aim is to show the attackers that they have not achieved their objective. If you withstand the attempt long enough, the attackers will typically turn their attention to someone else.
Record
Record the attack (netflows, server logs, email correspondence with the blackmailers, etc.). These are important for subsequent analysis and for filing any criminal charges against person or persons unknown.
Communication
Make sure that you are able to keep minimum external information channels open, e.g. a static website on which you provide your customers with information and alternative contact details (e.g. telephone, fax, email).
Analyse
Analyse the attack and establish a defence strategy:
If the attack originates from a limited number of IP addresses:
It may be sufficient to filter these addresses with your router or firewall. If the data volume exceeds your available bandwidth, this will need to be done by your internet service provider (ISP).
Move your attacked system to a different subnetwork, where applicable (for purely IP-based attacks). In this case, look for a solution in close collaboration with your ISP and/or a specialist DDoS mitigation provider.
The source IP addresses of the attack are probably bogus:
This is typically the case for SYN, UDP, BGP and SNMP flooding. It makes no sense here to filter the IP addresses, and it could even block legitimate users. You should work together with your ISP to find a solution. Your ISP can divert and filter out this traffic. However, you should also know beforehand what protocols are being used in your system and which ones can be filtered out without any damage. Public websites are generally limited to TCP-based protocols (HTTP, HTTPS, SMTP, etc.), so stateless protocols such as UDP can be filtered without any misgivings (possible exception: DNS).
Attacks on an application:
Your application is brought down by a large number of (complex) requests. The attacks generally use TCP as the network protocol. The sender address is therefore difficult to spoof and can be filtered using various criteria.
Attacks on the SSL/TLS protocol:
A possible remedy is to establish the SSL connection with a cloud service that subsequently forwards the filtered connection to your systems.
If most of your customers are located in specific countries, GeoIP blocking can be used to filter and/or assign priority. This enables the service to remain available for as long as possible. However, some legitimate users may be filtered out or assigned a low priority.
Next steps
Analyse the attack and establish a defence strategy. Prepare for the eventuality that the attacker will try to adjust to your defence measures and will use new tactics. In this case, analyse the DDoS again and take the appropriate countermeasures.
Reporting obligations and criminal charges
Reporting to NCSC
On 7 March, the Federal Council introduced a reporting obligation for cyberattacks on critical infrastructure, which will come into force on 1 April. Operators of critical infrastructure will be required to report cyberattacks to the National Cyber Security Centre (NCSC) within 24 hours of discovery. After submitting the initial report within 24 hours of discovering the incident, they have 14 days to complete their report.
Reporting to the FDPIC
In accordance with Article 24 of the new Federal Act on Data Protection (nFADP), which enters into force on 1 September 2023, data security breaches must now be reported to the FDPIC if the persons affected by the data leak are exposed to an increased risk of their privacy or basic rights being infringed as a result. The requirement applies to private individuals, businesses and federal bodies. Reports to the FDPIC must be submitted as soon as possible.
Criminal charges
File criminal charges with the cantonal police where your company is based. They will then initiate the necessary investigation.
Notes on ransom payments
The NCSC strongly advises against agreeing to the blackmailers' demands.
If you are nonetheless considering paying the ransom, the NCSC urgently recommends that you discuss this step with the cantonal police.
