A multinational company, specializing in digital automation and energy management, approached us to evaluate the efficiency and effectiveness of their existing infrastructure and protection measures against DDoS attacks.
The company uses Azure cloud services, including, Azure DDoS Protection.
However, the company uses a specialized HTTPS-based protocol that utilizes mTLS certificate validation and wanted to know whether an attacker would be able to exploit this to generate a DDoS attack.
The Red Button team carefully analyzed the company’s cloud architecture, we planned and executed multiple attack vectors, including volumetric, protocol, and application layer attacks, to stress and identify weak points in the existing protection.
Five of the six attack scenarios were fully mitigated by the Azure DDoS Protection service without impacting the company’s services.
However, the application-level attack scenario was neither detected nor mitigated, and it caused an immediate downtime to one of the company’s services. This deficiency could pose a significant, costly threat to the global organization’s business continuity.
To address the identified protection gaps, Red Button provided the following recommendations:
Check out these resources for more information
about our DDoS testing solutons for your business.