The IT Pro Podcast: Inside the DDoS arms race

Cyber attacks are something that every business worries about on a near-constant basis - but while DDoS attacks may not make it onto many CISOs lists of the most worrying threats, they remain one of the most prevalent types of attack - partly because they’re dangerously easy to launch.

The scale and speed with which DDoS attacks can be launched is lowering all the time, too, thanks to the spread of IoT-driven botnets and the rise of DDoS-as-a-service vendors. One of the companies on the front line of defending against this threat is Cloudflare, and in this episode of the IT Pro Podcast, we’re joined by Cloudflare CTO John Graham-Cumming to discuss the tactics used to mount these attacks, and why they’re never really going to go away.


“If you think back a few years, when you think about DDoS, it was often just that the website was not online for a business. And at a time when websites were primarily marketing tools, almost a brochure, it mattered from a reputation perspective and some loss of business. But of course, we've switched to using the internet for pretty much everything. I mean, look at us talking like this over the internet and schooling and working from home and ordering lunch. And you imagine the myriad of things we do on the internet; all of those things are vulnerable to DDoS attacks.”

“We built our systems up so that they can detect and mitigate this stuff, automatically. And from a capacity perspective, because we built the network to be very, very large, we don't worry about the size of attacks. Obviously, we worry in the sense of planning for bigger and bigger attacks, and making sure we have the infrastructure in place, making sure our systems are working… but in both the case of the two terabit per second attack, and in the case of the 17 million requests per second attack, those are just automatically mitigated.”

“We see continuous attacks of all sizes, and it seems to be growing, unfortunately. I had kind of hoped this problem would slow down, but it doesn't seem to be doing so. Sadly, DDoS is just part of what we deal with. It's almost like it's the background noise of the internet, there's always some nonsense going on.”

