An “attack on availability” is a type of cyberattack aiming to disrupt the access and functionality of systems, networks, or data, effectively denying service to legitimate users. These attacks are designed to prevent users from accessing critical resources, which is one of the core tenets of cybersecurity, alongside confidentiality and integrity. A notable example is the Distributed Denial of Service (DDoS) attack, which floods a target with overwhelming traffic, exhausting resources and rendering the service unavailable.
In September 2023, a prominent gaming platform was targeted by a massive DDoS attack, resulting in widespread service disruptions that left millions of users unable to access games and online services for several hours. This type of attack often involves a botnet, a network of compromised computers that collectively generate excessive traffic towards the target, overwhelming its capacity.
The broader implications of such attacks on organizations can be severe, leading to immediate financial losses, damaged reputation, and erosion of consumer trust. Outages can interrupt business operations, cause customer dissatisfaction, and potentially lead to legal or regulatory consequences, particularly in industries where service availability is critical.
To defend against availability attacks, organizations can implement a range of strategies. These include traffic filtering and rate limiting to manage incoming requests, deploying redundancy and load balancing to ensure service continuity, and utilizing cloud-based DDoS protection services that can absorb and neutralize malicious traffic. Additionally, maintaining a robust incident response plan is essential to swiftly mitigate the impact of an attack and restore normal operations.
References:
M. H. Bhuyan, H. J. Kashyap, D. K. Bhattacharyya and J. K. Kalita, “Detecting Distributed Denial of Service Attacks: Methods, Tools and Future Directions,” in The Computer Journal, vol. 57, no. 4, pp. 537-556, Apr. 2014, doi: 10.1093/comjnl/bxt031.
keywords: {DDoS;denial of service;agents;handler;network security},
K. S. Szatmáry, “Cybersecurity of the Gaming Industry,” 2024 IEEE 22nd Jubilee International Symposium on Intelligent Systems and Informatics (SISY), Pula, Croatia, 2024, pp. 000441-000446, doi: 10.1109/SISY62279.2024.10737510. keywords: {Industries; Law; Prevention and mitigation; Games; Companies; Data Breach; Ransomware; Computer crime; Protection; Intelligent systems; cybersecurity; gaming industry; cyberattacks},