pwshub.com

'Error' in Microsoft's DDoS defenses amplified Azure outage

Do you have problems configuring Microsoft's Defender? You might not be alone: Microsoft admitted that whatever it's using for its defensive implementation exacerbated yesterday's Azure instability.

No one has blamed the actual product named "Windows Defender," we must note.

According to Microsoft, the initial trigger event for yesterday's outage, which took out great swathes of the web, was a distributed denial-of-service (DDoS) attack. Such attacks are hardly unheard of, and an industry has sprung up around warding them off.

A DDoS attack aims to overwhelm the resources of the targeted system. It usually involves multiple machines infected with malware flooding the victim with network traffic. Admins employ various methods to differentiate real requests from malicious traffic, but according to F5 Labs, there was still an explosive growth in DDoS attacks in 2023.

"Attacks grew so much in fact that, on average, businesses can be expected to deal with a DDoS attack around eleven times a year, almost once a month," the security vendor said.

Microsoft has published its strategy to defend against network-based DDoS attacks, noting it was unique due to the global footprint of the company. Microsoft said it was able to "utilize strategies and techniques that are unavailable to most other organizations" thanks to that footprint, as well as draw from the collective knowledge of an extensive threat network.

"This intelligence, along with information gathered from online services and Microsoft's global customer base, continuously improves Microsoft's DDoS defense system that protects all of Microsoft online services' assets."

  • Microsoft Dynamics 365 called out for worker surveillance
  • Microsoft remains massively profitable, investors await AI payoff
  • Can't get Minecraft, MongoDB Cloud, others to work today? Blame that Azure outage
  • Microsoft's Azure networking takes a worldwide tumble

This is assuming Microsoft actually implemented that strategy correctly.

For yesterday's event, Microsoft's DDoS protection mechanisms were indeed triggered correctly. However, the response did not go so well. "Initial investigations suggest that an error in the implementation of our defenses amplified the impact of the attack rather than mitigating it," the Windows giant admitted last night.

The problem was global and affected a subset of customers attempting to connect to services, including Azure App Services, Application Insights, Azure IoT Central, Azure Log Search Alerts, Azure Policy, the Azure portal itself, and a subset of Microsoft 365 and Microsoft Purview services.

According to Microsoft the incident lasted from approximately 1145 UTC to 1943 UTC, although the company reckoned the majority of the impact was successfully mitigated by 1410 UTC. The problem wasn't, however, declared over until 2048 UTC.

We contacted Microsoft to learn more about the implementation of its DDoS defenses, but the company has yet to respond. A Preliminary Post Incident Review (PIR) is due in approximately 72 hours, and the company will publish a Final PIR in around two weeks. ®

Source: theregister.com

Related stories
1 month ago - Microsoft's distribution gets a new LTS kernel With impeccable timing considering recent Windows issues, Microsoft has made Azure Linux 3.0 generally available. It includes an update to the Linux kernel and new versions of various...
1 month ago - PSA comes amid multiple IT services crises in recent days US law enforcement and cybersecurity agencies are reminding the public that the country's voting systems will remain unaffected by distributed denial of service (DDoS) attacks as...
1 month ago - Some 'exceptional circumstances' will be given a minor extension as lawsuits start to fly As the DigiCert drama continues, we now have a better idea of the size and scope of the problem – with the organization's infosec boss admitting the...
1 month ago - Sectigo bosses claim it's only a matter of time before Microsoft and Apple drop Big E from their root stores too After falling down in the estimations of major browser makers Google and Mozilla, Entrust faces a lengthy fight on its hands...
1 week ago - AI hype is in full swing, with companies like Google, Microsoft, Meta and Apple putting it in everything. There's a lot of new words being thrown around. This glossary is your one-stop shop.
Other stories
35 minutes ago - After California passed laws cracking down on AI-generated deepfakes of election-related content, a popular conservative influencer promptly sued,...
58 minutes ago - Act fast to grab this high-performing mesh router for less than $500, keeping you connected while saving some cash too.
58 minutes ago - If the old-school PlayStation is dear to your heart, you can soon relive those totally sweet 1990s memories. Sony is releasing a series of products...
58 minutes ago - If you've got an old phone to part with, T-Mobile is offering both new and existing customers the brand-new Apple iPhone 16 Pro for free with this trade-in deal.
59 minutes ago - Who doesn't want the best for their beloved pooch? Grab some of these tasty treats to make your dog feel special.