Implementing DDoS protection
A DDoS attack is a collection of attack types aimed at disrupting the availability of a target by overwhelming it with malicious traffic. They are usually targeted at virtual network workloads that are accessible via the internet.
The Azure DDoS Protection service helps protect internet-facing virtual network workloads from these attacks by identifying and blocking the malicious attempts to overwhelm our network before they can reach our resources. This service uses the scale and elasticity of Microsoft’s global network to stop the attack at the edge of the Azure network (see Figure 8.1). There are three main types of DDoS attacks:
- Volumetric DDoS attacks such as amplification floods and UDP floods, which overload the network bandwidth capabilities of a target to make it inaccessible. This is the equivalent of what happens in a traffic jam – when vehicles cannot move forward because there is too much traffic. Mitigating this category...