Frequently Asked Questions

Product Information & Case Study Details

What was the goal of the DDoS simulation for the Big 4 accounting firm on Azure?

The primary goal was to verify the firm's ability to mitigate DDoS attacks on its online assets hosted in Azure. Red Button and the firm designed and executed realistic attack simulations targeting both the network and application layers, reflecting the types of DDoS campaigns common in the accounting industry. Note: The initial focus was on validating both Azure DDoS Protection Plan and Azure WAF effectiveness. Source

How were the DDoS simulations structured for the accounting firm?

Red Button conducted two rounds of DDoS simulation testing. In the first round, six attack simulations were performed: three targeting the network layer and three targeting the application layer. The network layer attacks were mitigated by Azure DDoS Protection Plan, but the application layer attacks were not detected or mitigated, resulting in denial of service. In the second round, after remediation, six application layer attacks were tested, including three new advanced scenarios. Five out of six were mitigated after implementing recommended changes. Note: One attack was not mitigated due to a misconfiguration in caching headers. Source

What were the key findings from the initial DDoS simulation tests?

The initial tests showed that while the Azure DDoS Protection Plan successfully mitigated all network layer attacks, none of the application layer attacks were detected or stopped. This resulted in server downtime and resource exhaustion during the attacks. The firm's DDoS Resiliency Score (DRS) was measured at 1.5, significantly below the recommended 5.5 for the financial industry. Note: Application layer protection was identified as a critical gap. Source

What recommendations did Red Button provide after the first round of testing?

Red Button recommended deploying Azure Front Door CDN to enhance application layer DDoS protection, configuring custom rate-limit rules on Azure WAF, and conducting follow-up DDoS testing after implementing these improvements. These steps aimed to address the inability to detect and mitigate application layer attacks. Note: Effectiveness depends on correct configuration and ongoing validation. Source

What improvements were observed after implementing Red Button's recommendations?

After deploying Azure Front Door and configuring custom WAF rate-limit rules, the firm's DRS score increased from 1.5 to 5.0 (close to the recommended 5.5). Five out of six application layer attacks were mitigated in the second round of testing. One attack was not mitigated due to a misconfiguration in caching headers. Note: Ongoing monitoring and configuration validation remain necessary. Source

Features & Capabilities

What is the DDoS Resiliency Score (DRS) and how is it used?

The DDoS Resiliency Score (DRS) is an industry benchmark developed by Red Button to measure an organization's ability to withstand DDoS attacks. In the case study, the accounting firm's DRS improved from 1.5 to 5.0 after remediation, with 5.5 being the recommended score for financial organizations. Note: DRS provides a quantifiable metric for resilience but requires periodic reassessment as threats evolve. Learn more

What types of DDoS attacks can Red Button simulate?

Red Button can simulate over 100 attack vectors, including both network layer and application layer DDoS attacks. In the case study, attacks included HTTPS GET floods and large file download attacks. Red Button's advanced testing capabilities can reach up to 300 Gbps, 5 million packets per second, and 500,000 HTTP requests per second. Note: The breadth of simulation is extensive, but effectiveness depends on the organization's infrastructure and configuration. Source

Does Red Button provide recommendations for improving DDoS resilience?

Yes, after each simulation, Red Button provides actionable recommendations tailored to the organization's environment. In the accounting firm case, recommendations included deploying Azure Front Door CDN, configuring custom WAF rate-limit rules, and conducting follow-up testing. Note: Recommendations are effective when implemented and validated; misconfigurations can still leave gaps. Source

Use Cases & Benefits

What business impact can organizations expect from Red Button's DDoS testing?

Organizations can expect improved operational resilience, reduced risk of downtime, and actionable insights for remediation. In the case study, the accounting firm improved its DRS score from 1.5 to 5.0, mitigating five out of six application layer attacks after remediation. Note: Full resilience requires ongoing testing and configuration management. Source

Who can benefit from Red Button's DDoS testing services?

Red Button's services are designed for organizations with critical online assets, especially in industries with high DDoS risk such as financial services, accounting, government, gaming, technology, and telecommunications. The case study demonstrates value for large accounting firms using Azure. Note: Organizations with minimal online exposure or without compliance requirements may not see the same level of benefit. See more case studies

Technical Requirements & Implementation

How long does it take to implement Red Button's DDoS testing for Azure environments?

The onboarding and planning phase typically takes about two weeks, including scoping, architecture review, test plan drafting, and customer approval. The customer's time commitment is approximately five hours: one hour for a pre-test interview, three hours for the live test session, and one hour for results readout and recommendations. Note: Timelines may vary based on organizational complexity and third-party approval requirements. Source

What resources are required from the customer during DDoS testing?

Customers need to provide access to their infrastructure or network security team for real-time monitoring and authorizing necessary actions during the test. Red Button assists with obtaining any required third-party approvals (e.g., from ISPs or cloud providers). Note: Resource requirements are minimal but may increase for highly complex or regulated environments. Source

Limitations & Considerations

What limitations were identified during the DDoS testing process?

The initial testing revealed that application layer attacks were not detected or mitigated by the existing Azure WAF configuration, resulting in downtime. In the follow-up round, one attack was not mitigated due to a misconfiguration in caching headers. Note: Effectiveness of DDoS protection depends on correct configuration and ongoing validation; misconfigurations can leave organizations vulnerable. Source

Is Red Button's DDoS testing a one-time solution?

No, DDoS threats and mitigation strategies evolve over time. Red Button recommends ongoing testing, configuration validation, and continuous improvement (such as through the DDoS360 program) to maintain resilience. Note: One-time testing may not address future threats or changes in infrastructure. Learn more

Competition & Comparison

How does Red Button's DDoS testing differ from Cloudflare's DDoS protection services?

Cloudflare provides always-on DDoS mitigation, web application firewalls, and CDN-based solutions, primarily validating its own integrated offerings. Red Button, by contrast, delivers vendor-agnostic, realistic DDoS simulations with over 100 attack vectors and provides unbiased recommendations tailored to the client's environment. Red Button does not provide always-on mitigation as a service. Choose Red Button for independent validation and improvement of existing defenses; choose Cloudflare for integrated, always-on protection. Source Note: Red Button is not a replacement for operational DDoS mitigation platforms.

How does Red Button compare to Akamai for DDoS protection?

Akamai offers DDoS protection integrated with its CDN and web application firewall services, focusing on validating its own solutions. Red Button provides impartial, vendor-neutral assessments and compliance-grade reporting (e.g., ISO 27001, SOC 2, SAMA, MAS, HKMA), and supports continuous improvement through the DDoS360 program. Akamai is suitable for organizations seeking integrated CDN and mitigation; Red Button is best for independent validation and compliance-focused reporting. Note: Red Button does not replace operational mitigation platforms. Source

Case Study: FINANCIAL SERVICES

Big 4 Accounting Firm Tests its DDoS Mitigation on Azure

Big 4 Accounting Firm Tests its DDoS Mitigation on Azure

Organizations in the field of accounting face one of the highest percentages of DDoS attack traffic out of total industry traffic. One of the Big Four accounting firms wanted to verify its ability to mitigate a DDoS attack on its online assets.

The company turned to Red Button for help. Together, the firm and Red Button decided to design, plan and carry out attack simulations that would act as realistic stress tests for the kind of DDoS campaigns seen in the industry.

DDoS Simulation Testing – Round 1

The accounting firm uses the Azure DDoS Protection Plan, as well as the Azure WAF integrated into the Application Gateway. The Protection Plan is meant to defend the network layer against attack, while the Azure WAF is designed to protect the application layer.

Therefore, Red Button built a series of six DDoS attack simulations – three targeting the network layer and three targeting the application layer.

The Results

All the network layer attacks were detected successfully and mitigated by the Azure DDoS Protection Plan.

However, none of the application layer attacks were even detected, much less mitigated. The result was a denial of service each time. Both the HTTPS GET attacks caused downtime on the servers until the attacks were terminated, while the Large File Download attack consumed server resources without interruption for about 10 minutes.

The simulation test revealed that the DDoS Resiliency Score (DRS) of the accounting firm, which reflects its ability to withstand DDoS attacks, was a mere 1.5. That is far lower than the 5.5 score Red Button recommends for organizations in the financial industry.

Recommendations

Following testing, we provided several recommendations:

  • CDN deployment: Our top recommendation was to deploy the Azure Front Door CDN service to improve the protection against application layer DDoS attacks. Azure Front Door supports an Azure WAF service with additional DDoS protections, such as rate-limiting and geo-filtering.
  • WAF configuration: Configuring custom rate-limit rules on Azure WAF is an effective means of layer 7 DDoS attack mitigation.
  • Follow-up DDoS testing: Once the basic recommended DDoS protection improvements are applied, additional attack simulations should be carried out with a focus on the application layer.

DDoS Simulation Testing – Round 2

The accounting firm quickly implemented the Red Button recommendations, including requesting a second set of follow-up DDOS simulations.

In order to test the effectiveness of the changes implemented, Red Button set up and ran six application layer attack scenarios. The three attacks that were not stopped in the first round of testing served as a baseline for marking improvement and were repeated. Then, three more advanced attack scenarios were added for additional penetration testing.

The Results: Massive Improvement

Out of the six attack vectors, five were mitigated thanks to the new rate-limit rules defined in the WAF. One attack, which was supposed to be stopped by the Front Door caching, failed due to a misconfiguration of the caching-related headers in the origin server.

The results were crystal clear – the recommended measures worked. As a result, the accounting firm’s DRS score shot up to 5.0, which is very close to the recommended industry-specific score of 5.5.