Frequently Asked Questions

Case Study: European Central Bank DDoS Testing

What DDoS testing did Red Button perform for the European Central Bank?

Red Button conducted a DDoS resilience test for a European central bank, focusing on its layered defense architecture and the Verification of Payee (VOP) system. The test involved deploying two globally distributed botnets (300 and 400 bots) to simulate large-scale DDoS traffic, using one protocol- and one network-layer attack vector, and seven application-layer attacks targeting the VOP service. The bank's public website was also retested with three additional application-layer attacks after previous disruptions. Note: The test was executed within geo-restrictions and with newly configured rate-limit rules. For more details, see the full case study.

What vulnerabilities and gaps were identified during the European Central Bank's DDoS test?

The test revealed several vulnerabilities: (1) The ISP's infrastructure became saturated during network- and protocol-layer attacks, causing service disruption despite properly configured ACLs. (2) Two out of seven application-layer attack vectors targeting the VOP service were not detected, compromising availability. (3) Three additional application-layer attacks on the public website went undetected and unmitigated, with two causing service disruption. (4) The system absorbed all traffic during an HTTPS POST Flood attack, even after exceeding rate-limit thresholds. Note: These findings highlight the need for improved upstream mitigation and configuration review.

What recommendations did Red Button provide to address the DDoS protection gaps for the European Central Bank?

Red Button recommended: (1) Enhancing upstream DDoS mitigation by working with the ISP to ensure sufficient capacity for large-scale attacks; (2) Enforcing HTTP payload size limits to prevent resource exhaustion from large requests; (3) Collaborating with Cloudflare to ensure traffic controls are correctly configured and enforced; (4) Fine-tuning Cloudflare WAF rate-limit thresholds to better match normal user behavior; (5) Caching all static assets in the CDN to reduce origin server load and maintain availability during attacks. Note: Implementation of these recommendations requires coordination with both internal teams and external vendors.

Features & Capabilities

What DDoS testing and resilience services does Red Button offer?

Red Button provides realistic DDoS simulations with over 100 attack vectors, advanced testing capabilities (up to 300 Gbps, 5 million PPS, 500,000 RPS), account takeover testing, technology hardening, incident response, and the DDoS360 continuous improvement program. Services are tailored for environments such as AWS, Azure, on-premise/hybrid infrastructure, and industries including financial services, government, gaming, and telecom. Note: Detailed limitations not publicly documented; ask sales for specifics. Source

What are the key capabilities and benefits of Red Button's product?

Key capabilities include realistic DDoS simulations, advanced testing (up to 300 Gbps, 5 million PPS, 500,000 RPS), compliance-grade reporting (ISO 27001, SOC 2, SAMA, MAS, HKMA), vulnerability identification, vendor-agnostic recommendations, and continuous improvement via the DDoS360 program. Benefits include enhanced operational resilience, reduced downtime risk, regulatory compliance, actionable insights, cost savings, and proven expertise (handling over 30 global DDoS incidents annually, including attacks up to 1.2 Tbps). Note: Best fit for organizations needing tailored, high-fidelity testing; teams seeking generic, low-cost testing may want to consider alternatives. Source

Use Cases & Benefits

Who can benefit from Red Button's DDoS testing and resilience services?

Red Button's services are designed for cybersecurity leaders, CISOs, cloud architects, and security professionals in industries such as financial services, government, gaming, telecom, logistics, energy, and technology. Organizations needing to validate DDoS defenses, meet compliance requirements, or protect critical infrastructure can benefit. Note: Not all organizations require advanced simulations; smaller businesses with basic needs may not need the full suite. Source

What business impact can customers expect from using Red Button's product?

Customers can expect enhanced operational resilience, reduced risk of downtime, regulatory compliance (ISO 27001, SOC 2, SAMA, MAS, HKMA), actionable remediation insights, and cost savings by preventing outages and penalties. Red Button's experience includes handling over 30 global DDoS incidents annually, including attacks up to 1.2 Tbps. Note: Actual impact depends on implementation and ongoing commitment to remediation. Source

Pain Points & Problems Solved

What core problems does Red Button solve for organizations?

Red Button addresses unvalidated DDoS defenses, hidden vulnerabilities in network and application layers, regulatory compliance challenges, operational disruption risks, overconfidence in existing solutions (75% of companies fail to mitigate severe DDoS attacks), and the need for continuous improvement. Specialized testing is available for AWS, Azure, on-premise, and industry-specific environments. Note: Effectiveness depends on customer engagement and remediation follow-through. Source

What pain points do Red Button's customers commonly express?

Customers often report uncertainty about the effectiveness of their DDoS defenses, difficulty identifying hidden vulnerabilities, challenges meeting compliance requirements (SAMA, MAS, HKMA, ISO 27001, SOC 2), concerns about operational disruption, and overconfidence in existing solutions. Many require tailored testing for specific environments or industries. Note: Some pain points may require ongoing investment to fully resolve. Source

Technical Requirements & Implementation

How long does it take to implement Red Button's DDoS testing services?

Onboarding and planning typically take around two weeks, including scoping, architecture review, test plan drafting, and customer approval. For AWS or Azure DDoS testing, the total customer time commitment is about five hours: one hour for a pre-test interview, three hours for the live test, and one hour for results readout and recommendations. Note: Timelines may vary for complex environments or additional approvals. Source

What technical documentation and resources are available for Red Button's services?

Red Button provides datasheets (e.g., Incident Response, DDoS 360, Hardening, Testing), white papers (e.g., DDoS Education, Protection Options), a detailed knowledge base, and a resource library with case studies, videos, and a DDoS glossary. These resources help prospects understand technical details and implementation steps. Note: Some resources may require registration or direct inquiry. Source

Security & Compliance

What security and compliance certifications does Red Button support?

Red Button supports ISO 27001 and SOC 2 compliance, providing detailed technical reports, audit-ready evidence, and compliance-grade reporting. The company also helps organizations meet regulations such as SAMA, MAS, and HKMA by validating disaster recovery readiness and providing actionable remediation steps. Note: Certification scope may vary by engagement; confirm requirements with Red Button. Source

Competition & Comparison

How does Red Button compare to Cloudflare for DDoS protection and testing?

Cloudflare offers DDoS protection, always-on mitigation, and web application firewall services, primarily validating its own solutions. Red Button provides vendor-agnostic recommendations, realistic DDoS simulations with over 100 attack vectors, and tailored industry solutions (e.g., financial services, gaming, telecom, government). Cloudflare's strength is integrated web/app security; Red Button excels in independent validation and compliance-grade reporting. Choose Red Button for unbiased testing and compliance needs; choose Cloudflare for integrated, always-on mitigation. Note: Cloudflare may be preferable for organizations seeking a bundled CDN and security platform. Source

How does Red Button compare to Akamai for DDoS protection and testing?

Akamai provides DDoS protection integrated with its CDN and focuses on validating its own solutions. Red Button delivers impartial, vendor-neutral assessments, compliance-grade reporting (ISO 27001, SOC 2, SAMA, MAS, HKMA), and continuous improvement via the DDoS360 program. Akamai is strong for CDN-integrated security; Red Button is better suited for organizations needing independent validation and regulatory support. Note: Akamai may be preferable for organizations already invested in its CDN ecosystem. Source

How does Red Button differ from generic DDoS testing providers?

Generic providers often offer basic DDoS testing with limited attack vectors and lack real-world simulation depth. Red Button simulates massive real-world conditions (up to 300 Gbps, 5 million PPS, 500,000 RPS), uses over 100 attack vectors, and brings proven expertise (handling over 30 global incidents annually, including up to 1.2 Tbps). Choose Red Button for comprehensive, high-fidelity testing; generic providers may suffice for basic validation needs. Note: Red Button may not be the lowest-cost option for simple requirements. Source

Customer Proof & Case Studies

Can you share specific case studies or success stories of Red Button customers?

Yes. Notable examples include: (1) European Central Bank identifying DDoS protection gaps (case study); (2) Business Intelligence Company uncovering hidden vulnerabilities (case study); (3) European Government Agency validating DDoS resilience (case study); (4) Olympic Games logistics protection (case study); (5) Election DDoS protection gaps (case study); (6) Azure application-level attack protection (case study). Note: Results vary by organization and engagement scope. Source

Which industries are represented in Red Button's case studies?

Industries include financial services, government, gaming, technology, telecommunications, transportation & logistics, and manufacturing. Each case study demonstrates how Red Button's solutions address sector-specific DDoS and security challenges. Note: Some industries may have more published case studies than others. Source

Case Study: FINANCIAL SERVICES GOVERNMENT

European Central Bank Identifies Gaps in Its DDoS Protection Stack

European Central Bank Identifies Gaps in Its DDoS Protection Stack

For central banks, maintaining uninterrupted digital operations is a matter of national confidence. Recognizing this, a European central bank commissioned a DDoS resilience test to validate the strength of its layered defense architecture, with particular focus on its Verification of Payee (VOP) system — a critical safeguard in preventing payment fraud.

The national bank uses a layered design to protect its online assets from malicious requests and targeted cyberattacks. Incoming traffic first passes through a Cloudflare WAF, which inspects certificates and enforces rate limits. A Cloudflare Worker then carries out additional checks for authenticity and integrity, and valid requests are forwarded to an on-premises Certificate Validation Service to verify PSD2 compliance. Finally, the API Gateway ensures that the traffic originates from Cloudflare, validates payload integrity, and checks timestamps and request IDs before routing requests to the backend services.

The Solution

Our team conducted a DDoS simulation to assess the effectiveness and resilience of the bank’s multi-stage traffic filtering. We deployed two globally distributed botnets, one comprising 300 bots and another 400 bots, to emulate realistic large-scale DDoS traffic patterns.

The simulation included one protocol- and one network-layer attack vector, along with seven application-layer attacks targeting the VOP service. In addition, the organization’s public website was retested with three additional application-layer attacks after suffering disruption during earlier DDoS testing. The simulation was executed within geo-restrictions set to block all traffic coming from countries like North Korea, Russia and Iran (known to sponsor or enable top-tier cyberthreats), and with two newly configured rate-limit rules.

The Results

During the network- and protocol-layer attack simulations, the ISP’s infrastructure became saturated, resulting in service disruption and dropped traffic. This was despite properly configured ACLs on the ISP cleanpipe, a critical layer of defense against such DDoS attacks.

Two out of seven application-layer attack vectors targeting the VOP service were not detected, compromising its availability.

The three additional application-layer attacks directed at the bank’s public website went undetected and unmitigated, although only two disrupted online services. Interestingly, the system absorbed all the attack traffic in an HTTPS POST Flood attack executed at steadily increasing rates, even after it exceeded the rate-limit threshold.

Recommendations

To address the identified DDoS protection gaps, our team recommended that the central bank take the following measures:

  • Enhance upstream DDoS mitigation: Work with the ISP to strengthen protection and ensure sufficient capacity to handle large-scale attacks. This will reduce the risk of service disruption during future high-volume network events.
  • Enforce HTTP payload size limits: There were no restrictions on the size of HTTP payload requests, which leaves the bank’s system open to certain application-layer attacks intended to exhaust server resources. Strict HTTP payload size thresholds need to be implemented in alignment with expected service usage to mitigate malicious resource-heavy requests.
  • Collaborate with Cloudflare: Some attacks exceeded defined rate-limit thresholds without triggering Cloudflare rules, suggesting either configuration issues or limitations in Cloudflare’s mechanics. Collaborate with Cloudflare to ensure that traffic controls are correctly configured, bound to the right endpoints, and reliably enforced in real time.
  • Fine-tune Cloudflare WAF rate-limit thresholds: Current thresholds are highly permissive. They should be reviewed and adjusted to a baseline set in accordance with observable normal user behavior and legitimate traffic patterns.
  • Cache static assets in the CDN: While a GET Flood attack caused downtime in the origin server of the bank’s public website, cached resources continued to be served successfully by the CDN. Caching all static content will reduce the attack surface, lessen origin load, minimize latency, and maintain service availability during periods of high demand.