{"id":12632,"date":"2024-09-17T08:51:38","date_gmt":"2024-09-17T14:51:38","guid":{"rendered":"https:\/\/zayo.zayowebservers.com\/?post_type=resources&#038;p=12632"},"modified":"2024-09-13T09:01:38","modified_gmt":"2024-09-13T15:01:38","slug":"how-governments-can-combat-ddos-risk-during-elections","status":"publish","type":"resources","link":"https:\/\/zayoustrans.burbledev.com\/fr\/resources\/how-governments-can-combat-ddos-risk-during-elections\/","title":{"rendered":"How Governments Can Combat DDoS Risk During Elections"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">As November\u2019s U.S. Presidential election gets closer, cybersecurity risks to the government\u2019s critical infrastructure are rising.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Those threats include phishing, malware, and ransomware scams designed to compromise voter registration databases and government email systems, <a href=\"https:\/\/www.cisa.gov\/cybersecurity-toolkit-and-resources-protect-elections\" target=\"_blank\" rel=\"noopener\">according to the Cybersecurity and Infrastructure Security Agency<\/a> (CISA).&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The FBI and CISA issued <a href=\"https:\/\/www.cisa.gov\/news-events\/news\/cisa-and-fbi-release-joint-psa-putting-potential-ddos-attacks-during-2024-election-cycle-context\" target=\"_blank\" rel=\"noopener\">a separate alert<\/a> about Distributed Denial of Service (DDoS) attacks, warning that \u201cwith election day (nearing) \u2026 DDoS attacks are one example of a tactic that we have seen used against election infrastructure in the past and will likely see again in the future.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">DDoS ambushes flood government websites with illegitimate traffic to knock them offline or slow them to a crawl. According to Zayo\u2019s report on the <a href=\"https:\/\/zayoustrans.burbledev.com\/resources\/ddos-insights-report-1H-2024\/?utm_source=ddos-press-release-1h-2024&amp;utm_medium=press-release-cta&amp;utm_content=1h-2024-ddos-report&amp;utm_campaign=1h-2024-ddos-report&amp;pi_content=4783d64bbd16efa8230983feb51ec2983cf2a7a539f07123cf1c3bc390af46df\">State of DDoS Attacks<\/a>:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>DDoS incidents against government targets lasted an average of over six hours during the first half of 2024, up 41% from a year earlier<\/li>\n\n\n\n<li>Government targets suffered the longest DDoS attacks of any industry sector<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Elections in other countries have already been targeted this year:&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>DDoS incidents hit several <a href=\"https:\/\/www.politico.eu\/article\/french-government-hit-with-cyberattacks-of-unprecedented-intensity\/\" target=\"_blank\" rel=\"noopener\">French government sites<\/a> in March ahead of the summer national elections\u00a0<\/li>\n\n\n\n<li>Before voting in European Union elections ended on June 9, <a href=\"https:\/\/www.bitdefender.com\/blog\/hotforsecurity\/websites-of-dutch-political-parties-hit-by-ddos-attack-before-eu-elections\/?srsltid=AfmBOorfyrzPsZxp8GRke27QxN3rCQ0VrGONGV3y1-8ZMDydFgtY9QsQ%2F%2F\" target=\"_blank\" rel=\"noopener\">pro-Kremlin hackers flooded the websites of two Dutch political parties<\/a> with over one billion HTTP requests on June 5<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>How DDoS attacks target elections<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Many DDoS attacks don\u2019t actually target the digital components of the voting or tabulation process. Instead, they overwhelm government websites that citizens depend on for services, whether it\u2019s applying for Social Security or paying a parking ticket.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cAffecting essential services for the public has a big impact because it tends to sow public distrust in the government,\u201d says Shawn Edwards, Senior Vice President and Chief Security Officer at Zayo.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">During elections, these incidents are often calculated to undermine voters\u2019 faith in democracy itself. For example, a foreign government might use state-sponsored DDoS to tamper with elections in Western democracies: a 2019 study concluded Russia was behind <a href=\"https:\/\/www.aspi.org.au\/report\/hacking-democracies\" target=\"_blank\" rel=\"noopener\">DDoS attacks during elections in Finland and Ukraine<\/a>.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">DDoS instigators may also target the websites of certain political parties or candidates.&nbsp;<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">If a candidate&#8217;s stance on an issue is undermined by a DDoS attack that takes down their websites, it effectively silences their voice and impacts their campaign.<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIf a candidate&#8217;s stance on an issue is undermined by a DDoS attack that takes down their websites, it effectively silences their voice and impacts their campaign. Such attacks can also disrupt critical media events, limiting their ability to communicate with the public,\u201d says Edwards.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two such incidents were timed to upstage or sabotage political events last year. A <a href=\"https:\/\/www.reuters.com\/world\/europe\/swiss-websites-hit-by-ddos-attack-ahead-zelenskiy-video-address-2023-06-12\/\" target=\"_blank\" rel=\"noopener\">DDoS onslaught hit several Swiss government websites<\/a> right before Ukrainian president Volodymyr Zelenskiy delivered a live video address to Switzerland\u2019s parliament. The <a href=\"https:\/\/www.itworldcanada.com\/article\/breaking-news-ddos-attacks-block-pm-trudeaus-web-site\/536110\" target=\"_blank\" rel=\"noopener\">website for Canadian Prime Minister Justin Trudeau was felled by DDoS<\/a> traffic just hours before he met with Ukrainian Prime Minister Denys Shmyhal.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>DDoS attackers crave attention<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">DDoS is also a favorite way for hacktivists to draw attention to their cause as a mass digital protest against a specific government\u2019s policies or actions. During opening ceremonies for the 2016 Rio Olympics, hacktivist group <a href=\"https:\/\/igarape.org.br\/with-anonymous-latest-attacks-in-rio-the-digital-games-have-begun-2\/\" target=\"_blank\" rel=\"noopener\">Anonymous flooded Brazilian government websites<\/a> with traffic to protest evictions in Rio\u2019s poorest neighborhoods.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hackers weaponize DDoS during elections because, like the Olympic games, they\u2019re huge global events. \u201cThey\u2019re looking for notoriety and visibility. Everybody\u2019s watching elections worldwide, so they use those opportunities in order to make a statement,\u201d says Edwards.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>What governments can do&nbsp;<\/strong><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Government IT systems are particularly vulnerable to DDoS incidents because they\u2019re vast, complex, disparate, and interwoven.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cGovernments have much more of a diverse infrastructure architecture. Every government department or entity is different and there are micro functions within the bigger function,\u201d says Edwards. \u201cGovernment systems are highly interdependent, so an issue in one small area can cause significant disruptions across larger, critical systems.\u201d&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Plus, DDoS attacks are becoming easier to execute \u2013 even for the least sophisticated cybercriminal. \u201cAnyone can go on the dark web and buy a DDoS-for-hire by the hour or the minute. Give them a fraction of a bitcoin and they\u2019ll just point their bots to pummel any side you want,\u201d says Edwards.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But governments can take bold, strategic action to protect their infrastructure and mitigate the effects so there\u2019s absolutely no end-user impact for citizens. Here are top tips from Edwards:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Disperse network traffic geographically<\/strong>: \u201cDon\u2019t have everything all in one data center in Virginia. Maybe put something on the West Coast or the EU or Canada. That just adds a bit of resiliency so you can move your traffic to different locations if DDoS hits.\u201d\u00a0<\/li>\n\n\n\n<li><strong>Maintain adequate network capacity<\/strong>: \u201cYou need enough bandwidth in order to weather a DDoS storm.\u201d\u00a0<\/li>\n\n\n\n<li><strong>Deploy edge networks, SD-WAN, or SASE<\/strong>: These can mitigate DDoS impact as part of a multi-layered security strategy.<\/li>\n\n\n\n<li><strong>Get automated DDoS protection<\/strong>: <a href=\"https:\/\/zayoustrans.burbledev.com\/resources\/technical-overview-ddos-protection\/\">Zayo\u2019s DDoS Protection<\/a> is a good example; it automatically reroutes nefarious traffic away from your network to \u201cscrubbers,\u201d so only legitimate traffic gets through.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cZayo\u2019s DDoS Protection provides that kind of dedicated visibility, proactive monitoring, and automated mitigation you need to really fight off attacks. Our team is there watching and doing this 24 hours a day,\u201d Edwards notes.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By monitoring and analyzing all your IP traffic in real-time, Zayo\u2019s DDoS Protection service alerts you to unusual patterns that could be potential attacks. While automated features save a lot of time and resources, you still have the ability to manually fine-tune as needed.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our multi-carrier DDoS protection works whether across all your network traffic, not just Zayo\u2019s.&nbsp; So even if you use multiple Internet service providers, it\u2019s that much easier to scale up your capacity to fend off persistent DDoS attacks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cZayo\u2019s DDoS protection and network services complement each other that way. It\u2019s a very unique position because you have all that network visibility and telemetry you don\u2019t get with another managed service DDoS offering,\u201d says Edwards.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Zayo\u2019s resilient fiber infrastructure, deep network visibility, scalable capacity, and strategic DDoS Protection service are designed to keep the most important government services safe and accessible when citizens need them most, on election day and every day.&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As November\u2019s U.S. Presidential election gets closer, cybersecurity risks to the government\u2019s critical infrastructure are rising.&nbsp; Those threats include phishing, malware, and ransomware scams designed to compromise voter registration databases and government email systems, according to the Cybersecurity and Infrastructure Security Agency (CISA).&nbsp; The FBI and CISA issued a separate alert about Distributed Denial of [&hellip;]<\/p>\n","protected":false},"featured_media":12633,"template":"","meta":{"_acf_changed":false,"_relevanssi_hide_post":"","_relevanssi_hide_content":"","_relevanssi_pin_for_all":"","_relevanssi_pin_keywords":"","_relevanssi_unpin_keywords":"","_relevanssi_related_keywords":"","_relevanssi_related_include_ids":"","_relevanssi_related_exclude_ids":"","_relevanssi_related_no_append":"","_relevanssi_related_not_related":"","_relevanssi_related_posts":"3939,3983,1675,3613,3994,3988","_relevanssi_noindex_reason":"","resource-post-excerpt":"DDoS and other cybersecurity threats rise during elections. Find out why and how government agencies can protect themselves this U.S. election cycle. ","footnotes":""},"resource-topics":[150],"displayed":[],"resources-categories":[44],"industry":[27,92],"services-amp-solutions":[87,33],"class_list":["post-12632","resources","type-resources","status-publish","has-post-thumbnail","hentry","resource-topics-cybersecurity","resources-categories-blog","industry-public-sector","industry-u-s","services-amp-solutions-ddos-protection","services-amp-solutions-network-connectivity"],"acf":[],"_links":{"self":[{"href":"https:\/\/zayoustrans.burbledev.com\/fr\/wp-json\/wp\/v2\/resources\/12632","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zayoustrans.burbledev.com\/fr\/wp-json\/wp\/v2\/resources"}],"about":[{"href":"https:\/\/zayoustrans.burbledev.com\/fr\/wp-json\/wp\/v2\/types\/resources"}],"version-history":[{"count":0,"href":"https:\/\/zayoustrans.burbledev.com\/fr\/wp-json\/wp\/v2\/resources\/12632\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zayoustrans.burbledev.com\/fr\/wp-json\/wp\/v2\/media\/12633"}],"wp:attachment":[{"href":"https:\/\/zayoustrans.burbledev.com\/fr\/wp-json\/wp\/v2\/media?parent=12632"}],"wp:term":[{"taxonomy":"resource-topics","embeddable":true,"href":"https:\/\/zayoustrans.burbledev.com\/fr\/wp-json\/wp\/v2\/resource-topics?post=12632"},{"taxonomy":"displayed","embeddable":true,"href":"https:\/\/zayoustrans.burbledev.com\/fr\/wp-json\/wp\/v2\/displayed?post=12632"},{"taxonomy":"resources-categories","embeddable":true,"href":"https:\/\/zayoustrans.burbledev.com\/fr\/wp-json\/wp\/v2\/resources-categories?post=12632"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/zayoustrans.burbledev.com\/fr\/wp-json\/wp\/v2\/industry?post=12632"},{"taxonomy":"services-amp-solutions","embeddable":true,"href":"https:\/\/zayoustrans.burbledev.com\/fr\/wp-json\/wp\/v2\/services-amp-solutions?post=12632"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}