Backup Archives - Simple Programmer https://simpleprogrammer.com/category/backup/ Mon, 10 May 2021 12:53:07 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 Best Cloud Backup Services for 2021 https://simpleprogrammer.com/best-cloud-backup-services-2021/ Mon, 10 May 2021 14:00:04 +0000 https://simpleprogrammer.com/?p=38634 With the expansion of high technologies and millions of data, the problem of losing any of the data becomes more serious. The sensitive data on personal devices or computers are prone to damage or loss caused by mechanical failure. Cloud backup is, so far, the best means to protect data and restore it in case...

The post Best Cloud Backup Services for 2021 appeared first on Simple Programmer.

]]>
best cloud backup servicesWith the expansion of high technologies and millions of data, the problem of losing any of the data becomes more serious. The sensitive data on personal devices or computers are prone to damage or loss caused by mechanical failure. Cloud backup is, so far, the best means to protect data and restore it in case of a crash.

Cloud backup or online backup is the tech service of sending data to a secondary server or a data storage system. A third-party service offers the consumer data storage space or access to data or restores it anytime needed. This technology is a key solution for companies to switch to more flexible data storage from physical devices to the cloud and reduce costs.

As an IT segment, cloud computing generated over $300 billion in revenue in 2020. Moreover, already 81% of all enterprises have implemented a multi-cloud strategy. In 2020, 67% of business infrastructure was transformed into cloud-based, and it is predicted that up to 94% of the global workload will be controlled by cloud servers shortly. It becomes evident that cloud backup is an important, even vital, technology.

In this post I will offer you a comprehensive analysis of the best cloud backup systems you can find, listing their pros and cons so that you can choose the solution most suitable to your needs.

Types of Clouds and Cloud Service Models

First of all, a clarification. “Cloud storage” and “cloud backup” are not synonymous. The former is a remote storage drive to save data and access it through the internet. On the other hand, cloud backup includes the functionality of cloud storage, plus it grabs all the data from the device and stores it in a cloud. Typically, cloud storage and cloud backup—alongside cloud sync—operate within the same software.

Generally, we can divide cloud into three separate categories: public, private, and hybrid:

  • Public cloud is owned by a third-party service provider and delivers services across the internet. The user gets access to the cloud services and manages their account through a web browser or a mobile app.
  • Private cloud, on the other hand, delivers services within an organization. Cloud computing services and resources are used by a single company and its members who have access. The cloud may be located on the on-site data center of the company or hosted by a third-party service provider.
  • Hybrid cloud offers both types of cloud usage. The flexible solution of hybrid cloud suggests a smooth switch between public and private clouds.

Besides this basic division, we can also categorize cloud services according to their models: Software as a Service (SaaS), Platform as a Service (PaaS), or Infrastructure as a Service (IaaS):

best cloud backup services
Source
  • Software as a Service (SaaS) offers data access from the device or a web browser with a network connection. This way the provider gives end-users network-based access to a single copy of an app created for SaaS distribution. At the same time, the cloud providers can manage the software app with SaaS and handle any maintenance like updates or security patching. With a compound annual growth rate of 18%, the SaaS market will reach a value of $623 billion by 2023.
  • Platform as a Service (PaaS). The PaaS model supplies an environment for developing an app and managing its future maintenance. The technology is more popular in mobile app development. It helps build an app faster without setting up the underlying infrastructure of servers and storage. Simply put, developers are renting everything needed to build an app from a cloud provider.
  • Infrastructure as a Service (IaaS). The form of cloud computing delivers on-demand resources like storage and network to consumers over the internet. Due to the rise of PaaS, the IaaS technology registered a fall. Still, by 2027, the IaaS market will be valued at $201 billion.

With hundreds of free and paid cloud services, it is vital to find a reliable one that will meet your requirements and provide secure backup and storage. After all, you are going to entrust this cloud with some really important parts of your life.

Cloud Backup Options

In this section I offer you a list of existing popular cloud backup services, including their pros and cons. This way, you can see which ones have the features you need so that you can make the choice that is right for you.

IDrive

Source

IDrive is so far the top popular cloud backup service that offers a whole host of useful features in terms of data backup process, synchronization, and sharing. It offers a free basic plan with 5GB storage and a standard paid plan with 5TB ($52,12/year) that can be upgraded to 10TB storage.

One of the major features of IDrive is unlimited devices’ integration and continuous data backup that ensures full data protection compared to a scheduled backup function.

Pros

  • Files are not automatically deleted from the cloud
  • Mobile backup service
  • Secure file transfer
  • Multiple platforms covered
  • Private encryption key

Cons

  • Limited storage
  • Lack of two-factor-authentication (2FA)
  • Baseline storage of only 250GB
  • Basic sharing options
  • Not user-friendly interface

NordLocker

Source

With 5GB of free storage space, NordLocker can be a great backup solution for personal usage. The paid plan gives up to 500GB of storage space. The high-level and rock-solid security has up-to-date encryption protocols. With the service, it is possible to sync the files and have access from different devices through the app.

Pros

  • Simple to use
  • “Zero-knowledge” policy

Cons

  • Files can be shared only with NordLocker users

pCloud

Source

The best thing about the pCloud service is that you get 4GB of free space and can max the storage out to 10GB by installing desktop and mobile versions and inviting your friends to pCloud. Another handy feature of the service is the client-side file encryption that works on 256-bit AES, allowing no one else except the user to access files.

Pros

  • Reasonable price ($48/year)
  • User-friendly interface
  • Desktop and mobile apps
  • Extended file history
  • Pocket-friendly

Cons

  • No collaboration options

Dropbox Business

best cloud backup services
Photo URL

Dropbox was the first to offer cloud backup and storage in 2007. At that time, it was a groundbreaking solution that started a new culture and trend of storing data on an off-site location. Today, Dropbox Business has a storage capacity of up to 5TB and extended features; single admin login, 256-bit AES and SSL/TLS encryption, controlling user permissions, watermarking, 180-day data retention, and much more.

Pros

  • Powerful collaboration tools
  • Unlimited storage options
  • Functional features and tools
  • Cloud storage and sync

Cons

  • High price ($25 per month for advanced features)
  • Doesn’t support online editing option

CrashPlan

SourceL

CrashPlan can be considered the top cloud backup service for small businesses as a result of its fast functionality and multiple-platform support. The customizable service offers to set the frequency of backup, account security, retention of deleted files, etc. The per-device pricing model is excellent for startups and small businesses with a few devices.

Pros

  • Unlimited storage
  • Fast download and upload speeds
  • Option to backup external drivers
  • Powerful encryption
  • Unlimited file versioning
  • Mobile devices’ support

 Cons

  • The pricing ($10/month)
  • Not supporting file sharing
  • Not supporting offline backup and restore

Microsoft OneDrive

best cloud backup services
Source

For Windows and Microsoft Office users, OneDrive is a functional cloud backup service with lots of benefits and features. The web and mobile interfaces are easy to handle. OneDrive supports multiple PCs and access to online and offline storage. However, as a corporate backup tool, OneDrive is less flexible and effective.

Pros

  • Available with Microsoft 365
  • Option to edit files online without downloading
  • 15GB free storage
  • Social network integration
  • User-friendly interface
  • Mobile app support

Cons

  • No advanced features
  • Synchronizing only specific folders

Backblaze Business

Source

This is one of the top budget-friendly and simple backup services for personal and business purposes. Cloud backup is mostly valued for its capacity, and Backblaze nailed it, offering unlimited backup space. Unfortunately, the service is more often underestimated for not having file synchronization, but it is perfect in its major role, i.e., backup. For security, the data is encrypted.

Pros

  • Low price ($60 for one year)
  • Unlimited storage
  • Data encryption
  • External drive backup

Cons

  • No multiple device support
  • Not user-friendly mobile app
  • Mid-range backup performance
  • No private encryption

Carbonite Safe

best cloud backup services
Source

One of the top advantages of the Carbonite Safe backup service is the intuitive interface that shows the files that have been fully or partially backed up or not backed up at all. The basic Safe plan is limited in functions, lacking the automated backup of large files, video files, and external drivers.

Pros

  • Unlimited storage
  • Continuous backup
  • Free trial usage of all available plans for 15 days
  • High level of security

 Cons

  • Slow upload speed
  • Extra costs for additional features
  • File versioning limited to 30 days
  • Large files should be chosen manually to backup
  • Relatively high price

SOS Online Backup

Source

SOS Online Backup offers a bulk of free features that are mostly premium add-ons in other services. It also supports SQL Server, Exchange, and SharePoint. SOS Online Backup stores any deleted file forever, so there is no chance to lose any data even if deleted by accident.

Pros

  • No restrictions
  • The option to integrate an unlimited number of devices
  • Unlimited versioning
  • Multiple platform support (iOS, Android, Mac, Windows Vista, etc.)

 Cons

  • No option to access from the web, and once the key is lost, it cannot be recovered
  • High pricе ($40 per month for 1TB)

SugarSync Business

best cloud backup services
Source

For personal use, SugarSync has a basic plan with 100GB of cloud storage, while business plans are enhanced with more features and storage of 1TB capacity. The service encrypts data during upload, storage, and download. SugarSync gives an option to choose folders to sync and exclude those that don’t need automatic backup.

Pros

  • Configurable sync service
  • Remote management
  • File Explorer integration

Cons

  • Lacking handy features
  • Slow upload and download speed
  • Expensive ($55 / month)
  • No 2FA

There Are Many Reasons To Choose a Cloud Backup

Cloud backup and storage are important, even vital for personal and corporate usage alike. It gives you the feeling of safety that your sensitive data is protected even if it gets lost from your device. So what criteria to pay attention to when choosing a cloud backup service?

Ultimately, it’s a matter of balance. Ideally, there would be a solution that would combine high performance and versatility of features and robust security at a low price—or, why not, even free. But there is no such option, so it’s a matter of finding the balance suitable to your needs.

Apart from these attributes above, you should also consider storage space options, the scalability of the service, the frequency of backups, and vendor disaster recovery.

Carefully considering the pros and cons of each option, based on your individual requirements, can reveal the choice you should make.

The post Best Cloud Backup Services for 2021 appeared first on Simple Programmer.

]]>
10 Reasons You Need Developers With Cybersecurity Skills https://simpleprogrammer.com/cybersecurity-skills-for-developers/ Wed, 06 Jan 2021 15:00:32 +0000 https://simpleprogrammer.com/?p=38026 Software developers will be key cybersecurity professionals in the coming years, as there is a consensus in the industry that security must be the major element of the software development lifecycle (SDLC).

The post 10 Reasons You Need Developers With Cybersecurity Skills appeared first on Simple Programmer.

]]>

cybersecurityThere’s a common saying that says, “Security is everyone’s responsibility.” While this is true in a practical sense, it’s simply not practical for most organizations, at least not for those who rely heavily on digital solutions.

In this digital era, cyber threats are becoming more of a reality for businesses and organizations across all sectors. This is why highly trained, dedicated, and skilled cybersecurity professionals are becoming the need of an hour.

According to Cybersecurity Magazine, “there will be 3.5 million vacant cybersecurity jobs globally by 2021.” To fill these positions, numerous new cybersecurity professionals will soon come into the picture depending on their ability to secure data and information systems.

It shouldn’t surprise you if I say software developers will be key cybersecurity professionals in the coming years, as there is a consensus in the industry that security must be the major element of the software development lifecycle (SDLC).

This is the best time for developers to switch to security where they can utilize their existing skill set and work in another high-income and low-unemployment industry. Programming knowledge accompanied with the right level of cybersecurity skill is very valuable for automating repetitive processes that save countless hours, analyzing software for vulnerabilities, identifying malicious software, and even creating security tools that can be used to test the security of applications or systems.

For programmers who are skilled with Python, JavaScript, HTML, and even recent languages like Go, opportunities here are vast. It has now become equally important to improve the practical security skills of all the developers in addition to having dedicated security experts.

According to Chris Coleman, president of Woz U, “Someone can predict and avert cyberattacks only with a definite understanding of the vulnerabilities of systems.” And in order to prevent cyber attacks, you should think like a cybercriminal.

Coleman recommends the following cybersecurity skills for programmers on a broader level, irrespective of the area of specialization:

  • Security and networking foundations
  • Logging and monitoring procedures
  • Network defence tactics
  • Cryptography and access management practices
  • Web application security techniques

Finding a programmer with these skills before jumping into the cybersecurity job market would really give your business a leg up on the competition.

There are plenty of reasons why developers are the right fit for the job… In fact, here are 10 reasons why you need developers with cybersecurity skills.

Thorough Knowledge of Programming Languages and Programming Skills

Profound knowledge of programming languages is crucial to stay ahead of hackers who have an intimate knowledge of these systems and the ways to exploit them. For example, by using Python, which is one of the easiest languages to learn, developers can integrate systems more effectively. You will find that a number of cybersecurity tools are written in Python. Also, Python script-based tools are used to navigate the website, test for XSS, and SQL injections.

Imperva, a leading cybersecurity software and service provider, reports that 77% of the websites they protect were attacked by a Python-based tool. This fact suggests that a cybersecurity professional, who could be a developer, should mimic real-life attacks to make sure that companies are ready when real attacks occur and also keenly understand the language and libraries used in real attacks.

Similarly, Javascript is also important because threat assessment of the functionality of web applications is usually written in Javascript and it is a common area where security professionals need to work.

On the other hand, programming skills in JavaScript, Python, and SQL are beyond useful to have when it comes to cybersecurity. As developers already have a better grasp of the core concepts around information security and protecting networks from malicious actors, it will open up more avenues in the industry for them.

Advanced-Level Cybersecurity Jobs

cybersecurityFor the advanced-level cybersecurity jobs, an extremely skilled and experienced software engineer proves to be a great candidate. These higher-level jobs require coding knowledge and are focused on some sort of software engineering, analysis, or penetration testing. It will allow you to pursue cybersecurity as a potential long-term career rather than just a mere job.

For this, it is important to have the following skills:

  • Information security
  • Network security
  • Cryptography
  • Project management
  • Linux

The report of 10 cybersecurity skills for 2021 by Burning Glass, a leading labor market analytics firm, suggests that Cloud Security skills are the most lucrative of all, predicted to deliver a $15,008 salary boost in 2021. Whereas, Application Development Security, DevSecOps, Container Security, Microservices Security, Application Security Code Review are predicted to see an average $12,266 salary boost.

Implement Security at the Foundation

A more secure environment or application gives you the opportunity to work safer and more efficiently. Setbacks may happen during development, but an outside threat such as a data breach or cyber-attack can cause an entire shut down for extended periods of time. Breaches are even more harmful further into development when you have significant assets and content on the line.

For this reason, it’s best to go for a secure development process that makes your life a whole lot easier. If you successfully implement security at the foundation, there are a smaller number of components and updates to work on, launch, or manage afterward. It also makes later revisions much faster and simpler, because you can piggyback on the existing technology.

Security Design Principles are Vital for Companies

Even if your password hashing algorithms are strong, the data of your users is in danger if your database security is weak. While designing any security mechanism for a system, keep the fundamental security design principles in mind.

It is important for companies to develop software with security as the base from the first day itself to build secure systems and cut back vulnerabilities where measures such as continuous testing, authentication safeguards, and adherence to best programming practices are also needed to be considered.

If you fail to implement security early on, even if you try persistently with great effort, you won’t have a perfect design plan and will eventually fail.

New-Fangled Apps Produce More Data that Lead to More Risks

The increase of data storage and collection of incredibly important information in the medical, fitness, and intelligence world poses an increased demand for secure, reliable protocols. The use of new software applications or mobile apps causes an increase in data generation, the sharing of that data, and increases the demand for security.

This all leads to higher risks and a greater likelihood of attack for many companies, brands, and even individuals. So, it is very important that security is followed very seriously in all aspects of development and design, from initial wireframing and prototyping to the live launch. And developers are the key to decreasing these threats. By baking security into the core development of applications and systems, better protection is achievable.

Put Together Educated Decisions on Contradictions

It seems a little hard when it comes to developing both secure and easy to use solutions. If your level of security is superior then it might take more time to develop a feature that is not actually noticeable for end-users while sometimes it might deteriorate the performance of your software too. So, developers have to make educated decisions on “what’s secure enough” by keeping all the above things in mind. The knowledge of cryptography helps developers to uncover the correct balance of security, ease of use, and performance.

Importance of Incorporating Crypto Components Correctly

Application developers can integrate cryptographic components or algorithms correctly and securely which helps protect private information from attackers. Security challenges can also be solved by integrating third-party components and SDKs. They help to take most of the crypto workload off programmers’ shoulders.

However, make sure that you choose and integrate them properly on all the platforms and in a scalable way. To achieve the same, actionable knowledge of security is a must. Also, regular maintenance and updates are very essential so that you not only have to find the right components, but you also have to make sure they work together properly.

Sorting out Security’s Biggest Headache

cybersecurityAs security developers are skilled at coding and development, security-friendly scripting language, and knowledge around APIs, they have the potential to create new tools with a cohesive security system. They are also capable of getting a new EDR, UEBA, or vulnerability scanner to work effectively within existing security, incident, event management (such as SIEM), or ticketing system.

If you have a security developer, the security team won’t rely on a separate development team to make changes to the technology stack during a new launch. Hence, new tools can be easily integrated into existing processes more effectively. All these points suggest that security developers have become so valuable.

A United Approach

In addition to security developers, organizations need to look for an extensible security platform that can fetch all those APIs and exciting tools into a central location where all of its data and employees can take advantage. One central system can help to pick out and present the most urgent threats which bring great benefits and give organizations a chance to respond as quickly as possible. With such greater collaboration within the industry, repositories can be provided where developers can share and collaborate, and also developers can work on their skills and make themselves and their teams more effective defenders.

However, keep in mind that one person can’t be a replacement for a good-sized team, make sure you have the right building blocks. The ideal situation is to have several team members with security developer skills.

Developers Can Adopt the Latest Technology Shift

Training and building security skills within development teams can help build a strategic security mindset for application development. They can efficiently use security-focused frameworks to ensure development is secure.

DevSecOps (Security + DevOps = DevSecOps) is the growing shift that fully integrates security into a DevOps workflow which builds a unified progression. It involves expanding each phase to include a security focus and incorporating cross-functional training in order to mitigate risks when the code is developed where the developer plays a big role.

Developer with Cybersecurity skills is surely a great platform for companies

Now you know the importance of having security skills for developers in addition to having dedicated security professionals. For developing secure software while minimizing vulnerabilities, the right mix of application developers, front-end, back-end, and dev-ops team with proficient skills in cybersecurity is a must.

Programming and security skills together form the key to create a reliable service and maintain user’s data safely.

The post 10 Reasons You Need Developers With Cybersecurity Skills appeared first on Simple Programmer.

]]>
Can Your Protection System Withstand These 30 Types of DDoS Attacks? https://simpleprogrammer.com/ddos-attacks-security/ Mon, 13 Jul 2020 14:00:52 +0000 https://simpleprogrammer.com/?p=36715 Get the lowdown on the complex ecosystem of present-day DDoS attacks. We identify the 30 dominant vectors so your organization is prepared to fend off the escalating threat, no matter what techniques malicious actors may use.

The post Can Your Protection System Withstand These 30 Types of DDoS Attacks? appeared first on Simple Programmer.

]]>
DDosThe phenomenon of distributed denial-of-service (DDoS) attacks debuted in the mid-1990s and has since gone through big evolutionary changes. At its dawn, it was largely a prerogative of hacktivists who knocked major internet services offline as a sign of protest against online censorship and controversial political initiatives.

Fast forward to the present day, and the situation is much scarier. Not only are DDoS raids highly sophisticated and impactful, but they are also forming a huge cybercrime economy whose operators are increasingly adept at monetizing their foul play. 

The latest addition to their genre is what’s called ransom DDoS. Its logic is to mount a destructive attack against an organization and then demand payment for discontinuing it.

At first blush, the idea behind DDoS seems simple: to inundate a network or a web server with more data packets than it can handle. It’s not a misconception, but this model is somewhat oversimplified.

There are numerous wicked tricks in malicious actors’ handbooks that allow them to diversify the attack vectors and select the one that exploits a specific victim’s pain points. For instance, if malefactors discover a vulnerable web application when probing an enterprise network for security weaknesses as part of the initial reconnaissance, they will probably use it as a launchpad for a DDoS attack.

Whereas most defenses you’ll find online are associated with the use of turnkey DDoS mitigation services such as Cloudflare, part of the protection is up to programmers. Crudely coded web applications can be susceptible to SQL injection, a dodgy mechanism that gained notoriety for being a common source of DDoS incursions. 

Once such a loophole is identified, the attacker tailors an appropriate query and injects it iteratively into the target website to make the server crash. Cross-site scripting (XSS) bugs also exemplify imperfections, allowing criminals to deluge a site with rogue queries and malware.

Sanitizing the code of web applications to eliminate SQL, XSS, and other vulnerabilities is an area where programmers can and must kick in. 

Besides strengthening the protection of a web service against the scourge of DDoS, this is a prerequisite for creating stable code that delivers a frictionless user experience.

Do You Know Your DDoS Attacks Points?

When it comes to cybersecurity, awareness is half the battle. If you know the weak links in your organization’s IT infrastructure that could be potentially exploitable by DDoS actors, you can prioritize the defenses and, at the very least, minimize the risk of encountering a single point of failure (SPOF) scenario.

Researchers single out three overarching categories of DDoS onslaughts: volumetric, network protocol, and application layer attacks. They differ in the targeted components of the network architecture and the mechanisms used to execute the raids.

Each one spans a handful of subtypes that run the gamut from TCP three-way handshake exploitation to powerful attacks weaponizing legitimate network stress testing tools. 

The breakdown below will give you an idea of the contemporary DDoS threat landscape in the context of the common attack methods. If you are a programmer, the list can give you some actionable insights into the areas you can focus on to prevent your code from being mishandled by DDoS operators.

Volumetric Attacks

DDosAlso referred to as volume-based attacks, these DDoS incursions engage a large number of computers and spoofed internet connections to flood a network or a website with more traffic packets than it can process. The upshot of this traffic amplification tactic is that legitimate users can no longer access the resource.

  • UDP Flood. To execute this attack, threat actors send a plethora of spoofed User Datagram Protocol (UDP) packets to a server until it becomes incapable of handling legitimate queries. Since UDP connections have limited source IP verification mechanisms, this incursion may fly under the radar of the target’s defenses.
  • ICMP Flood. Also known as Ping Flood, this attack leverages numerous rogue Internet Control Message Protocol (ICMP) pings. A server is configured to reply to every such echo request with a separate traffic packet, so it eventually runs out of resources and becomes unresponsive.
  • DNS Flood. Attackers overwhelm a DNS server with a slew of fake request packets mimicking a large number of IP addresses. DNS Flood is among the worst DDoS attacks in terms of prevention and mitigation.
  • Fraggle Attack. This one uses multiple UDP packets containing a spoofed IP address of the victim’s router. The device fails when replying to itself incessantly and trying to work out what to do with these ostensibly normal requests.
  • Advanced Persistent DoS (APDoS). This term applies when cybercriminals combine different amplification techniques to knock a network offline. A raid like this can last for weeks and tends to cause more damage than most counterparts.
  • Zero-Day DoS. The name is self-explanatory: The attack capitalizes on undocumented imperfections in a network or a server to disrupt its operation. This explains the very low preparedness of organizations in terms of thwarting such onslaughts.

Network Protocol Attacks

Unlike volumetric attacks, network protocol attacks attempt to siphon off the server resources rather than bandwidth. They typically target firewalls or auxiliary internet communication devices such as load balancers. Numerous rogue protocol requests fired at these entities end up consuming all their capacity.

  • SYN Flood. To set this attack in motion, criminals mishandle the TCP three-way handshake, used to establish a connection between a client, a host, and a server via the TCP protocol. The role of SYN (synchronize) packets in this model is to request a connection with a server. Crooks submit numerous SYN requests from a falsified IP address, which results in the denial of service for legitimate users.
  • LAND Attack. The acronym stands for Local Area Network Denial. This stratagem involves sketchy SYN requests where the source and destination IPs are the same. These messages perplex the receiving server, which ends up going down while trying to respond to itself.
  • SYN-ACK Flood. This protocol-based attack tampers with the TCP connection stage where a server submits a SYN-ACK message to acknowledge a client’s request. Criminals swamp a server with rogue packets of this kind. The server wastes its resources trying to figure out why it is receiving these messages in an improper order that contradicts the TCP three-way handshake logic.
  • ACK & PUSH ACK Flood. This one confuses a server with numerous incoming ACK and PUSH ACK packets. Since the target cannot understand how to handle these messages, it reaches its memory and CPU threshold.
  • Fragmented ACK Flood. An adversary bombards a network with fragmented ACK messages. Routers allocate too much processing power to try and reassemble these packets. The disruptive effect can be achieved with a relatively small number of such messages. To add insult to injury, these split packets can sneak past intrusion detection systems (IDS).
  • SSDP Flood. SSDP stands for Simple Service Discovery Protocol. It constitutes the Universal Plug and Play (UPnP) set of networking protocols. To execute the SSDP flood attack, a malefactor sends small UDP packets containing the victim server’s IP address to numerous devices that use UPnP services. The server crashes due to countless queries it receives from these devices.
  • SNMP Flood. This DDoS vector parasitizes the Simple Network Management Protocol (SNMP), which collects and organizes data associated with connected devices. Crooks send a bevy of tiny packets containing the target server’s spoofed IP to a router or a switch that uses SNMP. These devices are configured to reply to that source IP. The anomalous traffic eventually brings the server down.
  • NTP Flood. The Network Time Protocol (NTP) is meant for clock syncing between networks. It can be abused by malicious actors who exploit crudely secured NTP servers to deluge a computer network with redundant UDP packets.
  • VoIP Flood. This one homes in on easily accessible Voice over Internet Protocol (VoIP) servers. The target network is shelled with numerous rogue VoIP messages that appear to hail from different IPs and are wrongfully interpreted as legitimate.
  • DDosMedia Data Flood. When this flood is taking place, rogue video and audio files are used to waste a server’s resources. A hurdle to identifying the peril is that these media objects come from different IP addresses and therefore may not raise any red flags.
  • CHARGEN Flood. Launched in the 1980s, the Character Generator Protocol (CHARGEN) may be considered obsolete. Some printers, photocopiers, and DDoS operators still use it, though. Submitting small packets carrying a target server’s IP address to connected equipment that supports CHARGEN causes the devices to send multiple UDP packets back to the server, thereby exhausting its capacity.
  • Smurf Attack. This one uses a malicious application called Smurf to flood numerous connected devices with ICMP echo requests containing the victim’s IP address. As a result, the server receives too many traffic packets to continue proper operation.
  • Ping of Death Attack. Criminals swamp a network with ping packets whose size exceeds the maximum allowed value (64 bytes). When attempting to reassemble these unorthodox entities, the server crashes.
  • IP Null Attack. This raid relies on IPv4 packets whose header parameter is set to null. Because the receiving web server may fail to process these odd messages, it encounters a denial-of-service condition.

Application Layer Attacks

As the name suggests, these DDoS onslaughts occur at the application layer (“layer 7”) of the Open Systems Interconnection (OSI) conceptual model. They piggyback on known or zero-day vulnerabilities in web applications. These attacks are considered to be the most sophisticated and most difficult to detect.

  • HTTP Flood. The attacker bombards a web application with spoofed GET or POST requests to disrupt its operation. This vector often harnesses botnets consisting of zombified computers to mimic legitimate traffic.
  • Single Session HTTP Flood. This one involves a single HTTP session that generates a series of requests cloaked within the same HTTP packet. Not only does this trick allow crooks to amplify the impact, but it also hoodwinks some network defenses that treat such traffic as benign.
  • Recursive HTTP GET Flood. At an early stage of this attack, the adversary requests a number of webpages from a server and scrutinizes the responses. Next, every website component is requested iteratively until the server runs out of resources.
  • Random Recursive GET Flood. This technique is leveraged to bring down blogs, forums, and other types of sites containing recursive pages. The attacker randomly selects page numbers from a valid range to impersonate a regular user and then generates a slew of GET requests to deteriorate the target’s performance.
  • Spoofed Session Flood. To carry out this raid, the perpetrator uses a mix of a forged SYN packet, a few ACK packets, and one or more RST (reset) or FIN (connection termination) packets. Some protection systems don’t inspect return traffic, so this attack will slip below their radar.
  • Low Orbit Ion Cannon (LOIC). Originally masterminded as a way to help security professionals run network stress tests, the open-source LOIC tool is also one of the DDoS operators’ favorites. It is often abused to flood a server with a plethora of TCP, UDP, and HTTP packets.
  • High Orbit Ion Cannon (HOIC). Akin to LOIC, this is a network stress testing instrument that got out of hand. Criminals are heavily using its immense power to spread mayhem by DDoSing servers with a huge volume of GET and HTTP POST packets. HOIC can target up to 256 domains at the same time.
  • Slowloris. This sophisticated incursion can be executed using just one computer. Crooks open multiple concurrent connections to a web server and maintain them continuously via fragmented extra packets and new HTTP headers. Since these requests never reach a completion stage, they wear out the target’s resources.
  • Misused Application Attack. Threat actors infiltrate computers running resource-intensive applications such as P2P software and then reroute huge amounts of traffic from these client machines to a server.
  • ReDoS. The term stands for “regular expression denial-of-service.” To make this attack pan out, malefactors overwhelm a specific program with algorithmically complex string search queries that deteriorate the performance of the underlying server.

Dodging the Menace

Even large corporations may lack the bandwidth to cope with a dramatic spike in traffic artificially precipitated by DDoS attackers. The standard network gear is equipped with limited DDoS mitigation mechanisms. This issue makes itself felt much more distinctly in the ecosystem of small and medium-sized businesses (SMBs), where building protection systems on a limited budget is the norm.

Under the circumstances, the best defenses are multi-pronged. One of the optimal ways to bolster DDoS protection is to outsource it to cloud-based solutions such as Akamai, Sucuri, Netscout, or Cloudflare, which provide advanced prevention and mitigation services on a pay-per-use basis. This is your plan B in the worst-case scenario.

To fend off application layer attacks described above, IT teams within organizations should follow proper code auditing practices. This will minimize the number of exploitable loopholes in web applications deployed within the enterprise environment.

A combo of an intrusion prevention system (IPS) and a web application firewall (WAF) will take it up a notch. A reliable IPS will safeguard your network against vulnerability exploitation, malware, and downtime. An effective WAF, in its turn, can secure your web applications from SQL injection, cross-site scripting, and cross-site forgery attacks that are part of DDoS actors’ repertoire.

An extra tip is to keep your systems up to date. Patching your digital infrastructure will curb malicious actors by providing them with little to no room for maneuver.

Is Your System Ready?

DDosAlthough DDoS is an oldie in the cybercrime arena, it continues to be a serious concern you need to have effective countermeasures for. To top it off, it is rapidly evolving. Some of these raids rely on malware, IoT botnets, and open-source network stress testing frameworks to extend their reach. What’s worse, some of the novel attacks add extortion to the mix.

Assessing your IT infrastructure from the ground up to identify components most susceptible to volumetric, application layer, and protocol-based DDoS attacks will help your organization take the leap in terms of the protection.

In addition to proper coding hygiene, make sure you apply software patches once available and configure your network equipment to make the most of its built-in defenses. Also, consider leveraging a cloud-based DDoS mitigation service and an IPS to further harden your company’s security posture.

The post Can Your Protection System Withstand These 30 Types of DDoS Attacks? appeared first on Simple Programmer.

]]>
How to Create a Simple Backup Solution That You Can Trust https://simpleprogrammer.com/create-simple-backup-solution-can-trust/ https://simpleprogrammer.com/create-simple-backup-solution-can-trust/#comments Mon, 03 Nov 2014 15:00:00 +0000 https://simpleprogrammer.com/?p=12010 Backing up your data is really important.\n\nWe’ve all heard too many stories of hard drives crashing or computers getting lost or stolen without having a backup and their owner’s suffering a horrible loss of irreplaceable data.\n\n\n\nSo, if we all know that backing up data is so important, why don’t we do it?\n\nWell, some of us...

The post How to Create a Simple Backup Solution That You Can Trust appeared first on Simple Programmer.

]]>
Backing up your data is really important.\n\nWe’ve all heard too many stories of hard drives crashing or computers getting lost or stolen without having a backup and their owner’s suffering a horrible loss of irreplaceable data.\n\n
Why didn't I backup my data?
Why didn’t I backup my data?
\n\nSo, if we all know that backing up data is so important, why don’t we do it?\n\nWell, some of us do, but I know that a majority of software developers I talk to are either not really doing good backups at all or are doing what I would call a half-ass job.\n\nThe reason for this is simple: Coming up with a good backup solution is difficult–or at least it can appear that way.\n\nThat’s why I am writing this blog post. I want to make it as simple as possible.\n\nI’m going to show you a simple approach to create a backup strategy–not just a solution–that you can easily implement.\n\nThe basic approach will be as follows:\n\n

    \n

  • Reduce the amount of “stuff” that needs to be backed up
  • \n

  • Divide backed up data into two categories: critical and non-critical
  • \n

  • Have three copies of data, two local and one offsite
  • \n

  • Make everything automated
  • \n

\n\n

Step 1: Reducing the amount of “stuff” that needs to be backed up

\n\nThe easiest way to simplify your backup solution is to start by reducing the amount of stuff that you need to backup. The less you have to backup, the easier it will be to manage those backups and to actually do the backups themselves.\n\n

If you don't need it, don't store it
If you don’t need it, don’t store it
\n\nWhat we want to do is go through all the data that we think we need to backup and try to get rid of as much of it as possible.\n\nMost people I know, especially software developers and IT people, are storing all kinds of stuff that they will never need.\n\nI used to rip all kinds of movies, video games and music to my computer and save them in a huge library so that I would have access to all this stuff digitally if I ever needed it.\n\nGuess how often I actually needed some random movie I already watched, a video game I already beat or a book I already read?\n\nJust about never.\n\nNow, I realize that some people actually do use their huge libraries of media. For example, kid movies often get watched multiple times, but you have to admit that there is probably a lot of stuff that you will never ever touch again.\n\nI tried to purge as much stuff that I know I will never likely touch again as possible.\n\nI know you might be resistant to doing this, but let me try and convince you that this is a good idea, then you can ignore me and back it all up if you want to.\n\nFirst of all, think about how easy it is to rent digital content on demand today or buy something off of Amazon or Ebay. Do you really need to store a copy of “A Night at the Roxbury?” Probably not, if you ever want to watch it again, just pay a few bucks and get it here.\n\nIf you watch a lot of movies, you’ll be much better off having a subscription to Netflix than you will trying to store a copy of every movie you’ve ever had your hands on. Think about how many hours you are wasting ripping movies to disk and meticulously organizing them. How many of those movies do you actually watch?\n\nThe same goes for music, books and video games. Most things only get consumed once. Get rid of as much of this stuff as possible. You’ll not only stop wasting time storing all this stuff, but your backups will be easier and you will find that a huge mental load is lifted from you.\n\nEven huge music collections are mostly a waste of time. There are multiple music services you can subscribe to that will give you access to just about any music you want for a low monthly fee.\n\nPlus, this trend is only going to increase. More and more stuff is going to be available from the cloud, on demand, for a small rental fee or monthly charge.\n\nStop saving all that crap.\n\n

Step 2: Divide backed up data into two categories: critical and non-critical

\n\nBacking up one terabyte of data to the cloud takes a long time and it can be expensive–that is why most people don’t do it.\n\nSo, what do you end up with?\n\nWell, if you are like most people, you end up having some kind of local backup and you don’t really have a good cloud or offsite backup in place. It’s just too much trouble to try and backup all that data to the cloud.\n\nIf you followed my first step, you should be well on your way to reducing your total data that you need to backup, but we can do much better and get that data to an even smaller amount.\n\nInstead of trying to backup everything to the cloud or offsite, if you focus on backing up just what is critical, you’ll find that it is much more manageable and you won’t need gigabit internet to back everything up.\n\nTake all the data that you want to backup and sort it into two categories: critical and non-critical.\n\nCritical things are things that if you ever lost them, you would be very sad, because they couldn’t be replaced or would cause you some great harm.\n\nA good example of critical data for me is my wife’s photos. If I lost my wife’s photos, I would probably need to find a new wife.\n\n

If you loved me, you would have had a cloud backup
If you loved me, you would have had a cloud backup
\n\nOther critical data for me is current projects I am working on and past projects that I may need to access again at some point in the future.\n\nMy Pluralsight courses and other training courses are critical data. My source code for my applications is critical data.\n\nThe opposite of critical data is non-critical data–duh.\n\nBut what is non-critical data?\n\nIt’s data that would suck to lose, but would not be the end of the world. Perhaps data that would be a small inconvenience to you to lose, but could be replaced.\n\nCollections of movies, video games and music fall into this category. Yes, you’ll be disappointed if you lose this data, but you can replace that data even if it might cost you some money.\n\nNow, before you get all uppity about your movie collection, remember, I’m not saying we aren’t going to backup your non-critical data–we will–it’s just that we aren’t going to back this data up to the cloud or offsite.\n\nOther non-critical data might be an image of your computer or development workstation. If you lose that backup, you might have to re-install your operating system or waste some time re-installing other programs, but it won’t be that big of a deal.\n\nMost of your data should be non-critical. Unless, of course, you got rid of a large amount of that data, because you realized the futility of storing digital copies of stuff you won’t ever use again. But, if I haven’t convinced you by now, I probably never will, so we’ll just call your “The Complete Matrix Trilogy (The Matrix / The Matrix Reloaded / The Matrix Revolutions) [Blu-ray]” non-critical data.\n\n

Step 3: Have three copies of data, two local and one offsite

\n\nOk, now we are actually ready to back things up.\n\nMost likely, you’ll have a small amount of critical data and either a larger amount of non-critical data or almost none.\n\nThe critical data we don’t ever want to lose. So, we need to make sure that there are three copies of that data at all times.\n\n

Three copies of data, two local, one offsite or cloud
Three copies of data, two local, one offsite or cloud
\n\nThe easiest way to do this is to have:\n\n

    \n

  • one working copy
  • \n

  • one local backup
  • \n

  • and one cloud backup
  • \n

\n\nToday, this is actually quite simple to achieve.\n\nFor awhile I was doing this by using a service like CrashPlan. Crash plan allows you to specify folders on a computer to backup to another location and to specify some folders to be backed up to the CrashPlan cloud servers as well.\n\nI was creating two backup sets. One that backed up my critical data to another hard drive in my computer and another backup that backed up to CrashPlan’s servers.\n\nThis worked well for a while, but then I realized that I didn’t really need to pay CrashPlan’s monthly fee when I was already paying for extra storage space with Dropbox and also that I wanted to have a central place to backup data locally and not just back up from my one PC. My wife has data she needs to backup and I have a laptop and other devices as well.\n\nNow, don’t get me wrong, CrashPlan is great. I highly recommend it, but if you have a NAS (Network Attached Storage) and an account with either Dropbox or OneDrive, you might not really need to utilize a service like CrashPlan.\n\nBut, before I get into the specifics of what I am doing, let’s talk about the strategy one more time.\n\nWe want to have three copies of our data. One working copy, one local backup and one offsite backup.\n\nThere are many ways to accomplish this; the easiest way is to have a cloud storage solution like Dropbox or OneDrive as an offsite backup and then to figure out some way to have a local backup as well.\n\nThe reason why we want an offsite backup and a local backup is so that we are covered in two possible scenarios:\n\n

    \n

  1. Your local backup fails and when you go to recover your data you discover this problem. In that case you can just get the data from the cloud.
  2. \n

  3. Your cloud backup either fails, goes out of business or loses your data. In this case, you can use your local backup to recover your data and move your offsite backup to another service.
  4. \n

\n\nIf you just put your data in the cloud, it isn’t good enough, because you are relying completely on someone else’s service that you can’t control.\n\nIf you just locally back up your data, it isn’t good enough, because you could have a fire and your entire house could burn down, or you could be robbed, or your backup could just fail and you not know it.\n\n

How I’m backing up my critical data

\n\nSo, how am I actually backing up my critical data now that I’ve gotten rid of my CrashPlan subscription?\n\nWell, I invested in a Synology NAS, or network attached storage.\n\nI bought a Synology DiskStation 2-Bay (Diskless) Network Attached Storage (DS213j) which I have attached directly to my network.\n\nIt allows any computer in my network to use it as a file server and it runs its own little operating system that can do all kinds of neat things like backup my data to Dropbox or even Amazon Glacier.\n\nThere are two big advantages of this kind of device versus having some hard drives in my computer that I am using to create a copy of data:\n\n

    \n

  1. The data is accessible by all the computers and devices in my house easily. I don’t have to have my main PC on and connected to the network.
  2. \n

  3. The Synology devices very easily do a RAID style storage. So, I can have two hard disks in there and if one of them fails, the other one still has all the data.
  4. \n

\n\nA distant third, for me, would be that the Synology box can act as a full media server. I don’t use that functionality that much, but I know some people with huge movie collections do.\n\nThe big key point for my solution is that the Synology device creates a very good redundant RAID. In my book that counts as two copies of local data.\n\nI just attach my Synology box as a network drive on my computers and devices and I store any data that I want to make sure is backed up there.\n\nSynology has a service you can install that hooks up your device with your Dropbox account (OneDrive support coming really soon.) So, I just share out that Dropbox folder on my Synology drive out to my network and I can drop any files I want backed up in that share and those files will not only be in double backup on the Synology drive, but also backed up to my Dropbox account in the cloud.\n\nMy wife can also do the same, so this is very convenient.\n\nI also don’t even worry about having a local copy of a backup on my computer anymore, because I know that the data in the Synology drive is backed up on two hard drives and in the cloud.\n\n

How I’m backing up my non-critical data?

\n\nWhat about the non-critical data?\n\nSimple. I just copy that to a share on the Synology device that isn’t backed up to the Dropbox account.\n\nFor example, right now, the only thing I really have that I am considering non-critical data is images of my computers. I just put those on a share on the Synology and I don’t worry about them.\n\n

Why not just use a backup service like CrashPlan or Mozy?

\n\nAgain, this whole thing could be done with a backup service like CrashPlan, but if I am already going to have a Dropbox account that I use, I don’t see the point of paying for and managing another backup system.\n\nIn fact, I am probably going to switch over to OneDrive exclusively, because Microsoft just recently announced that Office 365 users get unlimited OneDrive storage.\n\nIf you want to use a backup service though, go ahead. Just make sure you have a local backup and a cloud based backup for your critical data.\n\n

Step 4: Make everything automated (and test it)

\n\nIf you followed my backup plan or you are using a service like CrashPlan, then you probably don’t need to do much here, because everything is already automated.\n\nCrashPlan automatically backs up the data on your computer as it changes, so you don’t really have to worry there.\n\nAnd, if you are using a NAS and a service like Dropbox, that is automated as well, because you basically just drop files into the Dropbox folder on your NAS and it automatically syncs with Dropbox.\n\nBut, if you are doing something else, just make sure the entire process is automated. You might, for example, want to automate backing up images of your computer. Or you might want to automate getting photos off of your phone or camera and dropping them into a backup location.\n\nFinally, make sure you test everything out.\n\nA backup that has never been tested is worthless.\n\nIf you use a service like CrashPlan, try restoring data from it.\n\nIf your backup is going to be your Dropbox box and your NAS, test it out. Make sure you can retrieve any data that you need. If you are backing up databases or snap-shotting PCs, make sure you can restore all of those backups, otherwise don’t bother backing them up in the first place.\n\nNothing is worse than trying to restore a backup and finding out that it was no good or wasn’t working.\n\n

Are you backing up your data?

\n\nLet me know in the comments below.\n\nAnd, if you liked this post and found it helpful, join the Simple Programmer community so that I can stay in touch and let you know when I have new posts or other free content you might be interested in.\n\nAlso, if you have some other suggestions or think there is something I missed or didn’t consider, leave a comment and let me know.\n\n \n\n 

The post How to Create a Simple Backup Solution That You Can Trust appeared first on Simple Programmer.

]]>
https://simpleprogrammer.com/create-simple-backup-solution-can-trust/feed/ 3