What is a Zero-Day DDoS Attack? - Check Point Software

What is a Zero-Day DDoS Attack?

In a zero-day Distributed Denial of Service attack, the attackers exploit previously unknown security vulnerabilities in systems, networks, or applications to launch a DDoS. This sudden flood of traffic from multiple sources renders targeted services or websites unavailable.

Origins & Examples of Zero-Day DDoS Attacks

Many zero-day exploits have their origin in the dark web, where cybercriminals distribute exploits to the highest bidder. Dark web marketplaces also facilitate the sale of so-called booster/stresser services, otherwise known as DDoS-for-hire.

Recent Examples of DDoS Attacks

A recent example of this phenomenon was the discovery and exploitation of the TP240PhoneHome vulnerability. Flaws in the configuration of PBX-to-Internet gateways enabled attackers to abuse the systems, leading to DDoS attacks which caused substantial disruption to targeted organizations.

Here’s another example: in July 2020 the FBI alerted the corporate world about four new DDoS attack vectors: CoAP (Constrained Application Protocol), WS-DD (Web Services Dynamic Discovery), ARMS (Apple Remote Management Services) and Jenkins web-based automation software. The vulnerabilities had been active for at least 12 months prior to this warning.

Understanding Zero-Day Attacks

Zero-day attacks catch victims off guard because they have not had a chance to prepare by patching or otherwise mitigating the flaws in the affected systems.

Zero-day exploits are typically only obtained after extensive work. A security researcher must first locate a weakness in a system, network or application. Developing an exploit based on the vulnerability further requires significant technical expertise, resources, time and effort.

To develop a valuable zero-day threat, the attacker needs:

Defending Against Zero-Day DDoS Attacks

Defending against zero-day DDoS attacks is challenging, but possible. Organizations must begin by taking proactive measures, such as:

Focus on Zero-Day Vulnerabilities

Here are some strategies organizations can use to reduce the potential attack surface:

Recommendations for CSOs

Acknowledging the risk of zero-day DDoS attacks and taking proactive steps to mitigate the threat is imperative for CSOs. Here are some of our recommendations:

By following these recommendations, CSOs take the lead in protecting their organization from the threat of zero-day DDoS attacks.

Secure Your Organization with Check Point DDoS Protector

Zero-day DDoS attacks exploit undisclosed vulnerabilities in systems, blindsiding the victim with a sudden overwhelming volume of traffic that disrupts operations, rendering services unavailable for use. The growing threat of these attacks necessitates that organizations prioritize implementation of effective zero-day protection strategies to safeguard valuable business assets.