figuerres said:

sounds very very weak.

 

it can be detected by the patern you describe.

 

the attacker can be blocked in many ways from ever reaching the service.

 

and the attacker will be at least partly tracable such that the data center can block them.

 

and i would bet that microsoft and other will take court action on such attacks if they happen.

 

one simple example is to use a client id certificate plus ssl.

 

attacker never gets to the service w/o a cert.  every cert is issued to a known customer and revoked when / if abused or compromised.

with all the data using ssl + cert hacker has almost no chance to see any trafic or to know what it valid.

a hardware firewall could block traffic that does not have the cert before granting access to the web servers or other network elements.

firewall can log attempted inbound traffic and use this to block or to alert staff to trace hackers and finhd them.

 

no different really than any other network attack.

 

Your Answers is very similar as Typical System Administrators answer

1) It can't be detected because, this is not a real attack on application.

Attackers does not try to destory your service, Potential attacker trys to send request to your application keeping all Azure Protocols.

From Azure Point this is a "normal" customer to your application

From your applicaton this is "stupid" customer witch send messages with mistakes. you application will requre to send it again and again.

2) SLL is one more simple barier, not a real protection.

 

Idea of kind attacks is that you attack applications without breaking genearal rules. Smiley and your aim is not working application your aim is budget of application owner.