Denial of Budget Attack
Hello Sirs. I want to explain new types of the attacks. Kind of the attacks might be called DDOB (distributed denial of Budget Attack).
Our Primary aim is Azure Microsoft's new Initiate.
Briefly what is an Azure? Azure is an Advanced Hosting (Marketing name Cloud).
So Azure is a Hosting Plan that you bought for hosting you application.
1) You have flexible hosting environment clustering over many datacenter is the world. (Up time is more than 100%).
2) Access on your server not depended on single connection line. (Access from every were)
3) You have dynamically growing disk space
4) Possibility dynamically changes your Application performance by attaching more CPU power to your hosting plan.
5) By design have n-tier application
6) Already installed Microsoft Server Solutions.
All this are in quite good price. Even more:
1) You do not pay for unused space
2) For unused traffic
3) For CPU Idle time.
You pay only for those are you using. See: http://www.microsoft.com/windowsazure/pricing/
Windows Azure: Compute = $0.12 / hour, Storage = $0.15 / GB stored / month, Storage Transactions = $0.01 / 10K, Bandwidth = $0.10 in / $0.15 out / GB. …
All above sounds great, is it? You may think not to build own datacenter any more, and host all your applications in cloud.
Yes but Cloud is so great idea it might not be fully true.
Why?
In real live we have groups of the people have interest to destroy our business. They try finding new ways to damage our every day works. Now I will explain how it is possible attack Cloud Application.
Assume you host your Application in Cloud. You have 100 000 Customers, your estimate outcome per month assume is 1000$ (cloud service cost). As Attacker I may make hundred accounts and make fake requests to your Application.
From Application point this requests is garbage, and it will ignored by them or even more store it in Log file.
From Cloud this is real traffic and real CPU Calls all that cost real money.
By end of the month you will receive check from Azure Service much more than you expected 100 000 000$.
Company has no possibility to pay kid of money to Microsoft (Azure), and Company is bankrupt.
DDOB attack is done.
Think about it. If Microsoft will not change Payment terms and will keep payment calculation as it is. Kind attacks will be always successful.
Is it not detectable attack by Microsoft because is not a real DDOS attack, it attacks only single Application and keeps it online (With helping Cloud Power).
Thanks for Comments.