Microsoft's Early June Service Outages Due to DDoS Attacks

Microsoft ascribed its "early June 2023" service outages as being caused by distributed denial of service (DDoS) attacks by a "Storm-1359" threat actor, per a Friday announcement.

It's not clear which early June outages Microsoft is referring to, as there were a couple of major ones. On June 5, Outlook on the Web had service outages, while the Azure Portal had service interruptions on June 9. Typically, Microsoft uses numbered memos to precisely identify its service incidents in its public announcements and its Message Center seen by account managers, but the Friday announcement didn't use them.

The early June attacks were carried out by Anonymous Sudan, according to this AP story, citing a Microsoft spokeswoman. Microsoft's announcement, though, used the Storm name instead, which is a temporary designation reserved for unknown or emerging threat activity. Microsoft recently switched to a new security nomenclature based on bad weather themes, which was announced in April.

Media reports have described Anonymous Sudan as a "hacktivist" group or as Russian or Russian affiliated, but Microsoft's announcement did not elaborate on the identity of the perpetrators.

The early June service outages occurred via DDoS attacks at "layer 7 rather than layer 3 or 4," the announcement explained. Layer 7 is used for application load balancing under the Open Systems Interconnect Model. The attackers likely used "rented cloud infrastructure" and "multiple virtual private servers," plus "a collection of botnets and tools," to carry out the DDoS attacks.  

A few main techniques were used by the attackers to slow the traffic. An "HTTP(S) flood" attack pushed a "a high load of SSL/TLS handshakes and HTTP(S) requests." A "cache bypass" attack used a series of queries to "force the frontend layer to forward all the requests to the origin," rather than to the cache. Also, a "Slowloris" attack was used, where download acknowledgments aren't recognized or they get delayed, which "forces the web server to keep the connection open and the requested resource in memory."

Microsoft's announcement oddly ended with steps for organizations to better protect their layer 7 implementations from DDoS attacks. For its part, Microsoft indicated that it had hardened its layer 7 protections in response, "including tuning Azure Web Application Firewall (WAF) to better protect customers from the impact of similar DDoS attacks."

Microsoft's Friday announcement perhaps was referring to its June 5 and June 9 service outages, although it's a bit vague. If so, then the DDoS description is more information than previously shared. For instance, Microsoft's team responding on June 5 had ascribed the Outlook on the Web service outage as being due to a problematic Microsoft service update. It did not mention a DDoS attack at that time.

About the Author

Kurt Mackie is senior news producer for 1105 Media's Converge360 group.


comments powered by Disqus

Subscribe on YouTube