The Dutch Anti-DDoS Coalition is a consortium of 20 Dutch organizations from different sectors (including ISPs, banks, government agencies and law enforcement agencies) that jointly combat DDoS attacks. To this end, they exchange knowledge, participate jointly in (research) projects, and practice at least once a year with a simulated scenario involving live DDoS attacks under controlled conditions.

The knowledge and experience generated by the coalition’s activities are shared within the coalition and, where possible, beyond. The coalition does all this with the goal of minimizing the impact of DDoS attacks and working toward a society that is resilient to DDoS attacks.

Origins and background

Although DDoS attacks have been around for at least 25 years, they have gained a much greater impact in recent years. The increasing dependence of the economy and society on services offered or facilitated over the Internet means that DDoS attacks have a greater potential for disruption and economic damage. In January 2018, this was highlighted by a series of major attacks whose victims included banks and government agencies.

These attacks were the immediate cause for the formation of the anti-DDoS coalition. At the time, the expectation was that DDoS attacks would become an increasing problem, partly due to the explosive growth of Internet of Things, in which all kinds of (poorly secured) devices are connected to the Internet. These devices can be abused in so-called botnets, where they are taken over by malicious actors and used to carry out DDoS attacks.

In addition, DDoS has become part of hybrid conflict management.

Unique collaboration as a cooperative coalition

Good resilience against DDoS attacks is more important than ever due to these developments. The Anti-DDoS Coalition is a volunteer consortium of 20 organizations from government, business and civil society that puts the concept of cooperative DDoS fighting into practice.

This set-up is unique in the Netherlands and Europe. For most organizations facing DDoS attacks, the focus is on protecting their own infrastructure, not on the collectivity of this problem and therefore not on collective solutions. The anti-DDoS coalition is thus successfully implementing a unique approach.

The coalition uses several cooperative tools:

sharing knowledge and experiences among themselves

sharing measurements of the characteristics of DDoS attacks through a so-called ‘DDoS clearinghouse’

jointly conducting DDoS exercises

providing information about DDoS attacks to the general public

promoting security standards that help protect against DDoS attacks

Coalition members have written a paper on the concept of a DDoS coalition. You can read more about that in this post (NL).

Coalition participation.

The core of the coalition (pictured below) consists of organizations working together through operational activities. These participants measure and share characteristics of DDoS attacks and conduct large-scale DDoS exercises together. For participants in the second category, the value of participation lies primarily in the mutual exchange of knowledge about repelling DDoS attacks.

Any organization that can contribute to the coalition in the form of knowledge sharing, participation in research and/or operational activities can become a member of the coalition. Existing members have a say in admitting new members. Membership is subject to an annual fee. Contact antiddoscoalitie@ecp.nl for more information on membership.