News

Microsoft June Service Outages Due to Denial of Service Attacks

Microsoft on Friday explained that its "early June" service outages happened because of distributed denial of service (DDoS) interruptions by an attacker labeled "Storm-1359."

Microsoft had a couple of major service outages in that time period. On June 5, the Outlook on the Web service had problems, which at the time was said to have been due to a bad service update. On June 9, the Azure Portal had service interruptions.

The announcement was not clear on which outages had been subject to the DDoS attacks.

The early June attacks were carried out by Anonymous Sudan, according to this AP story, citing a Microsoft spokeswoman. Microsoft's announcement, though, used the Storm name instead, which is a temporary designation reserved for unknown or emerging threat activity. Microsoft recently switched to a new security nomenclature based on bad weather themes, which was announced in April.

Media reports have described Anonymous Sudan as a "hacktivist" group or as Russian or Russian affiliated, but Microsoft's announcement did not elaborate on the identity of the perpetrators.

The early June service outages occurred via DDoS attacks at "layer 7 rather than layer 3 or 4," the announcement explained. Layer 7 is used for application load balancing under the Open Systems Interconnect Model. The attackers likely used "rented cloud infrastructure" and "multiple virtual private servers," plus "a collection of botnets and tools," to carry out the DDoS attacks.  

A few main techniques were used by the attackers to slow the traffic. An "HTTP(S) flood" attack pushed a "a high load of SSL/TLS handshakes and HTTP(S) requests." A "cache bypass" attack used a series of queries to "force the frontend layer to forward all the requests to the origin," rather than to the cache. Also, a "Slowloris" attack was used, where download acknowledgments aren't recognized or they get delayed, which "forces the web server to keep the connection open and the requested resource in memory."

Microsoft's announcement oddly ended with steps for organizations to better protect their layer 7 implementations from DDoS attacks. For its part, Microsoft indicated that it had hardened its layer 7 protections in response, "including tuning Azure Web Application Firewall (WAF) to better protect customers from the impact of similar DDoS attacks."

About the Author

Kurt Mackie is senior news producer for 1105 Media's Converge360 group.

Featured

  • Closeup of the new Copilot keyboard key

    Microsoft Updates Copilot To Add Context-Sensitive Agents to Teams, SharePoint

    Microsoft has rolled out a new public preview for collaborative "always on" agents in Microsoft 365 Copilot, bringing enhanced, context-aware tools into Teams channels, meetings, SharePoint sites, Planner workstreams and Viva Engage communities.

  • Windows 365 Cloud Apps Now Available for Public Preview

    Microsoft announced this week that Windows 365 Cloud Apps are now available for public preview. This aims to allow IT administrators to stream individual Windows applications from the cloud, removing the need to assign Cloud PCs to every user.

  • Report: Security Initiatives Can't Keep Pace with Cloud, AI Boom

    The increasingly fast adoption of hybrid, multicloud, and AI systems is easily outgrowing existing security measures, according to a recent global survey by the Cloud Security Alliance (CSA) and exposure management firm Tenable.

  • World Map Image

    Microsoft Taps Nebius in $17B AI Infrastructure Deal To Alleviate Cloud Strain

    Microsoft has signed a five-year, $17.4 billion agreement with Amsterdam-based Nebius Group to expand its AI computing capabilities through third-party GPU infrastructure.