Ellen Messmer reminds us that the two biggest security problems at internet service providers (ISPs) are, in some order:
- Denial-of-service attacks (DOS)
- Spam
Well, there are two mind-numbingly simple ways to defend against such problems. First, don’t use any web hosting company that doesn’t have free-standing security appliances. You don’t have much control over which brand it will be — Cisco, Juniper, whatever — but that’s not important. What you need is that the flood of traffic hits a specialized appliance rather than some less-well-suited piece of equipment. It’s amazing how many web hosts are too cheap to invest in appliances, which by now are or should be utterly standard enterprise security practice.
Second, outsource your email to somebody who knows what they’re doing. That’s not your web host, who typically provides free email support. But they’re probably using Spam Assassin for spam control, which isn’t good enough. One controversial alternative is Google. Or you can use a true specialist firm. But web hosts — even the good ones — aren’t up to the job.
By the way, these problems overlap — the only security problems I’ve ever had on my websites were via DOS attacks in the form spam email floods.




