Google has rolled out a free DDoS protection platform called Project Shield to protect news sites and free expression to defend the democratic process.
The program is accepting applications from news organizations, election monitoring organizations, and individual journalists and some political organizations
The service protects users from attackers using technology called a reverse proxy allows websites to route both legitimate and attack traffic through Google’s infrastructure to ultimately filters harmful traffic by absorbing it through caching.
Impact on individual site traffic can vary as website performance depends on several factors but Google said the service can be turned on or off as quickly as any other DNS change.
“Some Project Shield users see better website performance because of Project Shield’s caching features,” the company said in a blog describing the new service. Other users see slightly slower performance as traffic passes through Project Shield. ”
The service may also affect how some videos display on a user’s site however those served through YouTube won’t be affected.
Those concerned with privacy should know the program collects and stores user configuration settings and logs for traffic that is proxied through Project Shield but Google says said it only uses the site reader’s IP address and other information to evaluate whether traffic is an attack and only retains aggregated metrics and details about specific attacks.
If a user deletes their site from the Project Shield dashboard, their information will also be deleted from Project Shield site configuration information and the project will no longer collect traffic data from the site.
User needs a google account to access the service and may not be notified in some attacks however will be alerted to larger-scale attack which any require active mitigation.
“Google’s Project Shield should provide good protection,” Andrew Lloyd, President, Corero Network Security told SC Media. “What we tend to find is that shared cloud services are excellent for scrubbing the larger, prolonged DDoS attacks.
He added that irrespective of motivation, DDoS attacks are frequently the tool of choice for the cybercriminals looking to compromise a specific website and that the “DDoS for hire” market has made this criminal activity relatively straightforward, inexpensive and anonymous
Lloyd said it remains to be seen if Project Shield’s protection can successfully detect and swiftly mitigate smaller attacks and that potential users should know that Google Shield is a “best efforts” free service without a service level agreement.
“Consequently, news organizations with a revenue generating subscriber base and/or advertisers who are paying to access a targeted audience will need more comprehensive real-time DDoS protection to be able to stay online during a cyber-attack,” Lloyd said. “That said, we welcome this Internet society enhancing initiative by Google.”
Users should also understand the service won’t protect users from hacking or malware.