Load and Service Outage Testing

What load can your systems withstand?

What is a load and service outage test?

The availability of some IT systems is particularly important. If they come to a standstill, this can have far-reaching effects. Not only downtime, but also slowly responding systems are undesirable situations. These can occur due to sharply increased user numbers, programming errors, inadequate resources, or DoS attacks from hackers. But how many requests can a system withstand and is it easy for hackers to shut down a system? aramido's load and service outage testing provides an answer to this.

Stress tests simulate a high number of simultaneous user accesses to a system. Through the realistic reproduction of accesses, it can be measured how many users an application can support simultaneously. The load test is carried out in stages and the utilization of different system components is constantly measured.

An availability test can also be carried out in the context of hackers and their botnets. Malicious actors can influence a system to the extent that it is no longer available by using a large number of requests or by calling resource-intensive endpoints.

A load test is versatile and extends over various types of systems that are accessible via a network. This includes traditional websites with front- and backend structures, modern single-page applications (SPAs) as well as technical interfaces.

  • Benchmark your systems
  • Identify bottlenecks
  • Fend off DoS attacks
  • Verify the performance of the systems
  • Optimize the use of resources
Product landing page example image
Figure 1 Example of different metrics of a load test, which in the end led to the failure of the application.

When do I need a stress test?

On the internet, attacks on the availability of systems are possible at any time and worldwide. Consider a load test in the following situations:

  • A system must be highly available.
  • Important events or publications are imminent and it is unclear how a system will react.
  • Load balancers, cache systems and Content Delivery Networks (CDN) are intended to ensure availability.
  • Unexpected system failures have occurred.
  • Changes in technology or environment are taking place.
  • A system should be able to withstand a minimum number of users.

Ensure that you know the resilience of your systems in order to preempt unplanned outages and the associated financial damage.

Load tests in three steps

1

After a commission, a joint kick-off meeting takes place.

  • Goals of the audit are discussed.
  • The scope, location and period are determined.
  • Approvals from responsible departments are requested.
  • Contact persons during the audit are communicated.

This meeting forms the basis for an efficient and comprehensive execution of the load test and the service outage test. Subsequently, the careful preparation of the audit phase takes place.

2

In the main phase of the audit, the availability of the system is examined:

  • Previously defined test suites that reflect user behavior are repeated many times.
  • DoS attacks are carried out to identify vulnerabilities in availability.
  • The network and server infrastructure is analyzed and checked for possible bottlenecks.
  • All steps and results are precisely documented for the audit report.
3

Joint result discussion, in which the results of the audits and recommendations for action are presented.

  • Presentation: The results and their implications are presented to the stakeholders.
  • Recommendation: Concrete recommendations are given so that the desired level of availability can be achieved.
  • Discussion: Jointly consult on the next steps for security improvement and risk reduction.

With the end of the audits and its results, the cooperation often continues in the diverse product portfolio of aramido.

Compliance with Availability Standards

A variety of standards require the guarantee of availability of technical systems. The ISO 27001 standard includes availability assurance as an important topic in the risk management process. Similarly, the EU General Data Protection Regulation (GDPR) makes specifications on the robustness of systems. Further compliance requirements are defined by ISO/IEC 20000-3, ISO/IEC 24765, NIST 800-53 and FIPS-199.

Comprehensive Audit of the Application

A load test is based on various procedures and standards to ensure a thorough and standardized audit of the security situation. The following audits are typically carried out during a load test:

  • Review of the infrastructure planning to detect potential bottlenecks.
  • Testing different load curves to determine the maximum load failure point of a system.
  • Peak load tests to assess the elasticity of systems.
  • Utilization of the bandwidth of individual components of the network and server infrastructure.
  • Utilization of the computing power of individual components of the server infrastructure.
  • Abuse and bypassing of existing caching mechanisms.
  • Bypassing of deployed load balancers.

Are your systems able to withstand increasing user numbers? How are they equipped against DoS attacks? With a load and service outage test, we find weaknesses in availability early and efficiently.

Request stress test

aramido is your qualified partner for security audits

  • In-depth security analysis: Our audits go beyond a mere load test. The information security consultants from aramido carry out manual and automated tests and creatively use attack vectors to find ways to cause service failure. This enables a comprehensive analysis of the security situation of your platform.
  • Innovative expertise: Our team consists of highly qualified ethical hackers with many years of experience and current knowledge of the latest threats and attack techniques.
  • Tailored approaches: We adapt our tests to the individual needs of your systems.
  • Holistic security analysis: Our approach covers both automated scans and manual tests to detect even the most sophisticated security gaps.
  • Affordable security audit: We offer professional services at very good, market-standard conditions.
  • Understandable reports: Our reports are clearly structured and easy to understand. You receive not only a list of vulnerabilities, but also clear recommendations for action for remediation.
  • Reliable partnership: We are by your side not only during the test, but are your contact for all questions regarding information security.
  • Benchmark your systems
  • Identify bottlenecks
  • Fend off DoS attacks
  • Verify the performance of the systems
  • Optimize the use of resources

Related Articles

Niklas Fuhrberg

Published on 25.08.2024 published.

What is the NIS 2 Directive? (Part 1)

In response to the increasing number of cyberattacks, the EU is introducing new measures. Among these is NIS 2, which sets new requirements for companies. (read more)


Niklas Fuhrberg

Published on 19.08.2024 published.

NIS 2: What do companies need to do? (Part 3)

As a first step, responsibilities within the company should be established. In addition to a coordinating body, such as an Information Security Officer, the executive management must also fulfill specific obligations. (read more)


Moritz Kaumanns

Published on 01.02.2021 published.

Security Advisory: Amazon Secret Key Publicly Accessible (CVE-2020-28199)

A security vulnerability in an Amazon Pay plugin for Shopware 5 allows the unauthorized reading of the Amazon Secret Key (CVE-2020-28199). (read more)


Andreas Sperber

Published on 28.01.2017 published.

aramido at the 18th Industry Fair i+e 2017

aramido is an exhibitor at the Industry Fair i+e 2017 in Freiburg: visitors can receive information security consulting on February 1st and 2nd. (read more)


Armin Harbrecht

Published on 14.11.2016 published.

How Much Does a Penetration Test Cost?

As penetration testers, we are often asked about the cost of a penetration test. The answer depends on several factors. (read more)