Quantcast
Last updated on April 24, 2014 at 5:30 EDT

Prolexic’s Latest DDoS Attack Report

July 17, 2013

HOLLYWOOD, Fla., July 17, 2013 /PRNewswire-iReach/ — Prolexic Technologies, the global leader in Distributed Denial of Service (DDoS) protection services, today announced that the average packet-per-second (pps) rate reached 47.4 Mpps and the average bandwidth reached 49.24 Gbps based on data collected in Q2 2013 from DDoS attacks launched against its global client base. These metrics, representing increases of 1,655 percent and 925 percent respectively compared to Q2 2012, are just two of many findings contained in the company’s Quarterly Global DDoS Attack Report, which was published today.

(Photo: http://photos.prnewswire.com/prnh/20130717/MN48256)

“This quarter we logged increases for all major DDoS attack metrics, and some have been significant. DDoS attacks are getting bigger, stronger and longer,” said Stuart Scholly, president at Prolexic. “We believe this growth is being fueled by the increasing prevalence of compromised Joomla and WordPress web servers in increasingly large botnets.”

In Q1 2013, Prolexic recorded an average DDoS attack bandwidth of 48.25 Gbps, an all-time high since the company began issuing quarterly attack reports in Q3 2011. This second quarter, average bandwidth ticked even higher to 49.24 Gbps, representing a 2 percent increase over Q1 2013 and a 925 percent increase over Q2 2012. In addition, average packet-per-second volume reached 47.4 Mpps this quarter, a dramatic 46 percent increase over the 32.4 Mpps that was logged just last quarter. Compared to Q2 2012, the average packet-per-second rate has increased 1,655 percent.

After trending down in 2011 and part of 2012, average attack durations are increasing, rising from 17 hours in Q1 2012 and 34.5 hours in Q1 2013, to 38 hours this quarter.

“Attack durations are likely increasing because perpetrators are less concerned about detection and protecting their botnets,” said Scholly. “The widespread availability of compromised web servers makes it much easier for malicious actors to replenish, grow and redeploy botnets. Traditionally, botnets have been built from compromised clients. This requires malware distribution via PCs and virus infections, and takes considerable time and effort. Consequently, attackers wanted to protect their client-based botnets and were more fearful of detection, so we saw shorter attack durations.”

Summary highlights from Prolexic’s Q2 2013 Global DDoS Attack Report

Compared to Q2 2012

– 33 percent increase in total number of DDoS attacks

– 23 percent increase in total number of infrastructure (Layer 3 & 4) attacks

– 79 percent increase in total number of application (Layer 7) attacks

– 123 percent increase in attack duration: 38 hours vs. 17 hours

– 925 percent increase in average bandwidth

– 1,655 percent increase in average packet-per-second (pps) rate

Compared to Q1 2013

– 20 percent increase in total number of DDoS attacks

– 17 percent increase in total number of infrastructure (Layer 3 & 4) attacks

– 28 percent increase in total number of application (Layer 7) attacks

– 10 percent increase in attack duration: 38 hours vs. 34.50 hours

– 2 percent increase in average bandwidth: 49.24 Gbps vs. 48.25 Gbps

– 46 percent increase in average packet-per-second (pps) rate

– China maintains its position as the main source country for DDoS attacks.

Analysis and emerging trends

As in previous quarters, attackers predominantly used infrastructure-directed attacks (Layer 3 and Layer 4), which accounted for 74.7 percent of all attacks, with application layer attacks making up the remainder. SYN floods were the attack type of choice, accounting for nearly one-third of all attacks mitigated by Prolexic’s Security Operations Center (SOC). This is the highest volume for any single attack type since Prolexic began publishing its Quarterly Global DDoS Attack Report. GET, ICMP and UDP floods were also frequently directed against Prolexic clients over the three-month period.

Compared to the same quarter one year ago, the total number of DDoS attacks increased 33.8 percent. In addition, the total number of infrastructure attacks increased 23.2 percent while the total number of application attacks (Layer 7) increased by 79.4 percent compared to one year ago. While the split between the total number of infrastructure attacks and application layer attacks was similar between the two quarters, both attack types increased when the two quarters were compared. Average attack durations have increased significantly, rising from 17 hours in Q2 2012 to reach 38 hours this quarter, an increase of 124 percent.

Compared to Q1 2013, the total number of attacks increased by 20 percent. This reflects a consistently high level of denial of service attack activity around the globe over the last six months. The total numbers of both infrastructure and application attacks increased over Q1 2013 (17.4 percent and 28.9 percent respectively). Average attack duration continued to tick upwards, rising from 34.5 hours last quarter to 38 hours in Q2 2013.

April was the most active month of the quarter for DDoS attacks, accounting for 39.7 percent of all attacks, followed by May (31.6 percent) and June (28.7 percent). This quarter, two weeks tied for the most active week of the quarter: April 8-14 and April 15-21. This high level of activity can be attributed to attacks against financial services clients and the ongoing use of the itsoknoproblembro toolkit.

Data for the Q2 2013 report has been gathered and analyzed by the Prolexic Security Engineering & Response Team (PLXsert). The group monitors malicious cyber threats globally and analyzes DDoS attacks using proprietary techniques and equipment. Through digital forensics and post attack analysis, PLXsert is able to build a global view of DDoS attacks, which is shared with Prolexic customers. By identifying the sources and associated attributes of individual attacks, the PLXsert team helps organizations adopt best practices and make more informed, proactive decisions about DDoS threats.

A complimentary copy of the Prolexic Q2 2013 Global DDoS Attack Report is available as a free PDF download from www.prolexic.com/attackreports. The Q3 2013 report will be released early in the fourth quarter of 2013.

About Prolexic

Prolexic is the world’s largest, most trusted Distributed Denial of Service (DDoS) mitigation provider. Please visit www.prolexic.com, LinkedIn, Facebook, Google+, YouTube, and @Prolexic on Twitter.

Contact:

Michael E. Donner

SVP, Chief Marketing Officer

Prolexic

Media {at} Prolexic {dot} com

+1 (954) 620 6017

To view this video on YouTube, please visit: http://www.youtube.com/watch?v=O19W_lJVS_k&feature=c4-overview&list=UUN7sFfwx5NasLePvLFATODw

Media Contact: Michael E. Donner, Prolexic Technologies, +1 (954) 620 6017, media@prolexic.com

News distributed by PR Newswire iReach: https://ireach.prnewswire.com

SOURCE Prolexic Technologies


Source: PR Newswire