44.000 DDoS attacks daily in the first half of 2023

44.000 DDoS attacks daily in the first half of 2023

Share post

DDoS attacks have increased rapidly. The reason for this is both world events such as the Ukraine war and the expansion of mobile phone networks. The DDoS Threat Intelligence Report for H1 2023 does not show good development. 

Cybercriminals launched around 2023 million distributed denial of service (DDoS) attacks in the first half of 7,9, a 31% increase compared to the previous year. This is what the “DDoS Threat Intelligence Report” for the first half of 2023 from NETSCOUT revealed.

DDoS attacks on Sweden and Finland after NATO bid

Global events such as the Russia-Ukraine War and NATO accession negotiations have fueled the growth of DDoS attacks. Finland was attacked by pro-Russian hacktivists in 2022 while applying to join NATO. Turkey and Hungary were targeted with DDoS attacks because they opposed the Finnish bid. In 2023, Sweden experienced a similar attack related to its NATO bid, culminating in a 500 Gbit/s DDoS attack in May. Ideologically motivated DDoS attacks targeted the United States, Ukraine, Finland, Sweden, Russia and several other countries.

Mobile operators targeted by DDoS attacks

In the second half of 2022, NETSCOUT documented a trend in DDoS attacks against mobile operators that increased by 79% worldwide. This trend continued for APAC mobile operators in H1 2023 with an increase of 294%. This is due to many broadband gaming users shifting their activities to 5G fixed-line access as providers expand their networks.

NETSCOUT's threat landscape insights come from the ATLAS sensor network, built over decades of collaboration with hundreds of Internet service providers worldwide, and trends from an average Internet peering traffic of 424 Tbps, an increase of 5,7% from 2022 corresponds. The company has seen nearly 500% growth in HTTP/S application layer attacks since 2019 and 17% growth in DNS reflections/amplifications in the first half of 2023.

Always new attack tactics

“While world events and the expansion of 5G networks have led to an increase in DDoS attacks, attackers are evolving their approach to be more dynamic, leveraging tailored infrastructure such as bulletproof hosts or proxy networks to launch attacks” said Richard Hummel, Senior Threat Intelligence Lead at NETSCOUT. “The lifecycle of DDoS attack vectors demonstrates attackers’ persistence in finding and weaponizing new attack methods as DNS water torture and carpet bombing attacks become more common.”

Other key findings from the NETSCOUT 1H2023 DDoS Threat Intelligence Report include:

Carpet bombing attacks are on the rise. Since the beginning of the year, there has been a renewed increase in carpet bombing attacks by 55% to more than 724 per day. NETSCOUT considers this number to be a conservative estimate. The attacks cause significant damage by attacking hundreds or even thousands of hosts simultaneously. This tactic often avoids triggering an alarm at high bandwidth thresholds in order to start mitigating DDoS attacks in a timely manner.

DNS water torture attacks are becoming commonplace. The number of daily DNS water torture attacks has increased by almost 353% since the beginning of the year. The top five target industries include wired and wireless telecommunications, data processing hosting, electronic commerce and mail order, and insurance agencies and brokers.

Universities and governments disproportionately attacked. The attackers create their own platforms or use various types of exploitable infrastructure to launch attacks. For example, open proxies have been consistently used in HTTP/S application layer DDoS attacks against higher education and national government targets. DDoS botnets, on the other hand, have often been used in attacks on state and local governments.

DDoS sources are persistent. A relatively small number of nodes are involved in a disproportionate number of DDoS attacks. The average IP address change rate is only 10% because attackers tend to reuse abusive infrastructure. While these nodes are persistent, the impact varies as attackers cycle through a different list of exploitable infrastructure every few days.

Go directly to the report on Netscout.com

 


About NETSCOUT

NETSCOUT SYSTEMS, INC. helps secure digital business services against security, availability and service disruptions. Our market and technology leadership is based on the combination of our patented smart data technology with intelligent analytics. We provide the comprehensive, real-time insight that customers need to accelerate and secure their digital transformation. Our advanced Omnis® cybersecurity platform for threat detection and mitigation offers comprehensive network visibility, threat detection, contextual investigations and automated mitigation at the network edge.


Matching articles on the topic

Cybersecurity platform with protection for 5G environments

Cybersecurity specialist Trend Micro unveils its platform-based approach to protecting organizations' ever-expanding attack surface, including securing ➡ Read more

Data manipulation, the underestimated danger

Every year, World Backup Day on March 31st serves as a reminder of the importance of up-to-date and easily accessible backups ➡ Read more

Printers as a security risk

Corporate printer fleets are increasingly becoming a blind spot and pose enormous problems for their efficiency and security. ➡ Read more

The AI ​​Act and its consequences for data protection

With the AI ​​Act, the first law for AI has been approved and gives manufacturers of AI applications between six months and ➡ Read more

Windows operating systems: Almost two million computers at risk

There are no longer any updates for the Windows 7 and 8 operating systems. This means open security gaps and therefore worthwhile and ➡ Read more

AI on Enterprise Storage fights ransomware in real time

NetApp is one of the first to integrate artificial intelligence (AI) and machine learning (ML) directly into primary storage to combat ransomware ➡ Read more

DSPM product suite for Zero Trust Data Security

Data Security Posture Management – ​​DSPM for short – is crucial for companies to ensure cyber resilience against the multitude ➡ Read more

Data encryption: More security on cloud platforms

Online platforms are often the target of cyberattacks, such as Trello recently. 5 tips ensure more effective data encryption in the cloud ➡ Read more