|
Q4 2014 Distributed Denial of Service Trends Report – From Oct. 1, 2014 through Dec. 31, 2014, Verisign observed a rise in the average size of DDoS attacks against our customers, a significant increase in targeting of certain industries and some other notable trends that have set the stage for increased DDoS activity in 2015. (Click to Download)Verisign has released its Q4 2014 DDoS Trends Report providing a unique view into online distributed denial of service (DDoS) attack trends from mitigations on behalf of, and in cooperation with, customers of Verisign DDoS Protection Services, and the security research of iDefense Security Intelligence Services. Many notable observations were made, including a rise in the average size of DDoS attacks against our customers; the most common attack vector continued to be User Datagram Protocol (UDP) amplification attacks leveraging Network Time Protocol (NTP), while Simple Service Discovery Protocol (SSDP) also continued to be exploited. Verisign also mitigated more attacks in December than any other month in 2014.
The most notable observation, however, is that public-sector customers experienced the largest increase in attacks, constituting 15 percent of total mitigations in Q4. Verisign believes the steep increase in the number of DDoS attacks levied at the public sector may be attributed to attackers’ increased use of DDoS attacks as tactics for politically motivated activism, or hacktivism, against various international governing organizations, as well as in reaction to various well-publicized events throughout the quarter, including protests in Hong Kong and Ferguson, Missouri. As outlined in iDefense’s 2015 Cyber Threats and Trends blog post, the convergence of online and physical protest movements contributed to the increased use of DDoS as a tactic against organizations, including the public sector, throughout 2014.
Following are highlights of various trends observed in the Q4 2014 DDoS Trends Report:
Finally, the increasing availability of DDoS-for-hire services—also known as “booters”—presents a huge risk for security professionals, as they enable virtually anyone to hire skilled cyber criminals to launch a targeted DDoS attack for as little as $2 USD per hour. This quarter’s feature article, “DDoS-for-Hire Services Mean Greater Threat to Business,” outlines how this malicious marketplace works, and presents some sobering details on just how affordable hiring a DDoS attack has become.
For more DDoS trends in Q4, access the full Q4 2014 report here. To read more about what we saw in Q3, including the increase in frequency in DDoS attacks of 10 Gbps in size, which accounted for 20 percent all mitigations in Q3, you can access that report here.
Be sure to check back in a few months when we release our Q1 2015 DDoS Trends Report.
Q4 2014 – DDoS Trends Infographic:
Sponsored byDNIB.com
Sponsored byCSC
Sponsored byVerisign
Sponsored byIPv4.Global
Sponsored byWhoisXML API
Sponsored byRadix
Sponsored byVerisign