DDOS attacks decrease in Q4 2017: Verisign

Verisign observed a 25 percent decrease in the number of attacks in Q4 2017 compared to Q3 2017 and an 850 percent increase in the average of attack peak sizes.

Verisign Mar 28th 2018

Verisign Distribution Denial of Service trends, observed attack trends of October, December, the fourth quarter of 2017. These trends include attack statistics, behavioural trends and future outlook. Compiled on the basis of observations and insights about attack frequency and size obtained from mitigations enacted on behalf of customers from Verisign DDOS Protection Services.

Verisign observed the following key trends in Q4 2017:

  • Number of attacks - 25 percent decrease compared to the third quarter of 2017 from July 1, 2017 through September 30, 2017 (Q3 2017)
  • Peak attack size -  (volume) 53 Gigabits per second (Gbps), (Speed) 5 Million packets per second (Mpps)
  • Average peak attack size – 7.6 Gbps ( 850 percent increase compared to Q3 2017, but a 32 percent year-over-year decrease compared to Q4 2016), 40 percent of attacks over 5 Gbps
  • Most common attack mitigated - 42 percent of attacks were User Datagram Protocol (UDP) floods; 82 percent of attacks employed multiple attack types

DDoS attacks vary in speed and complexity

Verisign observed a 25 percent decrease in the number of attacks in Q4 2017 compared to Q3 2017 and an 850 percent increase in the average of attack peak sizes. This large increase is partially attributed to the historically low average of attack peak sizes observed in Q3 2017. From Q4 2016 to Q4 2017, Verisign observed a year-over-year decrease of 32 percent in the average of attack peak sizes. Verisign also observed that 25 percent of customers who experienced DDoS attacks in Q4 2017 were targeted multiple times during the quarter. While the number of DDoS attacks has continued to decrease from quarter to quarter, DDoS attacks remain unpredictable in speed and complexity.

Multi-vector DDoS attacks remain constant

Eighty-two percent of DDoS attacks mitigated by Verisign in Q4 2017 employed multiple attack types. Verisign observed attacks targeting networks at multiple layers and attack types that changed over the course of a DDoS event. Today’s DDoS attacks require continuous monitoring to optimize mitigation strategies.

Types of DDoS Attacks

Continuing the trend, UDP flood attacks were the most common attack vector in Q4 2017, accounting for 42 percent of total attacks in the quarter. The most common UDP floods included Domain Name System (DNS), Network Time Protocol (NTP), Lightweight Directory Access Protocol (LDAP) and Simple Service Discovery Protocol (SSDP) reflective amplification attacks.

Largest Volumetric Attack and Highest Intensity Flood Attack

The largest volumetric and highest intensity DDoS attack observed by Verisign in Q4 2017 was a multi-vector attack that peaked at approximately 53 Gbps and over 5 Mpps. This attack sent a flood of traffic to the targeted network for about an hour. The attack consisted of a wide range of attack vectors including TCP SYN and TCP RST floods, DNS amplification attacks, Internet Control Message Protocol (ICMP) floods and invalid packets.

Mitigations on Behalf of Verisign Customers by Industry for Q3 20172**

  • IT Services/Cloud/SaaS
  • 33 percent of mitigations
  • 1.9 Gbps remains the average attack size
  • Financial
  • 40 percent of mitigations
  • 13 Gbps remains the average attack size
  • Media and Entertainment content
  • 7 percent of mitigations
  • <1 Gbps remains the average attack size
  • Telecom
  • 13 percent of mitigations
  • 1.7 Gbps average attack size
  • E-commerce and online advertising
  • 7 percent of mitigations
  • 22.2 Gbps remains the average attack size