Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

4/1/2008
09:50 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

A Peek at ISP DDOS, Spam Traffic Trends

An average of 1,300 distributed denial-of-service attacks hit each day, according to data from Arbor Networks's ISP customers

Here’s another perspective on the rise in malicious Internet traffic: Nearly 5 percent of all Internet traffic among ISP domains consists of either DDOS or spam, according to preliminary statistics gathered by Arbor Networks of around 70 of its ISP customers.

And there’s an average of 1,300 distributed denial-of-service attacks occurring each day, according to data gathered by Arbor over the past year and a half via its Atlas program.

Five percent may not sound like a lot at first glance, but it’s a disturbing statistic when you put it into context, according to Danny McPherson, chief research officer with Arbor. “How much junk would you allow in your drinking water? Or, if you could improve service or margins or download speeds by 5 percent, what would that mean to your business?”

Arbor has been working with 68 ISPs under its Atlas program, gathering network and transport layer traffic data -- inter-domain, rather than ISP customer or internal traffic. The data comes from around 1,300 routers and 100,000 interfaces, according to Arbor, with peak traffic rates close to 1.5 Tbit/s.

DDOS attacks accounted for around 1 to 3 percent of all of this traffic (not including spam, phishing, or other malicious traffic). SMTP email in Port 25, meanwhile, is about 1 to 1.5 percent of ISP inter-domain traffic, according to Arbor’s findings. And over half of that is likely spam, according to McPherson, so that makes nearly 4 percent of all inter-domain traffic “junk,” although Arbor has seen spikes up to 5 percent at times.

McPherson says Arbor also found that nine of the 10 most frequently attacked DDOS targets were IRC servers -- “ego-driven” attacks mostly. The most common DDOS attack vectors are TCP SYN flood attacks, with ICMP floods as the second most common.

And in case you were wondering, cybercriminals do take holidays: “Attack frequency seems to drop significantly on Christmas Day, New Year’s Eve, and New Years Day (perhaps while the miscreants are either hung over or expending their spoils),” McPherson wrote in a blog post yesterday.

Arbor plans to issue a formal, more detailed report in the next few months on malicious traffic trends ISPs are experiencing.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • Arbor Networks Inc.

    Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    Data Leak Week: Billions of Sensitive Files Exposed Online
    Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/10/2019
    Lessons from the NSA: Know Your Assets
    Robert Lemos, Contributing Writer,  12/12/2019
    4 Tips to Run Fast in the Face of Digital Transformation
    Shane Buckley, President & Chief Operating Officer, Gigamon,  12/9/2019
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon
    Current Issue
    The Year in Security: 2019
    This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
    Flash Poll
    Rethinking Enterprise Data Defense
    Rethinking Enterprise Data Defense
    Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2019-19807
    PUBLISHED: 2019-12-15
    In the Linux kernel before 5.3.11, sound/core/timer.c has a use-after-free caused by erroneous code refactoring, aka CID-e7af6307a8a5. This is related to snd_timer_open and snd_timer_close_locked. The timeri variable was originally intended to be for a newly created timer instance, but was used for ...
    CVE-2014-8650
    PUBLISHED: 2019-12-15
    python-requests-Kerberos through 0.5 does not handle mutual authentication
    CVE-2014-3536
    PUBLISHED: 2019-12-15
    CFME (CloudForms Management Engine) 5: RHN account information is logged to top_output.log during registration
    CVE-2014-3643
    PUBLISHED: 2019-12-15
    jersey: XXE via parameter entities not disabled by the jersey SAX parser
    CVE-2014-3652
    PUBLISHED: 2019-12-15
    JBoss KeyCloak: Open redirect vulnerability via failure to validate the redirect URL.