Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

2/5/2020
07:00 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Majority of Network, App-Layer DDoS Attacks in 2019 Were Small

Attacks turned to cheaper, shorter attacks to try and disrupt targets, Imperva analysis shows.

Distributed denial of service attacks appear to be getting smaller, shorter, and more persistent.

An analysis by Imperva of DDoS attack data from 2019 showed that more than 51% of network layer DDoS attacks lasted barely 15 minutes and another 10% or so for between 15 and 30 minutes. Only about one-in-five attacks lasted more than an hour and about four percent for between six and 12 hours.

The security vendor attributed the trend to the increasing availability and use of so-called "stresser" or DDoS for hire services that allow almost anyone to launch small attacks against targets of their choice for prices starting at around $5.

"Short duration attacks are cheaper," says Johnathan Azaria, data scientist at Imperva. "They disrupt the site’s function for the duration they're active and have a chance of crashing the site."

Though relatively small in nature, for victims such attacks can be disruptive all the same. Often though it might take just a few minutes to knock a site offline, recovery can take much longer, Azaria says. "In some cases the attack causes the website to shut down, not just slow down. It might be just a process that crashed, or that the server fell and needs to restart." When multiple processes and servers are involved, getting restarted even after a small DDoS attack can be time-consuming, Azaria says.

Criminals have long used DDoS attacks for a variety of reasons, including extortion, vandalism, hacktivism, and business rivalry. Many security experts expect a sharp increase in DDoS attacks this year by actors seeking to impact and influence the US presidential elections.

Just this week for instance, the FBI reportedly issued a so-called Private Industry Notification (PIN) alerting about a DDoS campaign that targeted a state voter registration and voter information website.

In this particular case, the attackers reportedly hit the DNS server of the voter registration website with short bursts of DNS requests in a bid to crash the server. BleepingComputer, which was the first to report on the so-called Pseudo Random Subdomain (PRSD) DDoS attack on the voter registration site, described it as occurring in short bursts over a one-month period.

"PRSD attacks are a type of DNS flood," says Avishay Zawoznik, Security Research Manager at Imperva. Such attacks have the potential to exhaust the resources of the authoritative server and limit its ability to function properly.

PSRD attacks are relatively easy to pull off and are likely available as part of some DDoS for hire services. "The nature of the attack is simple and easy to pull off, assuming the attacker has enough bandwidth," Zawoznik says.

Imperva's analysis showed that about two-thirds of those who were attacked last year were hit up to five times with short duration DDoS floods. Twenty-five percent were attacked 10 times or more.

Imperva defines a single DDoS attack as one that lasts at least five minutes. Azaria says. A network-layer DDoS attack is considered finished after three hours have passed with no malicious traffic detected. For application layer attacks, the company's threshold for an attack to be considered as finished is 30 minutes without malicious traffic.

Small Attacks

About nine-in-10 (87%) of DDoS attacks at the network layer were small and topped out at 50 Gbps. Ninety-seven percent reached no more than 50 Mpps (million packets per second).

Application layer DDoS attacks—which are designed to deplete system resources such as CPU and RAM—were similarly small with most topping out at about 1,000 requests per second. As with network layer attacks, Imperva attributed the relatively small nature of application level attacks to the use of stresser services.

Some 3,643 of the DDoS attacks that Imperva helped customers address happened at the network layer and 42,390 were application layer DDoS attacks. For those hit by such attacks, the type of DDoS flood unlikely makes much of a difference from an impact standpoint, Azaria says. "It really depends on the skills of the attacker and how well he knows his target," he says. "Both can cause the website to malfunction to a point it's not usable. Both can be difficult to mitigate.

"A majority of the machines used to launch application and network layer DDoS attacks last year were located in China and the Philippines, Imperva noted.

Organizations in the fiercely competitive gaming and gambling sectors continued to be the most heavily targeted in DDoS attacks last year, followed by technology companies and business entities. From a regional standpoint organizations in India were most heavily targeted in DDoS attacks last year.

Related Content:

Check out The Edge, Dark Reading's new section for features, threat data, and in-depth perspectives. Today's top story: "C-Level & Studying for the CISSP."

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
44% of Security Threats Start in the Cloud
Kelly Sheridan, Staff Editor, Dark Reading,  2/19/2020
Zero-Factor Authentication: Owning Our Data
Nick Selby, Chief Security Officer at Paxos Trust Company,  2/19/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
6 Emerging Cyber Threats That Enterprises Face in 2020
This Tech Digest gives an in-depth look at six emerging cyber threats that enterprises could face in 2020. Download your copy today!
Flash Poll
How Enterprises Are Developing and Maintaining Secure Applications
How Enterprises Are Developing and Maintaining Secure Applications
The concept of application security is well known, but application security testing and remediation processes remain unbalanced. Most organizations are confident in their approach to AppSec, although others seem to have no approach at all. Read this report to find out more.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-4537
PUBLISHED: 2020-02-26
IBM WebSphere Service Registry and Repository 8.5 could allow a user to obtain sensitive version information that could be used in further attacks against the system. IBM X-Force ID: 165593.
CVE-2019-4596
PUBLISHED: 2020-02-26
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session...
CVE-2019-4597
PUBLISHED: 2020-02-26
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 167880.
CVE-2019-4598
PUBLISHED: 2020-02-26
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 167881.
CVE-2019-4726
PUBLISHED: 2020-02-26
IBM Sterling B2B Integrator Standard Edition 5.2.0.0 through 5.2.6.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 172363.