5

Q42014 DDoS Trends

Embed Size (px)

Citation preview

Page 1: Q42014 DDoS Trends
Page 2: Q42014 DDoS Trends

2

Executive Summary

For the period starting Oct. 1, 2014 and ending Dec. 31, 2014, Verisign observed the following key trends:• Sustained attacks reaching 60 Gbps/16 Mpps for UDP floods and

55 Gbps/60 Mpps for TCP-based attacks.

• Average attack size increased to 7.39 gigabits per second (Gbps), rising 14% higher than in Q3 2014 and 245% higher than Q4 2013. 

• The most frequently targeted industry in Q4 was IT Services/Cloud/SaaS, representing one third of all mitigation activity and peaking at just over 60 Gbps.

• A significant increase in the number of attacks against Public–Sector organizations, which represented 15% of all Verisign mitigations in Q4.

Page 3: Q42014 DDoS Trends

3

Attack StatsMitigations by Attack Size:• Q4 attacks averaged 7.39 Gbps, a 14% increase

in average attack size from Q1 2014 and a 245% increase from Q4 2013.

• 42% of attacks leveraged more than 1 Gbps of attack traffic

• Largest volumetric UDP-based attack: 60 Gbps; largest TCP-based attack: 55 Gbps.

Mitigations by Vertical: • IT/Cloud/SaaS had the largest volume of

attacks, making up more than 1/3 of attacks and peaking at just over 60 Gbps in Q4.

• Attacks against Public-Sector customers doubled since Q3 to account for more than 15% of attacks in Q4.

Page 4: Q42014 DDoS Trends

4

Feature: DDoS-for-Hire Services Mean Increased Threat

• DDoS-for-hire services – also known as “booters” – present a huge risk for security professionals, as they enable virtually anyone to hire skilled cyber criminals to launch a targeted DDoS attack.

• “Booters” can be hired today for as little as $5 USD an hour – and some as low as $2 USD an hour (see table), according to Verisign iDefense research.

• Given the ready availability of DDoS-as-a-service offerings, and the increasing affordability of such services, organizations of all sizes and industries are at greater risk than ever of falling victim to a DDoS attack.

• For more information on the DDoS-for-hire threat, please visit www.VerisignInc.com/DDoSTrends

Page 5: Q42014 DDoS Trends

© 2015 VeriSign, Inc. All rights reserved. VERISIGN and other trademarks, service marks, and designs are registered or unregistered trademarks of VeriSign, Inc. and its subsidiaries in the United States and in foreign countries. All other trademarks are property of their respective owners.