Most DDoS Attacks Originate from Fewer than 50 Hosting Companies

Most DDoS Attacks Originate from Fewer than 50 Hosting Companies
Depositphotos

Nokia Deepfield announced the results of its global DDoS traffic analysis, which examined service provider network traffic encompassing thousands of routers on the internet between January 2020 and May 2021. The study found more than 100% increase in daily DDoS peak traffic in this time period, and identified DDoS threat potential over 10 Tbps as four to five times higher than the largest current attacks reported due to rapidly growing number of open and insecure internet services and IoT devices.

In an environment where attackers constantly leverage opportunistic resources to source their attacks, Nokia Deepfield found in the past 15 months accessibility of DDoS for hire services has increased the threat potential of the existing botnet, IoT and cloud-based attack models. The results trace the origins of most of the high-bandwidth, high-intensity (volumetric) attacks to a limited number of internet domains, finding that most global DDoS attacks (by frequency and traffic volume) originate in less than 50 hosting companies and regional providers.

As COVID lockdown measures were implemented in 2020, there was a 40-50% increase in DDoS traffic. The continued increases in intensity, frequency and sophistication of DDoS attacks have resulted in a 100% increase in the “high watermark levels“ of DDoS daily peaks - from 1.5 Tbps (January 2020) to over 3 Tbps (May 2021).

“It is equally important for every participant in the network security ecosystem to understand the dangers DDoS poses to the availability of internet content, applications and critical connectivity services. With this knowledge and a community commitment to solving the DDoS problem, we can go a long way towards making our networks, services and subscribers more secure,“ said Craig Labovitz, CTO at Nokia Deepfield.

“With the new Nokia Deepfield Defender solution, we take a unique approach in leveraging the combined power of high-performance IP networks and big data analytics to protect the network on all fronts from all volumetric DDoS attacks, at petabit scale, without lifting a hand. It will allow network operators to make a big leap towards improving overall security and availability of their networks and services for all their customers,“ added Labovitz.