Key Country Level DDoS Attack Statistics From Jan 1, 2022 to June 30, 2022 / ISSUE 9: FINDINGS FROM 1ST HALF 2022
Finland
Despite a slight decrease in DDoS attack frequency toward the end of 2021, adversaries unfortunately ramped up their nefarious activities in 1H 2022. Not content to simply rest on their laurels, attackers increasingly used powerful DDoS-capable botnets to launch TCP-based direct path attacks and often tied them to sociopolitical and entertainment events – think war, politics, religion, and sports.
The end result is that adversaries are constantly innovating, trying new attack methods, vectors, and motivations. EMEA experienced a 7 percent increase in DDoS attacks, with many of those tied to the conflict between Russia and Ukraine. The APAC region experienced about 8,600 DDoS attacks per day – or a new attack launched every 10 seconds. The LATAM region experienced an increase of 125 percent in botnet-based TCP floods. And North America experienced 1.04 million DDoS attacks in the six-month period, with adversaries increasingly targeting cloud-related service providers and even primary schools.
Max Multivector Attack
Max number of vectors seen in a single attack
24
Attack Vectors Used
1. ARMS Amplification
2. chargen Amplification
3. CLDAP Amplification
4. COAP Amplification
5. DHCP Discovery Amplification
6. DNS
7. DNS Amplification
8. ICMP
9. mDNS Amplification
10. memcached Amplification
11. MS SQL RS Amplification
12. NetBIOS Amplification
13. NTP Amplification
14. RIPv1 Amplification
15. rpcbind Amplification
16. SNMP Amplification
17. SSDP Amplification
18. TCP ACK
19. TCP RST
20. TCP SYN
21. TCP SYN/ACK Amplification
22. Ubiquiti Amplification
23. UDP
24. VSE Amplification
Top Attack Vectors
Dn
DNS Amp
Number of Attacks
21,402
Np
NTP Amp
Number of Attacks
20,163
Ts
TCP SYN
Number of Attacks
12,372
Ss
SSDP Amp
Number of Attacks
6,649
Cd
CLDAP Amp
Number of Attacks
6,613
Top Nine Vertical Industries Under Attack
The following industry chart shows the most targeted sectors in 1H 2022 by number of attacks.
Rank | Vertical | Frequency | Max Attack | Max Impact | Average Duration |
---|---|---|---|---|---|
1 |
Wireless Telecommunications Carriers (except Satellite)
|
63,750 | 780.36 Gbps | 388.19 Mpps | 54 Minutes |
2 |
Wired Telecommunications Carriers
|
5,407 | 980.17 Gbps | 13.0 Mpps | 26 Minutes |
3 |
Data Processing Hosting and Related Services
|
1,621 | 54.17 Gbps | 6.62 Mpps | 21 Minutes |
4 |
Commercial Banking
|
31 | 0.75 Gbps | 1.81 Mpps | 44 Minutes |
5 |
Internet Publishing and Broadcasting and Web Search Portals
|
25 | 1.3 Gbps | 0.21 Mpps | 80 Minutes |
6 |
Other Motor Vehicle Parts Manufacturing
|
23 | 3.35 Gbps | 0.3 Mpps | 16 Minutes |
7 |
Process Physical Distribution and Logistics Consulting Services
|
3 | 0.3 Gbps | 0.03 Mpps | 9 Minutes |
8 |
All Other Telecommunications
|
2 | 0.0 Gbps | 0.01 Mpps | 7 Minutes |
9 |
Administrative Management and General Management Consulting Services
|
1 | 0.14 Gbps | 0.01 Mpps | 18 Minutes |