Key Country Level DDoS Attack Statistics From Jan 1, 2022 to June 30, 2022 / ISSUE 9: FINDINGS FROM 1ST HALF 2022

Flag of Germany

Germany

Despite a slight decrease in DDoS attack frequency toward the end of 2021, adversaries unfortunately ramped up their nefarious activities in 1H 2022. Not content to simply rest on their laurels, attackers increasingly used powerful DDoS-capable botnets to launch TCP-based direct path attacks and often tied them to sociopolitical and entertainment events – think war, politics, religion, and sports.

The end result is that adversaries are constantly innovating, trying new attack methods, vectors, and motivations. EMEA experienced a 7 percent increase in DDoS attacks, with many of those tied to the conflict between Russia and Ukraine. The APAC region experienced about 8,600 DDoS attacks per day – or a new attack launched every 10 seconds. The LATAM region experienced an increase of 125 percent in botnet-based TCP floods. And North America experienced 1.04 million DDoS attacks in the six-month period, with adversaries increasingly targeting cloud-related service providers and even primary schools.

Max Multivector Attack

Max number of vectors seen in a single attack

25

Attack Vectors Used

1. ARMS Amplification
2. chargen Amplification
3. CLDAP Amplification
4. DHCP Discovery Amplification
5. DNS Amplification
6. ICMP
7. L2TP Amplification
8. memcached Amplification
9. MS SQL RS Amplification
10. NetBIOS Amplification
11. NTP Amplification
12. OpenVPN Amplification
13. Quake Amplification
14. RIPv1 Amplification
15. rpcbind Amplification
16. SNMP Amplification
17. SSDP Amplification
18. TCP ACK
19. TCP RST
20. TCP SYN
21. TCP SYN/ACK Amplification
22. Ubiquiti Amplification
23. UDP
24. VSE Amplification
25. WS-DD Amplification

Top Attack Vectors

Ta

TCP ACK

Number of Attacks

18,383

Ts

TCP SYN

Number of Attacks

16,364

Np

NTP Amp

Number of Attacks

12,177

Tr

TCP RST

Number of Attacks

12,051

Im

ICMP

Number of Attacks

11,448

Top Ten Vertical Industries Under Attack

The following industry chart shows the most targeted sectors in 1H 2022 by number of attacks.

Rank Vertical Frequency Max Attack Max Impact Average Duration
1
Data Processing Hosting and Related Services
14,708 606.17 Gbps 124.7 Mpps 23 Minutes
2
Wired Telecommunications Carriers
6,504 122.89 Gbps 48.62 Mpps 26 Minutes
3
Electronic Shopping and Mail-Order Houses
4,333 29.17 Gbps 7.58 Mpps 16 Minutes
4
cell phone icon Wireless Telecommunications Carriers (except Satellite)
2,578 84.44 Gbps 67.16 Mpps 68 Minutes
5
Offices of Dentists
148 7.65 Gbps 1.7 Mpps 22 Minutes
6
All Other Telecommunications
137 3.94 Gbps 3.37 Mpps 31 Minutes
7
Aircraft Engine and Engine Parts Manufacturing
81 1.08 Gbps 0.25 Mpps 51 Minutes
8
Computer Storage Device Manufacturing
75 10.13 Gbps 2.7 Mpps 18 Minutes
9
Other Residential Care Facilities
70 36.67 Gbps 8.49 Mpps 7 Minutes
10
All Other Miscellaneous Manufacturing
66 4.96 Gbps 0.46 Mpps 5 Minutes