Key Country Level DDoS Attack Statistics From Jan 1, 2022 to June 30, 2022 / ISSUE 9: FINDINGS FROM 1ST HALF 2022

Flag of Poland

Poland

Despite a slight decrease in DDoS attack frequency toward the end of 2021, adversaries unfortunately ramped up their nefarious activities in 1H 2022. Not content to simply rest on their laurels, attackers increasingly used powerful DDoS-capable botnets to launch TCP-based direct path attacks and often tied them to sociopolitical and entertainment events – think war, politics, religion, and sports.

The end result is that adversaries are constantly innovating, trying new attack methods, vectors, and motivations. EMEA experienced a 7 percent increase in DDoS attacks, with many of those tied to the conflict between Russia and Ukraine. The APAC region experienced about 8,600 DDoS attacks per day – or a new attack launched every 10 seconds. The LATAM region experienced an increase of 125 percent in botnet-based TCP floods. And North America experienced 1.04 million DDoS attacks in the six-month period, with adversaries increasingly targeting cloud-related service providers and even primary schools.

Max Multivector Attack

Max number of vectors seen in a single attack

23

Attack Vectors Used

1. chargen Amplification
2. CLDAP Amplification
3. DHCP Discovery Amplification
4. DNS Amplification
5. ICMP
6. mDNS Amplification
7. memcached Amplification
8. MS SQL RS Amplification
9. NetBIOS Amplification
10. NTP Amplification
11. openvpn Amplification
12. RIPv1 Amplification
13. rpcbind Amplification
14. Sentinel Amplification
15. SNMP Amplification
16. SSDP Amplification
17. TCP ACK
18. TCP SYN
19. TCP SYN/ACK Amplification
20. Ubiquiti Amplification
21. UDP
22. Unreal-tournament Amplification
23. WS-DD Amplification

Top Attack Vectors

Dn

DNS Amp

Number of Attacks

34,966

Ta

TCP ACK

Number of Attacks

32,710

Np

NTP Amp

Number of Attacks

23,884

Im

ICMP

Number of Attacks

19,293

Tk

TCP SYN/ACK Amp

Number of Attacks

18,129

Top Eight Vertical Industries Under Attack

The following industry chart shows the most targeted sectors in 1H 2022 by number of attacks.

Rank Vertical Frequency Max Attack Max Impact Average Duration
1
Wired Telecommunications Carriers
41,108 430.87 Gbps 152.44 Mpps 23 Minutes
2
cell phone icon Wireless Telecommunications Carriers (except Satellite)
10,291 163.95 Gbps 117.19 Mpps 44 Minutes
3
Data Processing Hosting and Related Services
893 119.9 Gbps 25.33 Mpps 12 Minutes
4
All Other Telecommunications
87 12.38 Gbps 2.69 Mpps 9 Minutes
5
All Other Professional Scientific and Technical Services
17 17.15 Gbps 3.96 Mpps 8 Minutes
6
Colleges Universities and Professional Schools
7 1.13 Gbps 0.3 Mpps 8 Minutes
7
vault icon Commercial Banking
6 0.35 Gbps 0.09 Mpps 28 Minutes
8
Other Management Consulting Services
5 0.68 Gbps 1.83 Mpps 5 Minutes