Key Country Level DDoS Attack Statistics From Jan 1, 2022 to June 30, 2022 / ISSUE 9: FINDINGS FROM 1ST HALF 2022

Flag of Russian Federation

Russian Federation

Despite a slight decrease in DDoS attack frequency toward the end of 2021, adversaries unfortunately ramped up their nefarious activities in 1H 2022. Not content to simply rest on their laurels, attackers increasingly used powerful DDoS-capable botnets to launch TCP-based direct path attacks and often tied them to sociopolitical and entertainment events – think war, politics, religion, and sports.

The end result is that adversaries are constantly innovating, trying new attack methods, vectors, and motivations. EMEA experienced a 7 percent increase in DDoS attacks, with many of those tied to the conflict between Russia and Ukraine. The APAC region experienced about 8,600 DDoS attacks per day – or a new attack launched every 10 seconds. The LATAM region experienced an increase of 125 percent in botnet-based TCP floods. And North America experienced 1.04 million DDoS attacks in the six-month period, with adversaries increasingly targeting cloud-related service providers and even primary schools.

Max Multivector Attack

Max number of vectors seen in a single attack

24

Attack Vectors Used

1. chargen Amplification
2. CLDAP Amplification
3. COAP Amplification
4. DHCP Discovery Amplification
5. DNS
6. DNS Amplification
7. ICMP
8. L2TP Amplification
9. mDNS Amplification
10. memcached Amplification
11. MS SQL RS Amplification
12. NetBIOS Amplification
13. NTP Amplification
14. RDP Amplification
15. RIPv1 Amplification
16. rpcbind Amplification
17. SNMP Amplification
18. SSDP Amplification
19. TCP ACK
20. TCP NULL
21. TCP RST
22. TCP SYN
23. TCP SYN/ACK Amplification
24. UDP

Top Attack Vectors

Ts

TCP SYN

Number of Attacks

59,788

Ds

DNS

Number of Attacks

35,179

Ta

TCP ACK

Number of Attacks

28,697

Tk

TCP SYN/ACK Amp

Number of Attacks

18,478

Tr

TCP RST

Number of Attacks

17,837

Top Ten Vertical Industries Under Attack

The following industry chart shows the most targeted sectors in 1H 2022 by number of attacks.

Rank Vertical Frequency Max Attack Max Impact Average Duration
1
All Other Telecommunications
105,143 41.71 Gbps 19.43 Mpps 126 Minutes
2
Wired Telecommunications Carriers
3,420 187.85 Gbps 43.39 Mpps 248 Minutes
3
Data Processing Hosting and Related Services
2,156 79.46 Gbps 66.52 Mpps 23 Minutes
4
All Other Professional Scientific and Technical Services
444 46.54 Gbps 12.96 Mpps 90 Minutes
5
cell phone icon Wireless Telecommunications Carriers (except Satellite)
352 102.58 Gbps 9.48 Mpps 102 Minutes
6
Electronic Computer Manufacturing
134 151.65 Gbps 15.57 Mpps 10 Minutes
7
Computer and Office Machine Repair and Maintenance
85 17.57 Gbps 3.27 Mpps 27 Minutes
8
Software Publishers
73 4.82 Gbps 0.43 Mpps 53 Minutes
9
Full-Service Restaurants
30 0.01 Gbps 0.04 Mpps 15 Minutes
10
Television Broadcasting Television Broadcasting
16 2.56 Gbps 0.84 Mpps 12 Minutes