Key Country Level DDoS Attack Statistics From Jan 1, 2022 to June 30, 2022 / ISSUE 9: FINDINGS FROM 1ST HALF 2022

Flag of United Kingdom of Great Britain and Northern Ireland

United Kingdom of Great Britain and Northern Ireland

Despite a slight decrease in DDoS attack frequency toward the end of 2021, adversaries unfortunately ramped up their nefarious activities in 1H 2022. Not content to simply rest on their laurels, attackers increasingly used powerful DDoS-capable botnets to launch TCP-based direct path attacks and often tied them to sociopolitical and entertainment events – think war, politics, religion, and sports.

The end result is that adversaries are constantly innovating, trying new attack methods, vectors, and motivations. EMEA experienced a 7 percent increase in DDoS attacks, with many of those tied to the conflict between Russia and Ukraine. The APAC region experienced about 8,600 DDoS attacks per day – or a new attack launched every 10 seconds. The LATAM region experienced an increase of 125 percent in botnet-based TCP floods. And North America experienced 1.04 million DDoS attacks in the six-month period, with adversaries increasingly targeting cloud-related service providers and even primary schools.

Max Multivector Attack

Max number of vectors seen in a single attack

22

Attack Vectors Used

1. ARMS Amplification
2. chargen Amplification
3. CLDAP Amplification
4. DNS Amplification
5. ICMP
6. mDNS Amplification
7. memcached Amplification
8. MS SQL RS Amplification
9. NetBIOS Amplification
10. NTP Amplification
11. RIPv1 Amplification
12. rpcbind Amplification
13. SNMP Amplification
14. SSDP Amplification
15. STUN Amplification
16. TCP ACK
17. TCP RST
18. TCP SYN/ACK Amplification
19. TFTP Amplification
20. UDP
21. Unreal-tournament Amplification
22. WS-DD Amplification

Top Attack Vectors

Ta

TCP ACK

Number of Attacks

22,923

Dn

DNS Amp

Number of Attacks

21,749

Tr

TCP RST

Number of Attacks

20,883

Tk

TCP SYN/ACK Amp

Number of Attacks

15,687

Np

NTP Amp

Number of Attacks

12,874

Top Ten Vertical Industries Under Attack

The following industry chart shows the most targeted sectors in 1H 2022 by number of attacks.

Rank Vertical Frequency Max Attack Max Impact Average Duration
1
Wired Telecommunications Carriers
38,004 322.49 Gbps 114.49 Mpps 79 Minutes
2
cell phone icon Wireless Telecommunications Carriers (except Satellite)
10,499 221.2 Gbps 62.94 Mpps 22 Minutes
3
Data Processing Hosting and Related Services
4,333 83.22 Gbps 17.59 Mpps 29 Minutes
4
All Other Telecommunications
2,939 307.12 Gbps 42.14 Mpps 57 Minutes
5
Electronic Shopping and Mail-Order Houses
436 20.83 Gbps 21.08 Mpps 84 Minutes
6
Securities and Commodity Exchanges
217 0.49 Gbps 0.2 Mpps 12 Minutes
7
Industrial Machinery and Equipment Merchant Wholesalers
216 53.46 Gbps 12.38 Mpps 8 Minutes
8
Electronic Computer Manufacturing
101 4.72 Gbps 0.97 Mpps 14 Minutes
9
Offices of Real Estate Appraisers
89 0.65 Gbps 0.19 Mpps 367 Minutes
10
Television Broadcasting Television Broadcasting
66 0.51 Gbps 0.08 Mpps 146 Minutes