Key Country Level DDoS Attack Statistics From Jan 1, 2022 to June 30, 2022 / ISSUE 9: FINDINGS FROM 1ST HALF 2022

Flag of Brazil

Brazil

Despite a slight decrease in DDoS attack frequency toward the end of 2021, adversaries unfortunately ramped up their nefarious activities in 1H 2022. Not content to simply rest on their laurels, attackers increasingly used powerful DDoS-capable botnets to launch TCP-based direct path attacks and often tied them to sociopolitical and entertainment events – think war, politics, religion, and sports.

The end result is that adversaries are constantly innovating, trying new attack methods, vectors, and motivations. EMEA experienced a 7 percent increase in DDoS attacks, with many of those tied to the conflict between Russia and Ukraine. The APAC region experienced about 8,600 DDoS attacks per day – or a new attack launched every 10 seconds. The LATAM region experienced an increase of 125 percent in botnet-based TCP floods. And North America experienced 1.04 million DDoS attacks in the six-month period, with adversaries increasingly targeting cloud-related service providers and even primary schools.

Max Multivector Attack

Max number of vectors seen in a single attack

21

Attack Vectors Used

1. chargen Amplification
2. CLDAP Amplification
3. DNS
4. DNS Amplification
5. ICMP
6. ISAKMP
7. mDNS Amplification
8. memcached Amplification
9. MS SQL RS Amplification
10. NetBIOS Amplification
11. NTP Amplification
12. RIPv1 Amplification
13. rpcbind Amplification
14. SNMP Amplification
15. SSDP Amplification
16. TCP ACK
17. TCP RST
18. TCP SYN
19. Ubiquiti Amplification
20. UDP
21. Unreal-tournament Amplification

Top Attack Vectors

Ta

TCP ACK

Number of Attacks

74,996

Dn

DNS Amp

Number of Attacks

52,369

Tr

TCP RST

Number of Attacks

41,204

Tk

TCP SYN/ACK Amp

Number of Attacks

40,956

Ts

TCP SYN

Number of Attacks

39,437

Top Ten Vertical Industries Under Attack

The following industry chart shows the most targeted sectors in 1H 2022 by number of attacks.

Rank Vertical Frequency Max Attack Max Impact Average Duration
1
cell phone icon Wireless Telecommunications Carriers (except Satellite)
32,010 299.21 Gbps 63.43 Mpps 252 Minutes
2
Wired Telecommunications Carriers
13,982 450.79 Gbps 98.68 Mpps 80 Minutes
3
All Other Telecommunications
2,270 25.57 Gbps 15.35 Mpps 32 Minutes
4
hands in prayer icon Religious Organizations
2,128 1.54 Gbps 0.3 Mpps 186 Minutes
5
vault icon Commercial Banking
465 6.1 Gbps 0.53 Mpps 66 Minutes
6
Data Processing Hosting and Related Services
381 38.37 Gbps 4.56 Mpps 746 Minutes
7
Electronic Computer Manufacturing
183 17.88 Gbps 40.16 Mpps 41 Minutes
8
Offices of Physicians (except Mental Health Specialists)
91 0.3 Gbps 0.03 Mpps 44 Minutes
9
Computer Storage Device Manufacturing
89 3.36 Gbps 2.59 Mpps 9 Minutes
10
Internet Publishing and Broadcasting and Web Search Portals
85 2.01 Gbps 0.6 Mpps 12 Minutes