Key Country Level DDoS Attack Statistics From Jan 1, 2022 to June 30, 2022 / ISSUE 9: FINDINGS FROM 1ST HALF 2022

Flag of United States of America

United States of America

Despite a slight decrease in DDoS attack frequency toward the end of 2021, adversaries unfortunately ramped up their nefarious activities in 1H 2022. Not content to simply rest on their laurels, attackers increasingly used powerful DDoS-capable botnets to launch TCP-based direct path attacks and often tied them to sociopolitical and entertainment events – think war, politics, religion, and sports.

The end result is that adversaries are constantly innovating, trying new attack methods, vectors, and motivations. EMEA experienced a 7 percent increase in DDoS attacks, with many of those tied to the conflict between Russia and Ukraine. The APAC region experienced about 8,600 DDoS attacks per day – or a new attack launched every 10 seconds. The LATAM region experienced an increase of 125 percent in botnet-based TCP floods. And North America experienced 1.04 million DDoS attacks in the six-month period, with adversaries increasingly targeting cloud-related service providers and even primary schools.

Max Multivector Attack

Max number of vectors seen in a single attack

27

Attack Vectors Used

1. ARMS Amplification
2. chargen Amplification
3. CLDAP Amplification
4. COAP Amplification
5. DNS
6. DNS Amplification
7. ICMP
8. ISAKMP
9. mDNS Amplification
10. memcached Amplification
11. MS SQL RS Amplification
12. NetBIOS Amplification
13. NTP Amplification
14. RDP Amplification
15. RIPv1 Amplification
16. rpcbind Amplification
17. SIP Amplification
18. SNMP Amplification
19. SSDP Amplification
20. TCP ACK
21. TCP RST
22. TCP SYN
23. TCP SYN/ACK Amplification
24. UDP
25. UDP Fragment
26. WS-DD Amplification
27. WS-Discovery Amplification

Top Attack Vectors

Ts

TCP SYN

Number of Attacks

262,145

Ta

TCP ACK

Number of Attacks

202,881

Dn

DNS Amp

Number of Attacks

144,779

Tr

TCP RST

Number of Attacks

140,059

Im

ICMP

Number of Attacks

137,847

Top Ten Vertical Industries Under Attack

The following industry chart shows the most targeted sectors in 1H 2022 by number of attacks.

Rank Vertical Frequency Max Attack Max Impact Average Duration
1
Wired Telecommunications Carriers
351,272 482.35 Gbps 199.87 Mpps 70 Minutes
2
Data Processing Hosting and Related Services
152,627 462.38 Gbps 136.45 Mpps 103 Minutes
3
cell phone icon Wireless Telecommunications Carriers (except Satellite)
68,931 214.05 Gbps 25.33 Mpps 38 Minutes
4
Satellite Telecommunications
40,067 52.36 Gbps 10.22 Mpps 154 Minutes
5
All Other Professional Scientific and Technical Services
36,054 648.17 Gbps 127.73 Mpps 169 Minutes
6
Internet Publishing and Broadcasting and Web Search Portals
31,328 59.13 Gbps 84.14 Mpps 191 Minutes
7
Electronic Computer Manufacturing
12,486 72.19 Gbps 16.71 Mpps 81 Minutes
8
Electronic Shopping and Mail-Order Houses
10,711 200.07 Gbps 107.25 Mpps 21 Minutes
9
Elementary and Secondary Schools
8,473 95.79 Gbps 23.59 Mpps 19 Minutes
10
Automobile Manufacturing
6,470 313.19 Gbps 1.96 Mpps 35 Minutes