Key metrics from the 1H 2022 Netscout DDoS Threat Intelligence Report / ISSUE 9: FINDINGS FROM 1ST HALF 2022

Flag of India

India

Despite a slight decrease in DDoS attack frequency toward the end of 2021, adversaries unfortunately ramped up their nefarious activities in 1H 2022. Not content to simply rest on their laurels, attackers increasingly used powerful DDoS-capable botnets to launch TCP-based direct path attacks and often tied them to sociopolitical and entertainment events – think war, politics, religion, and sports.

The end result is that adversaries are constantly innovating, trying new attack methods, vectors, and motivations. EMEA experienced a 7 percent increase in DDoS attacks, with many of those tied to the conflict between Russia and Ukraine. The APAC region experienced about 8,600 DDoS attacks per day – or a new attack launched every 10 seconds. The LATAM region experienced an increase of 125 percent in botnet-based TCP floods. And North America experienced 1.04 million DDoS attacks in the six-month period, with adversaries increasingly targeting cloud-related service providers and even primary schools.

Max Multivector Attack

Max number of vectors seen in a single attack

20

Attack Vectors Used

1. chargen Amplification
2. CLDAP Amplification
3. DNS
4. DNS Amplification
5. ICMP
6. ISAKMP
7. mDNS Amplification
8. memcached Amplification
9. MS SQL RS Amplification
10. NetBIOS Amplification
11. NTP Amplification
12. RIPv1 Amplification
13. rpcbind Amplification
14. SIP Amplification
15. SNMP Amplification
16. SSDP Amplification
17. TCP ACK
18. TCP RST
19. TCP SYN
20. UDP

Top 5 Attack Vectors

Ta

TCP ACK

Number of Attacks

47,047

Im

ICMP

Number of Attacks

36,231

Tr

TCP RST

Number of Attacks

35,302

Ts

TCP SYN

Number of Attacks

33,403

Tk

TCP SYN/ACK Amp

Number of Attacks

18,408

Top Ten Vertical Industries Under Attack

The following industry chart shows the most targeted sectors in 1H 2022 by number of attacks.

Rank Vertical Frequency Max Attack Max Impact Average Duration
1
three wires with plugs icon Wired Telecommunications Carriers
119,558 519 Gbps 212 Mpps 3259 Minutes
2
Data Processing Hosting and Related Services
35,068 305 Gbps 42 Mpps 14371 Minutes
3
cell phone icon Wireless Telecommunications Carriers (except Satellite)
16,898 131 Gbps 16 Mpps 2303 Minutes
4
cell tower icon All Other Telecommunications
9,537 27 Gbps 7 Mpps 1313 Minutes
5
grocery cart icon Electronic Shopping and Mail-Order Houses
1,081 70 Gbps 8 Mpps 2338 Minutes
6
Software Publishers
474 7 Gbps 0 Mpps 2285 Minutes
7
Electronic Computer Manufacturing
341 14 Gbps 2 Mpps 723 Minutes
8
vault icon Commercial Banking
198 0 Gbps 0 Mpps 1712 Minutes
9
Computer Storage Device Manufacturing
189 13 Gbps 3 Mpps 2024 Minutes
10
Electronics Stores
148 0 Gbps 0 Mpps 908 Minutes