Key metrics from the 1H 2022 Netscout DDoS Threat Intelligence Report / ISSUE 9: FINDINGS FROM 1ST HALF 2022

Flag of France

France

Despite a slight decrease in DDoS attack frequency toward the end of 2021, adversaries unfortunately ramped up their nefarious activities in 1H 2022. Not content to simply rest on their laurels, attackers increasingly used powerful DDoS-capable botnets to launch TCP-based direct path attacks and often tied them to sociopolitical and entertainment events – think war, politics, religion, and sports.

The end result is that adversaries are constantly innovating, trying new attack methods, vectors, and motivations. EMEA experienced a 7 percent increase in DDoS attacks, with many of those tied to the conflict between Russia and Ukraine. The APAC region experienced about 8,600 DDoS attacks per day – or a new attack launched every 10 seconds. The LATAM region experienced an increase of 125 percent in botnet-based TCP floods. And North America experienced 1.04 million DDoS attacks in the six-month period, with adversaries increasingly targeting cloud-related service providers and even primary schools.

Max Multivector Attack

Max number of vectors seen in a single attack

21

Attack Vectors Used

1. ARMS
2. chargen Amplification
3. CLDAP Amplification
4. DHCP Discovery Amplification
5. DNS
6. DNS Amplification
7. ICMP
8. mDNS Amplification
9. memcached Amplification
10. MS SQL RS Amplification
11. NetBIOS Amplification
12. NTP Amplification
13. rpcbind Amplification
14. SNMP Amplification
15. SSDP Amplification
16. TCP ACK
17. TCP RST
18. TCP SYN
19. TCP SYN/ACK Amplification
20. UDP
21. WS-DD Amplification

Top 5 Attack Vectors

Ta

TCP ACK

Number of Attacks

34,756

Im

ICMP

Number of Attacks

26,017

Dn

DNS Amp

Number of Attacks

24,120

Np

NTP Amp

Number of Attacks

20,569

Ts

TCP SYN

Number of Attacks

17,937

Top Ten Vertical Industries Under Attack

The following industry chart shows the most targeted sectors in 1H 2022 by number of attacks.

Rank Vertical Frequency Max Attack Max Impact Average Duration
1
cell phone icon Wireless Telecommunications Carriers (except Satellite)
40,025 308 Gbps 284 Mpps 5717 Minutes
2
three wires with plugs icon Wired Telecommunications Carriers
37,856 423 Gbps 152 Mpps 5466 Minutes
3
Data Processing Hosting and Related Services
6,323 78 Gbps 105 Mpps 2561 Minutes
4
New Car Dealers
3,610 72 Gbps 12 Mpps 13029 Minutes
5
Electronic Computer Manufacturing
783 5 Gbps 1 Mpps 2613 Minutes
6
vault icon Commercial Banking
721 0 Gbps 0 Mpps 810 Minutes
7
grocery cart icon Electronic Shopping and Mail-Order Houses
650 2 Gbps 0 Mpps 1195 Minutes
8
Investment Banking and Securities Dealing
331 0 Gbps 0 Mpps 1811 Minutes
9
cell tower icon All Other Telecommunications
153 6 Gbps 2 Mpps 1201 Minutes
10
Optical Instrument and Lens Manufacturing
41 0 Gbps 0 Mpps 2052 Minutes