SlideShare a Scribd company logo
1 of 10
Overview of Prolexic Quarterly DDoS Attack Report
Q1 2013
www.prolexic.com
www.prolexic.com
Prolexic Quarterly DDoS Attack Report: Q1 2013
• What happened in Q1 2013?
– The most formidable distributed denial of service
(DDoS) attacks to date
– More than 10 percent of attacks exceeded 60
Gigabits per second (Gbps)
– The headline-making Spamhaus.org attack
2
May 2013 www.prolexic.com
www.prolexic.com
Average Bandwidth of DDoS Attacks in Q1 2013
• Volumetric bandwidth averaged an attention-
grabbing 48.25 Gbps
3
www.prolexic.com
Emerging DDoS Attack Trends: Q1 2013
• Important trends?
– Targeting Internet Service Providers (ISPs) and
Carrier router infrastructures
– High average packets-per-second (PPS)
• Greater average than most DDoS mitigation equipment
capacity.
• Even routers carrying traffic to the mitigation
equipment would be strained at this level
– See full report for details on PPS trends
4
www.prolexic.com
Analysis of Attack Types: Q1 2013
• Attackers focused on infrastructure attacks
• Favored application attacks were:
– SYN
– GET
– UDP
– ICMP
• Download the full report for percentages and graphs by attack
type, including attack volume and trends
5
www.prolexic.com
DDoS Attack Frequency in Q1: 2013 vs 2012
• Prolexic mitigated more DDoS attacks than ever in Q1 2013
• The month of March accounted for nearly half of all Q1
attacks (44 percent)
6
www.prolexic.com
Top Ten Source Countries: DDoS Attacks in Q1 2013
7
www.prolexic.com
DDoS Attack Case Study: An Enterprise (Q1 2013)
• Case 1: Enterprise Organization
– Attack traffic peaked at a massive 130 Gbps
– Multiple botnets with thousands of compromised
servers
– Primarily SYN, UDP and DNS floods
– Modifications to attack scripts executed on the fly,
requiring expertise and responsiveness to block them
– Successfully mitigated by Prolexic.
– Get full report for specific attack vectors and traffic
distribution and other details
8
www.prolexic.com
DDoS Attack Case Study: DNS Reflection (Q1 2013)
• Case 1: DNS Reflection attack against Prolexic
– New extensions such as SNSSEC are being used as
attack vectors
– Attack directed at ns1.prolexic.com on Jan 23, 2013
– Malicious actor used DNS amplification techniques
• 64 byte request generated a response exceeding 3,000 bytes
and averaged 1,200 bytes
• 18x amplification
– Successfully mitigated by Prolexic
– View full report for specific attack metrics, traffic
distribution, heat map of participating countries, and more
9
www.prolexic.com
Prolexic Q1 2013 Global Attack Report
• Download the Q1 2013 Global Attack Report for:
– Average and trends in attack duration and bandwidth
– Total number and trends of attacks by type
– In-depth case studies
– Year-over-year and quarter-over-quarter comparisons
– A look forward at emerging DDoS trends
• About Prolexic
– Prolexic Technologies is the world’s largest and most trusted
distributor of DDoS protection and mitigation services.
– Prolexic Security and Engineering Response Team (PLXsert)
monitors the global malicious cyber threats and actively
analyzes DDoS attacks using proprietary techniques and
equipment.
10

More Related Content

Recently uploaded

+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
panagenda
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Recently uploaded (20)

Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...Apidays New York 2024 - The value of a flexible API Management solution for O...
Apidays New York 2024 - The value of a flexible API Management solution for O...
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
Deploy with confidence: VMware Cloud Foundation 5.1 on next gen Dell PowerEdg...
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost SavingRepurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
Repurposing LNG terminals for Hydrogen Ammonia: Feasibility and Cost Saving
 
Why Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire businessWhy Teams call analytics are critical to your entire business
Why Teams call analytics are critical to your entire business
 
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live StreamsTop 5 Benefits OF Using Muvi Live Paywall For Live Streams
Top 5 Benefits OF Using Muvi Live Paywall For Live Streams
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024Tata AIG General Insurance Company - Insurer Innovation Award 2024
Tata AIG General Insurance Company - Insurer Innovation Award 2024
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin WoodPolkadot JAM Slides - Token2049 - By Dr. Gavin Wood
Polkadot JAM Slides - Token2049 - By Dr. Gavin Wood
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 

Featured

Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Featured (20)

PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
 
Barbie - Brand Strategy Presentation
Barbie - Brand Strategy PresentationBarbie - Brand Strategy Presentation
Barbie - Brand Strategy Presentation
 

Prolexic Quarterly DDoS Attack Report Q1 2013

  • 1. Overview of Prolexic Quarterly DDoS Attack Report Q1 2013 www.prolexic.com
  • 2. www.prolexic.com Prolexic Quarterly DDoS Attack Report: Q1 2013 • What happened in Q1 2013? – The most formidable distributed denial of service (DDoS) attacks to date – More than 10 percent of attacks exceeded 60 Gigabits per second (Gbps) – The headline-making Spamhaus.org attack 2 May 2013 www.prolexic.com
  • 3. www.prolexic.com Average Bandwidth of DDoS Attacks in Q1 2013 • Volumetric bandwidth averaged an attention- grabbing 48.25 Gbps 3
  • 4. www.prolexic.com Emerging DDoS Attack Trends: Q1 2013 • Important trends? – Targeting Internet Service Providers (ISPs) and Carrier router infrastructures – High average packets-per-second (PPS) • Greater average than most DDoS mitigation equipment capacity. • Even routers carrying traffic to the mitigation equipment would be strained at this level – See full report for details on PPS trends 4
  • 5. www.prolexic.com Analysis of Attack Types: Q1 2013 • Attackers focused on infrastructure attacks • Favored application attacks were: – SYN – GET – UDP – ICMP • Download the full report for percentages and graphs by attack type, including attack volume and trends 5
  • 6. www.prolexic.com DDoS Attack Frequency in Q1: 2013 vs 2012 • Prolexic mitigated more DDoS attacks than ever in Q1 2013 • The month of March accounted for nearly half of all Q1 attacks (44 percent) 6
  • 7. www.prolexic.com Top Ten Source Countries: DDoS Attacks in Q1 2013 7
  • 8. www.prolexic.com DDoS Attack Case Study: An Enterprise (Q1 2013) • Case 1: Enterprise Organization – Attack traffic peaked at a massive 130 Gbps – Multiple botnets with thousands of compromised servers – Primarily SYN, UDP and DNS floods – Modifications to attack scripts executed on the fly, requiring expertise and responsiveness to block them – Successfully mitigated by Prolexic. – Get full report for specific attack vectors and traffic distribution and other details 8
  • 9. www.prolexic.com DDoS Attack Case Study: DNS Reflection (Q1 2013) • Case 1: DNS Reflection attack against Prolexic – New extensions such as SNSSEC are being used as attack vectors – Attack directed at ns1.prolexic.com on Jan 23, 2013 – Malicious actor used DNS amplification techniques • 64 byte request generated a response exceeding 3,000 bytes and averaged 1,200 bytes • 18x amplification – Successfully mitigated by Prolexic – View full report for specific attack metrics, traffic distribution, heat map of participating countries, and more 9
  • 10. www.prolexic.com Prolexic Q1 2013 Global Attack Report • Download the Q1 2013 Global Attack Report for: – Average and trends in attack duration and bandwidth – Total number and trends of attacks by type – In-depth case studies – Year-over-year and quarter-over-quarter comparisons – A look forward at emerging DDoS trends • About Prolexic – Prolexic Technologies is the world’s largest and most trusted distributor of DDoS protection and mitigation services. – Prolexic Security and Engineering Response Team (PLXsert) monitors the global malicious cyber threats and actively analyzes DDoS attacks using proprietary techniques and equipment. 10