• Home
  • Cyber Crime
  • Cyber warfare
  • APT
  • Data Breach
  • Deep Web
  • Digital ID
  • Hacking
  • Hacktivism
  • Intelligence
  • Internet of Things
  • Laws and regulations
  • Malware
  • Mobile
  • Reports
  • Security
  • Social Networks
  • Terrorism
  • ICS-SCADA
  • POLICIES
  • Contact me
MUST READ

Cisco removed the backdoor account from its Unified Communications Manager

 | 

U.S. Sanctions Russia's Aeza Group for aiding crooks with bulletproof hosting

 | 

Qantas confirms customer data breach amid Scattered Spider attacks

 | 

CVE-2025-6554 is the fourth Chrome zero-day patched by Google in 2025

 | 

U.S. CISA adds TeleMessage TM SGNL flaws to its Known Exploited Vulnerabilities catalog

 | 

A sophisticated cyberattack hit the International Criminal Court

 | 

Esse Health data breach impacted 263,000 individuals

 | 

Europol dismantles €460M crypto scam targeting 5,000 victims worldwide

 | 

CISA and U.S. Agencies warn of ongoing Iranian cyber threats to critical infrastructure

 | 

U.S. CISA adds Citrix NetScaler flaw to its Known Exploited Vulnerabilities catalog

 | 

Canada bans Hikvision over national security concerns

 | 

Denmark moves to protect personal identity from deepfakes with new copyright law

 | 

Ahold Delhaize data breach affected over 2.2 Million individuals

 | 

Facebook wants access to your camera roll for AI photo edits

 | 

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 51

 | 

Security Affairs newsletter Round 530 by Pierluigi Paganini – INTERNATIONAL EDITION

 | 

The FBI warns that Scattered Spider is now targeting the airline sector

 | 

LapDogs: China-nexus hackers Hijack 1,000+ SOHO devices for espionage

 | 

Taking over millions of developers exploiting an Open VSX Registry flaw

 | 

OneClik APT campaign targets energy sector with stealthy backdoors

 | 
  • Home
  • Cyber Crime
  • Cyber warfare
  • APT
  • Data Breach
  • Deep Web
  • Digital ID
  • Hacking
  • Hacktivism
  • Intelligence
  • Internet of Things
  • Laws and regulations
  • Malware
  • Mobile
  • Reports
  • Security
  • Social Networks
  • Terrorism
  • ICS-SCADA
  • POLICIES
  • Contact me
  • Home
  • Breaking News
  • Cyber Crime
  • Hacking
  • Reports
  • One Third of The Internet Has Seen a DDoS Attack In The Past Two Years

One Third of The Internet Has Seen a DDoS Attack In The Past Two Years

Pierluigi Paganini November 07, 2017

A group of researchers has conducted a rigorous comprehensive characterization of this DDoS attacks and of countermeasures to mitigate the associated risks.

Denial of Service (DoS) attacks have been around about as long as computers have been network connected. A website’s purpose is to accept connections from the Internet and return information. A bad actor can take advantage of this setup to overwhelm the web server with so many connection requests that valid connections are denied. If your business relies on eCommerce to sell products, a DoS attack directly affects your revenue. For this reason, a lot of people work to find methods to guard against such attacks. And bad actors work to find new ways of overcoming such protections.

One method deployed by the bad actors is the Distributed Denial of Service (DDoS) attack. Many computers work together to attack a single target. Defenders put in new defences and attackers combine ever-larger collections of devices in a cyber arms race of sorts. This arms race took a new turn in 2016 when the Mirai botnet was unleashed against DNS servers showing how potent a DDoS attack can be. Leveraging consumer devices like home routers and webcams, Mirai was able to maintain a sustained attack of 640Gbps. This overwhelmed DNS servers in the United States making large portions of the Internet unavailable. There followed several equally high profile attacks and people woke up to the new reality.

In 2017, researchers uncovered a new botnet which is expanding on the tricks used by Mirai. In addition to scanning for default passwords, Reaper uses exploits to compromise more devices and grow the attack potential. There are disagreements about the specific size of the Reaper botnet, but everyone agrees it is a significant threat.

These major botnets are capable of impacting large portions of the Internet and getting into the headlines doing it. But there is another DoS story that is arguably more impactful and less well known. Over 28,00 DoS attacks occur on the Internet every day!

A group of researchers unveiled their findings at the recent AMC Internet Measurement Conference in London. They gathered data from DDoS Protection Services (DPS) , amplification honeypots, and a DNS measurement platform. The data showed that one-third of all /24 networks recently estimated to be active on the Internet have suffered at least one DoS attack over the last two years.

“Our results reveal the massive scale of the DoS problem, including an eye-opening statistic that one-third of all /24 networks recently estimated to be active on the Internet have suffered at least one DoS attack over the last two years. We also discovered that often targets are simultaneously hit by different types of attacks” reads the research paper published by the experts.

While large-scale attacks like Mirai and Reaper may get the headlines, this amount of DDoS attacking will have real impacts for the victims.

DDoS attack timeline

The researchers noted that victims are likely to engage DPS providers following an attack.

“One of the things we show is if a website is attacked, this creates an urgency for people to start outsourcing to protection services,” said Mattjis Jonker, one of the researchers from the University of Twente.

This early research sheds light on the breadth and scale of the problem beyond the headline-grabbing attacks.

“During this recent two-year period under study, the internet was targeted by nearly 30,000 attacks per day,” said Alberto Dainotti, one of the researchers from CAIDA (Center for Applied Internet Data Analysis)

“These absolute numbers are staggering, a thousand times bigger than other reports have shown.”

The researchers have also validated some assumptions about potential targets. The United States hosts around 25% of web addresses and received around 25% of DDoS attacks. Following a similar pattern, Google, GoDaddy, and Wix services host the most websites and also see the most attacks.

Following this early success, researchers are next planning to include more data including DoS attacks on email servers with the ultimate goal being DDoS protection solutions.

The researchers plan to investigate the impact of DoS attacks on mail infrastructure in future projects, they already instrumented a measurement infrastructure to query for more DNS RRs on the names found in MX records.

About the author:  Steve Biswanger has over 20 years experience in Information Security consulting, and is a frequent speaker on risk, ICS and IoT topics. He is currently Director of Information Security for Encana, a North American oil & gas company and sits on the Board of Directors for the (ISC)2 Alberta Chapter.

 

 

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – DDoS Attack, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]


facebook linkedin twitter

botnet DDoS attack Hacking Mirai

you might also like

Pierluigi Paganini July 02, 2025
Cisco removed the backdoor account from its Unified Communications Manager
Read more
Pierluigi Paganini July 02, 2025
U.S. Sanctions Russia's Aeza Group for aiding crooks with bulletproof hosting
Read more

leave a comment

newsletter

Subscribe to my email list and stay
up-to-date!

    recent articles

    Cisco removed the backdoor account from its Unified Communications Manager

    Security / July 02, 2025

    U.S. Sanctions Russia's Aeza Group for aiding crooks with bulletproof hosting

    Cyber Crime / July 02, 2025

    Qantas confirms customer data breach amid Scattered Spider attacks

    Cyber Crime / July 02, 2025

    CVE-2025-6554 is the fourth Chrome zero-day patched by Google in 2025

    Hacking / July 02, 2025

    U.S. CISA adds TeleMessage TM SGNL flaws to its Known Exploited Vulnerabilities catalog

    Hacking / July 02, 2025

    To contact me write an email to:

    Pierluigi Paganini :
    pierluigi.paganini@securityaffairs.co

    LEARN MORE

    QUICK LINKS

    • Home
    • Cyber Crime
    • Cyber warfare
    • APT
    • Data Breach
    • Deep Web
    • Digital ID
    • Hacking
    • Hacktivism
    • Intelligence
    • Internet of Things
    • Laws and regulations
    • Malware
    • Mobile
    • Reports
    • Security
    • Social Networks
    • Terrorism
    • ICS-SCADA
    • POLICIES
    • Contact me

    Copyright@securityaffairs 2024

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities...
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
    Non-necessary
    Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
    SAVE & ACCEPT