No it's not a summary of some new action movie or war documentary. Carpet-bombing and DNS water torture attacks are among the biggest trends in 2023 for distributed denial of service (DDoS), according to Netscout's 1H2023 DDoS Threat Intelligence Report.
The report found carpet-bombing and DNS water torture tactics becoming more pervasive. The former, hitting hundreds or thousands of targets simultaneously, was up 55% while the latter, utilizing DNS amplification, swelled nearly 353%. Netscout warns these obfuscating approaches make defending against the broader fallout increasingly difficult.
Overall, Netscout saw a major increase in DDoS attacks during the first six months of 2023 according to its latest threat intelligence report. The analysis found that cybercriminals and hacktivists carried out nearly 7.9 million DDoS assaults over the period — a 31% year-over-year rise.
[caption id="attachment_134618" align="alignnone" width="717"] Image credit: Netscout.[/caption]
Netscout credited several geopolitical factors with contributing to the growth in attacks. Russia's ongoing invasion of Ukraine continued to see DDoS activity aimed at both countries as the conflict persisted into 2023. Sweden also found itself as a target in May when it experienced its largest ever DDoS attack, at 500 Gb/s, during the ongoing process for its own application to the NATO military alliance.
Beyond international events, Netscout data showed DDoS against wireless carriers rising precipitously with a 79% increase.
Carpet-bombing and DNS water torture DDoS explainedRichard Hummel, senior threat intelligence lead at Netscout, explained to SDxCentral that carpet-bombing works by targeting more than one host in an attack.
He noted that in the past most attacks would target one IP address (i.e., the host), but as time has passed, adversaries have realized that defenders are doing host-based monitoring and looking for high bandwidth/throughput destined for those hosts. The attackers have figured out that instead of targeting one host with a lot of traffic, they can target 100 IP addresses with the same amount of traffic spread across all hosts.
"It doesn’t negate the effect on the network to carry that load of traffic, but it does prevent the typical detection mechanisms, making it harder to spot and thus defend against," Hummel said.
A DNS water torture attack is a form of amplification attack whereby attackers flood random DNS requests in an adversarial approach. Hummel noted that, in general, DNS attacks have always been harder to mitigate because it’s literally what makes the internet work, and you can’t just wholesale block it.
According to Hummel, what makes DNS attacks more insidious these days is that adversaries are using different methods and different types of infrastructure, including botnets and cloud hosting, to launch the attacks, adding more burden to the detection and mitigation of these attacks. At the same time, defenders are trying not to overblock and cut off the internet for their customers, which makes it challenging to defend against DNS attacks.
5G in the crosshairsThe report also found a rise in attacks against wireless telecom infrastructure as 5G rollouts continue.
Hummel commented that while wireless infrastructure is being targeted more, attackers aren't necessarily specifically going after 5G, rather they are taking advantage of a transition.
"A lot of fixed wired networks are being converted to fixed wireless networks over 5G," Hummel said. “Naturally, the DDoS attacks will follow suit since their targets have changed network types."
Comments