Distributed Denial of Service (DDoS) attacks can literally overwhelm networks.

Earlier this week, Cloudflare revealed that it successfully defended its network, and the customers that rely on it, from the largest DDoS attack it, or anyone else for that matter has ever seen. At its peak, the attack exceeded 71 million requests per second (rps), which Cloudflare classifies as a "hyper-volumetric" attack. The cyberattack exceeded the previous record for DDoS attack volume, which was 46 million rps, reported in June 2022 by Google.

The 71 million rps attack was generated by attackers using over 30,000 different IP addresses to flood Cloudflare's network with traffic. The attack specifically took aim at a number of Cloudflare protected sites, including gaming and cryptocurrency companies.

DDoS attacks can be measured in different ways, including looking at the amount of attack bandwidth consumed as well as request frequency.

"This attack was approximately 100 gigabits per second (gbps)," Omer Yoachimik, product manager at Cloudflare, told SDxCentral. "It is important to note that there is a difference between request-intensive attacks, bit-intensive attacks, and packet-intensive attacks – they are not apples-to-apples comparisons."

Yoachimik said that an attacker can generate a record-breaking request-per-second (rps) attack without necessarily generating a meaningful bit-per-second (bps) rate.

How the attackers generated the DDoS volume

Of particular note is how the attackers were able to generate the massive volume of 71 million requests per second.

Yoachimik said that the attack method was a flood from virtual private servers (VPSs)/virtual machines (VMs) with both high throughput and high computation power. Each node generated around 4-5 thousand requests per second (rps) at peak. These attacks were distributed -- originating from more than 30,000 different IP addresses, and as many as 15,000 per second.

"This aligns with the current trend we are seeing where attackers are moving from IoT-based botnets to VM-based botnets," he said.

Yoachimik said that VM-based botnets can generate a lot of force with a smaller fleet compared to IoT-based botnets. IoT-based botnets usually require millions of devices to generate substantial floods because IoT devices typically have lower computational capacity and lower throughput. In years past, IoT botnets, like the infamous Mirai botnet in 2016, launched large DDoS attacks involving over half a million bots.

This botnet, however, managed to execute the largest HTTP DDoS attack on record using only 30,000 bots. The requests were also over HTTPS (encrypted), which requires more resources to establish than a plaintext unencrypted connection.

As to why VM-based botnets are now emerging, Yoachimik said that it is possible that the move to VM-based botnets is due to the availability of stolen credit card details from data leaks, which could be used to pay for the virtual machines without revealing the identity of the attackers.

"Another factor to consider is that VM-based botnets are easier to execute than IoT-based botnets," he said. "VM-based botnets do not require propagating malware, infecting, and controlling physical IoT devices."

Vigilance is the key to DDoS protection

DDoS attacks are routinely impacting networks of all sizes, with cloud vendors and others reporting increasingly large attacks.

"DDoS attacks will only continue to grow in size and evolve in scope," Phil Venables, CISO, Google Cloud told SDxCentral via email. " It is imperative that organizations implement defense-in-depth strategies and understand their attack surfaces to best protect them."

Akamai is also no stranger to the world of DDoS, releasing a report in late 2022 outlining the growth of attacks that take aim at applications.

"The new records being set for web infrastructure attacks are not surprising,"  Steve Winterfeld, Advisory CISO at Akamai, told SDxCentral. "We continue to see the speed, complexity and volume of attack increase every year. Last year's huge outlier event is quickly becoming this year's normal attack."

Winterfeld noted that it's critical for organizations to keep their playbooks and protections up to date and minimize the impact of these attacks.

For its part, Yoachimik said that Cloudflare has  kept its customers protected and informed since the attacks were first observed .

"We are actively working with other cloud providers to take down the botnet and offer a botnet threat feed to help upstream defenders better stop these large, coordinated attacks in their tracks," Yoachimik said.