Cloudflare released its distributed denial-of-service (DDoS) Threat Report for the third quarter, showing attacks may be initiated by humans, but they are often executed by bots, and “to play to win, you must fight bots with bots.”

The content delivery network (CDN) provider reported an increase in DDoS attacks compared to the same quarter last year, with longer-lasting volumetric attacks – those designed to create congestion between a site and the larger internet by targeting the network – and a spike in attacks generated by the Mirai botnet and its variants.

A DDoS attack is an attempt to disrupt normal traffic flowing to a targeted server, service, or network by overwhelming it with “a flood of internet traffic,” Cloudflare said in its “Five Best Practices for Mitigating DDoS Attacks.”

To be effective, these attacks require threat actors to take control of online computers, routers, IoT devices, or other endpoints to leverage as sources of attack traffic. These machines are infected with malware and then weaponized in a “botnet” that is remotely activated.

IoT devices have "allowed botnets to grow in size and sophistication," John Engates, field CTO at Cloudflare explained. Many times these devices are not secured before deployment, like in the case of changing default login credentials, which means they are "prime targets for malware infections which can then replicate and spread via the internet," he told SDxCentral.

Because their code was made open source, the Mirai botnet continues to evolve and spread.

"Botnets made up of IoT devices, such as the Mirai botnet, have seen a resurgence in this past quarter despite its original creators having already been caught, charged, and punished," Engates added.

‘Fighting Bots With Bots’

Engates said overall, DDoS attack sizes and frequencies have been "steadily growing at an exponential pace for the past decade," adding he expects this trend to continue "until network operators and law enforcement around the world begin to take cybercrime more seriously."

Ransom DDoS attacks increased by 67% year-over-year and 15% quarter-over-quarter, according to Cloudflare.

“Over the years, it has become easier, cheaper, and more accessible for attackers and attackers-for-hire to launch DDoS attacks,” Cloudflare said in its report.

The company recommends detection and mitigation be automated as much as possible, because “relying solely on humans puts defenders at a disadvantage.”

Cloudflare also noted that protecting against DDoS attacks requires the ability to differentiate between traffic spikes stemming from an attack or from high user demand and blocking traffic flowing from botnets without interrupting legitimate traffic. Routing the remaining traffic by breaking it into “manageable chunks” to prevent denial of service and continuously analyzing traffic for malicious patterns are also measures organizations can take to ward off DDoS attacks.

Move DDoS to the Edge for SASE Implementation

Cloudflare was an early player in the secure access service edge (SASE) market, after Gartner coined the term to define the convergence of SD-WAN and security as a cloud-delivered service.

The provider claims SASE eliminates the need for legacy virtual private networks, hardware firewalls, and DDoS protection appliances, “giving organizations more visibility into and control over their network security configurations.”

Engates explained that traditional and legacy DDoS mitigation solutions rely on scrubbing centers, meaning network traffic gets routed back to a limited number of dedicated centers to be cleaned, and then sent to its ultimate destination.

"While this approach may have sufficed in the past, it no longer keeps up with modern network demands - it is difficult to scale and adds latency - providing a poor user experience," he added.

Additionally, Engates noted that DDoS attacks often make use of compromised computers and devices that are scattered all around the world, and filtering malicious traffic as close to the source as possible helps to prevent bottlenecks and congestion on the internet.

"Combining DDoS protection with other edge networking and security services, like SASE, allows them to work in concert and better protects users and applications end-to-end," he said.

To implement SASE, Cloudflare says organizations should move DDoS protection to the edge. By getting rid of DDoS appliances in favor of cloud-native, network-layer DDoS protection that can detect and mitigate threats in real time, corporate networks are better defended from attacks.