Multi-vector distributed denial of service (DDoS) attacks reached a record high in 2021, as DDoS ransomware is also on the rise, Comcast Business’ recent report found.

Comcast Business DDoS Mitigation Services claimed it identified and defended 24,845 multi-vector attacks targeting Layers 3, 4, and 7 simultaneously last year, a 47% increase from the previous record number in 2020.

Overall, 69% of Comcast Business customers experienced DDoS attacks, 41% more than the year before. Of that 69%, 55% were hit by multi-vector DDoS, as opposed to the year before when most of cases were single-vector attacks, its DDoS Threat Report showed.

This increase acts as a reminder for the broader community as most organizations without proper visibility tools, often don’t realize that they are under attack, according to Comcast Business.

“DDoS attacks are an under-appreciated threat vector, an area of residual risk for many large enterprises as well as mid-market customers as well,” Ivan Shefrin, executive director for Comcast Business Managed Security Services, told SDxCentral.

DDoS Becomes Harder to Fight

Among the multi-vector attacks Comcast Business customers suffered, 69% lasted under 10 minutes, according to the report.

“In general, the trend is shorter duration attacks and higher intensity,” Shefrin noted. It gives victims less time to respond and perform a root cause analysis, so it’s more difficult to detect and defend against.

Plus, “it's a little bit harder and more expensive to detect and protect against a Layer 7 attack or a multi-vector attack than it is against a network-based, Layer 3 and 4 attack,” he added.

Because of this, Comcast uses highly-automated BGP Flowspec tools instead of traditional methods to detect DDoS attacks which “deliver the full application flow with almost zero latency,” Shefrin touted. 

This methodology can mitigate attacks within seconds, and Shefrin expects most other carriers will quickly catch onto its method.

DDoS Evolves Into a Lucrative Business

Over the past two years, Comcast Business saw DDoS-extortion ransomware attacks go up by 125%.

“DDoS attacks are initiated by botnets, which became a tradable asset within the attacker community," Shefrin said, adding, “It's ridiculously inexpensive.”

“When we see trends up or down in the number of DDoS attacks, it generally reflects the economic value to the attacker. Organized crime groups are leveraging those botnet assets for different threat vectors,” he added. “Then they sell them off as a service,” and other malicious groups use them for ransomware or financial fraud.

Additionally, DDoS is a costly risk and ultimately is an availability attack, Shefrin pointed out. A recent IDC report showed the average hourly cost of an infrastructure failure is $100,000 per hour. 

“CISOs need to account for it when they look at residual risk,” Shefrin said. And he suggests organizations that have an advanced firewall turn on the rate-limiting policy.

 This step “at least gives you some early warning and some better information about whether you're experiencing a DDoS attack and how to prevent it. And then the firewall should be used ideally in conjunction with the service from a CSP to provide DDoS mitigation as well,” he explained.

“Those are two of the most simple things that almost every organization can do today,” Shefrin added. “You don't have to go buy really expensive DDoS mitigation equipment … that is probably not the best use of your cybersecurity budget.”