For years, one of the most impactful and common distributed denial of service (DDoS) attack method relied on amplification and redirection techniques. According to Netscout that's no longer the case as adversaries have fallen back to using direct-path attacks.
Netscout released its annual DDoS Threat Intelligence Report this week, revealing a number of new trends as threat adversaries have shifted tactics as part of a never-ending game of cat and mouse with network defenders. Looking at aggregate traffic, Netscout reported that it saw peak DDoS alert traffic hit a staggering high of 436 petabits (a petabit is one million gigabits) in a single day.
The techniques that attackers are using are many and varied as well. Netscout reported a 110% increase in the second half of 2022 for carpet-bombing DDoS attacks. A carpet-bombing DDoS is one where adversaries go after entire IP address ranges on internet service provider (ISP) networks.
Richard Hummel, threat intelligence lead at Netscout, commented that a key trend is adversary methodology changes and adaptation.
"We witnessed significant increases in direct-path, application-layer, carpet-bombing, and DNS water-torture DDoS attacks," Hummel told SDxCentral. "It wasn't an isolated phenomena, but global increases across the board highlighting the general sophistication of attacks is growing."
Why direct-path DDoS attacks are increasingThe most common way that the biggest DDoS attacks have been staged in the past is with the use of amplification and redirection attacks. For example, over the years, attacks have taken advantage of misconfigured network time protocol (NTP) services to reflect and amplify attacks.
Netscout found that amplification/reflection attacks decreased by over 18% while direct-path attacks increased by the same amount. A direct-path attack does not rely on a misconfigured service to amplify attack volume.
"Community efforts to shut down volumetric reflection/amplification attacks by implementing best current practices and measures like source address validation have had a positive effect," Hummel said. "As such, adversaries are moving to other attack methods to avoid these security measures and direct-path attacks, which do not spoof source addresses, are one method to achieve that."
While direct-path attacks are on the rise, that doesn't discount the continued pervasive threat of other DDoS attack methods including botnets like Mirai. The Mirai botnet first raised its malicious tentacles in 2016 as a conflagration of compromised IoT devices that were used to attack victims. Seven years after it first appeared, Mirai is still very much alive.
"Mirai is absolutely still a major threat and likely the largest threat in the DDoS botnet space," Hummel said. " However, groups like Killnet and tools like Meris and Dvinis use compromised routers or open proxies as part of their attack apparatus and that expands the available resources of adversaries to launch different kinds of attacks."
The intersection of 5G and DDoSAn emerging attack trend that Netscout reports is a growing number of attacks against telecom networks and 5G in particular.
According to Netscout, DDoS attacks targeting the wireless telecommunications industry have increased by 79% since 2020, with 5G wireless technology being the primary reason. There are several driving factors behind the growth of DDoS attacks against telco networks.
Hummel said that approximately 80% of the near 13 million DDoS attacks in 2022 were motivated by online gaming and gambling associated with online gaming. He noted that historically, these attacks took place predominantly on wired or wireless networks from broadband access subscribers to broadband access subscribers. However, as 5G increases and more service providers deliver high-speed wireless, these attacks are shifting. In his view it is likely a natural evolution as technology advances and 5G becomes more stable and even preferred by home users.
Looking forward, Hummel warned that there is no end in sight for DDoS.
"I believe we'll continue to see an ever-increasing number of attacks aimed at applications and services," Hummel said.
Comments