Distributed Denial Of Service (DDoS) attacks have long been the scourge of the internet, but apparently they are getting worse, according to the latest report from Cloudflare.

Today Cloudflare releases its first quarter 2024 DDoS threat report and the headline finding is that attacks jumped by 50% on a year-over-year basis. According to the report, Cloudflare's automated defense systems mitigated an astonishing 4.5 million DDoS attacks during the first three months of the year, equivalent to nearly a third of all DDoS attacks mitigated by the company in 2023.

Alex Forster, engineering manager, DDoS team at Cloudflare called the 50% DDoS attack spike an unprecedented result compared to recent years.

“Accelerated by the newfound popularity of crowdsourced hacktivism, DDoS tooling is becoming more accessible and easy to use,” Forster told SDxCentral. “The good news is that, while attackers carry out increasingly sophisticated and more impactful attacks, defenders are developing cutting-edge methods and technology to combat this.”

DNS-based attacks dominate the landscape

The report highlights a concerning trend: DNS-based DDoS attacks have surged by 80% year-over-year, cementing their position as the most prominent attack vector. These attacks now account for a substantial 33% of all DDoS attacks observed by Cloudflare's network.

According to Forster, the growth in DNS based DDoS attacks can be attributed to a rise in “DNS laundering.” He explained that this method takes place when a threat actor “launders” their attack traffic through reputable public DNS resolvers.  A DNS resolver is a type of DNS server that is responsible for tracking down the IP address of a website from various other DNS servers.

“While this method is not novel, its growing popularity over the past several quarters is due to the effectiveness threat actors are having,” Forster said. “The complexity of sophisticated DNS DDoS attacks lies in their paradoxical nature, while they are relatively easy to detect, effectively mitigating them is significantly more difficult.”

Mirai botnet strikes back with 2 Tbps attack

Among the numerous DDoS attacks mitigated by Cloudflare in Q1 2024, one stands out as the largest yet this year.

A Mirai botnet variant launched a massive 2 Tbps attack targeting an Asian hosting provider protected by Cloudflare's Magic Transit service. Cloudflare's systems automatically detected and mitigated this attack.

The Mirai botnet, infamous for its massive DDoS attacks since 2016, continues to be a persistent threat, with four out of every 100 HTTP DDoS attacks and two out of every 100 network-layer attacks traced back to Mirai-variant botnets.

New HTTP/2 vulnerability poses severe threat

The report also highlights a newly discovered vulnerability in the HTTP/2 protocol, dubbed the HTTP/2 Continuation Flood.

This vulnerability, disclosed by security researcher Bartek Nowotarski on April 3, 2024, could potentially lead to severe DDoS attacks by exhausting server resources and causing out-of-memory crashes or CPU exhaustion.

While Cloudflare's network and customers remain unaffected by this vulnerability, the company warns that it poses a potentially severe threat, potentially more damaging than the previously known HTTP/2 Rapid Reset attacks that targeted Cloudflare in 2023.

Overall Forster noted that DDoS attacks threats are evolving quickly, and are far from a low-level annoyance that they used to be. He added that attackers are likely to continue using attack techniques that are working and will evolve and enhance those methods.

“We expect to see these numbers continue to trend in the same direction as large world events take place , for example, important global election days and the summer Olympics – and geopolitical tensions continue to mount,” he said.