Akamai Technologies saw a threefold uptick in web application and API attacks in the first quarter compared to the same period last year, and found the U.S. is the most targeted country for such attacks. 

The security vendor identified more than 6.3 billion web application and API attack attempts so far this year. The surge was largely driven by local file inclusion (LFI) attacks, which surged past structured query language injection (SQLI) attacks to become the most prevalent web attack vector since mid-2021, according to research. 

“Web application and API attacks and zero-day vulnerabilities have been on an absolute tear over the last 9 months,” Thomas Emmons, principal product architect at Akamai Technologies, wrote in a blog post. 

Akamai’s research also showed that the majority of the attacks target customers in the U.S., followed by Europe, the Middle East, and Africa (EMEA), and the Asia-Pacific regions. Researchers also broke down the victims into industries and found the retail vertical hit by the most attacks, while the high-technology industry had the most growth this year. 

Top Web Application and API Attack Patterns

Analyzing the top 1,000 attacks so far this year across its 93 customers, Akamai gleaned three major patterns.

The first came from data tied to long-running attack campaigns that three of its customers experienced. Researchers found there has been a steady increase of web application and API attacks since the first quarter of 2021, with peaks of more than 10 million daily attacks.

Akamai also found a pattern of short-burst attacks that run 10- to 30-times more volume than average and tend to cluster over a few days. 

“The bursts are difficult to predict — they seem to come out of nowhere and go away as they came,” Emmons explained. “These short-burst campaigns can be just as daunting to an organization as the previous type.”

Lastly, Akamai found one-time big booms — attack activity volumes of more than 30-times a customers’ norm. This pattern is even harder to predict than the short-burst attacks, researchers noted.

“Attackers can leverage long-term persistence, short attack flurries, or surprise one-time attacks,” Emmons concluded. “Although we may not be able to predict how an attacker will exploit web application and APIs next, this is further proof that we need to do all we can to stay current with patches and ensure proper protections are in place.”