Distributed denial of service (DDoS) attacks are getting progressively more complex, with software-defined and cloud-driven infrastructures becoming tantalizing targets for threat actors relying on previously overlooked vectors.

Nexusguard’s 2025 DDoS Trends Report showed that while the total number of DDoS attacks increased by just 2% year-over-year (YoY), the average attack size increased by 69%, with maximum attack sizes reaching 962.2 Gb/s.

The main line of attack in 2024 continued to be short-burst attacks, with 85% of attacks found to be less than 1 Gb/s.

Meanwhile, HTTPS Flooding, where an attacker overwhelms a web server or application by flooding it with a large number of HTTPS requests, accounted for one-fifth of all DDoS attacks.

Domain name system (DNS) attacks, where threat actors exploit vulnerabilities in a network’s DNS service to steal data or redirect users to malicious websites, grew by a whopping 876% YoY, though improved detection capabilities have helped increase incident reporting.

The report suggests threat actors are specifically targeting DNS servers themselves, flooding them with queries to bring down a website or platform.

Another attack front on the rise is TCP SYN-ACK. Actors target transmission control protocols (TCP), which establish a stable connection between client and server.

What makes TCP-based attacks notable is their difficulty in detecting, as they’re often harder to distinguish from legitimate traffic. They effectively spoof requests, forcing servers to waste resources matching responses to requests that don’t exist.

Attacks like TCP SYN-ACK are particularly problematic in software-defined networks, where dynamic routing and automated handshake processes can be more vulnerable to spoofed traffic.

Compounding the problem is the rise of botnets, or interconnected devices infected and operated by a bad actor, which could make TCP-based attacks even harder to prevent.

The scale of the threat posed by botnets could grow in tandem with the rise of smart devices and IoT, according to Nexusguard.

The report cites figures from GSMA Intelligence, which forecasts IoT connections to reach more than 38 billion by 2030, which in turn could increase the threat posed by botnets.

“Volumetric and application layer attacks often use botnets as they allow the attacker to generate massive amounts of traffic or requests from a distributed set of compromised machines, making the attack larger and more difficult to mitigate,” the report reads. “As the number of connected devices globally continues to rise, so will the threat from these kinds of attacks.”

Nexusguard called on network operators to enhance network security by adopting advanced DDoS protection strategies in order to keep up with such evolving threats.

“DDoS attacks are evolving faster than ever, with attackers employing increasingly sophisticated tactics to disrupt critical infrastructure,” said Donny Chong, product director at Nexusguard. “Our 2025 report highlights the importance of adopting multi-layered protection strategies, as attackers continue to exploit overlooked vulnerabilities like DNS and HTTPS.”