{"id":14445,"date":"2017-01-26T08:43:06","date_gmt":"2017-01-26T08:43:06","guid":{"rendered":"http:\/\/www.intelligentcio.com\/me\/?p=14445"},"modified":"2018-04-26T11:10:44","modified_gmt":"2018-04-26T10:10:44","slug":"attacker-innovation-and-iot-exploitation-fuel-ddos-attack-landscape","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/me\/2017\/01\/26\/attacker-innovation-and-iot-exploitation-fuel-ddos-attack-landscape\/","title":{"rendered":"Attacker innovation and IoT exploitation fuel DDoS attacks"},"content":{"rendered":"<p><strong><a href=\"http:\/\/www.arbornetworks.com\/\">Arbor Networks<\/a>,<\/strong>\u00a0the security division of NETSCOUT, has\u00a0released its 12th Annual Worldwide Infrastructure Security Report (WISR). The report covers a range of issues from threat detection and incident response to managed services, staffing and budgets. Its focus is on the operational challenges Internet operators face daily from network-based threats and the strategies adopted to address and mitigate them.<\/p>\n<p>This year\u2019s report shows the stakes have changed for network and security teams. The threat landscape has been transformed by the emergence of Internet of Things (IoT) botnets. As IoT devices proliferate across networks, bringing tremendous benefits to businesses and consumers, attackers are able to weaponise them due to inherent security vulnerabilities. This year\u2019s report goes in-depth, covering how attackers exploit and recruit IoT devices, how IoT botnets enabled by Mirai source code operate and offers practical advice on how to defend against them.<\/p>\n<p>The largest distributed denial-of-service (DDoS) attack reported this year was 800 Gbps, a 60% increase over 2015\u2019s largest attack of 500 Gbps. Not only are DDoS attacks getting larger, but they are also becoming more frequent and complex. This increased scale and complexity has led more businesses to deploy purpose-built DDoS protection solutions, implement best practice hybrid defenses and increase time for incident response practice \u2013 all positive developments in an otherwise gloomy threat environment.<\/p>\n<p>\u201cThe survey respondents have grown accustomed to a constantly evolving threat environment with steady increases in attack size and complexity over the past decade,\u201d said Darren Anstee, Arbor Networks Chief Security Technologist. \u201cHowever, IoT botnets are a game changer because of the numbers involved. There are billions of these devices deployed and they are being easily weaponised to launch massive attacks. Increasing concern over the threat environment is reflected in the survey results, which show significant improvements in the deployment of best practice technologies and response processes.\u201d<\/p>\n<p><strong>Key findings<\/strong><\/p>\n<p>Innovation and Exploitation Fuel DDoS Attack Landscape:\u00a0The emergence of botnets that exploit inherent security weaknesses in IoT devices and the release of the Mirai botnet source code have increased attacker ability to launch extremely large attacks.<\/p>\n<p>Scale:\u00a0The massive growth in attack size has been driven by increased attack activity on all reflection\/amplification protocols, and by the weaponization of IoT devices and the emergence of IoT botnets.<\/p>\n<ul>\n<li>Since Arbor began the WISR in 2005, DDoS attack size has grown 7,900%, for a compound annual growth rate (CAGR) of 44%.<\/li>\n<li>In the past five years alone, DDoS attack size has grown 1,233%, for a CAGR of 68%.<\/li>\n<\/ul>\n<p>Frequency:\u00a0The chances of being hit by a DDoS attack have never been higher, with respondents showing increased rates of attack.<\/p>\n<ul>\n<li>53% of service providers indicated they are seeing more than 21 attacks per month \u2013 up from 44% last year.<\/li>\n<li>21% of data-centre respondents saw more than 50 attacks per month, versus only 8% last year.<\/li>\n<li>45% of enterprise, government and education respondents experienced more than 10 attacks per month \u2013 a 17% year over year increase.<\/li>\n<\/ul>\n<p>Complexity:\u00a0Multiple simultaneous attack vectors are increasingly being used to target different aspects of a victim\u2019s infrastructure at the same time. These multi-vector attacks are popular because they can be difficult to defend against and are often highly effective, driving home the need for an agile, multi-layer defence.<\/p>\n<ul>\n<li>67% of service providers and 40% of Enterprise, Government and Education (EGE) reported seeing multi-vector attacks on their networks.<\/li>\n<\/ul>\n<p>Consequences of DDoS Attacks Are Becoming Clear:\u00a0DDoS attacks have successfully made many leading web properties unreachable \u2013 costing thousands, sometimes millions, of dollars in revenue. This has led the C-suite and company boards to make DDoS defense a top priority.<\/p>\n<ul>\n<li>61% of data centre operators reported attacks totally saturating data centre bandwidth.<\/li>\n<li>25% of data centre and cloud providers saw the cost of a major DDoS attack rise above $100,000, and 5% cited costs of over $1 million.<\/li>\n<li>41% of EGE organisations reported DDoS attacks exceeding their total internet capacity. Nearly 60% of EGE respondents estimate downtime costs above $500\/minute.<\/li>\n<\/ul>\n<p><em>More appreciation of risk leads to better behaviour:\u00a0<\/em>This year\u2019s survey results indicate a better understanding of the brand damage and operational expense of successful DDoS attacks, driving focus on best-practice defensive strategies. Across the board, in every industry, there has been an increase in the use of purpose-built DDoS protection solutions and best practice methods.<\/p>\n<ul>\n<li>77% of service provider respondents are capable of mitigating attacks in less than 20 minutes.<\/li>\n<li>Nearly 55% of EGE respondents now carry out DDoS defense simulations, with approximately 40% carrying them out at least quarterly.<\/li>\n<li>The proportion of data centre and cloud provider respondents that are using firewalls for DDoS defence has fallen from 71% to 40%.<\/li>\n<\/ul>\n<p><strong>Additional Resources<\/strong><\/p>\n<p>Download the full report\u00a0<a href=\"https:\/\/www.arbornetworks.com\/insight-into-the-global-threat-landscape?utm_campaign=WISR_2015_release&amp;utm_content=whitepaper&amp;utm_medium=press_release&amp;utm_source=press_release&amp;utm_term=ALL\">here<\/a>\u00a0(registration required).<\/p>\n<p><strong>Survey scope &amp; demographics<\/strong><br \/>\n\u2022 The WISR survey data is based upon 356 responses from a mix of Tier 1, Tier 2 and Tier 3 service providers, hosting, mobile, enterprise and other types of network operators from around the world.<br \/>\n\u2022 Two-thirds of all respondents identify as security, network or operations professionals.<br \/>\n\u2022 Data covers November 2015 through October 2016.    \t<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Arbor Networks,\u00a0the security division of NETSCOUT, has\u00a0released its 12th Annual Worldwide Infrastructure Security Report (WISR). The report covers a range of issues from threat detection and incident response to managed services, staffing and budgets. Its focus is on the operational challenges Internet operators face daily from network-based threats and the strategies adopted to address and [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":14446,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,430,6,432,54],"tags":[730,3595,292,41,577,284,113],"class_list":["post-14445","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-enterprise-security","category-features","category-insights","category-oman","category-research","tag-arbor-networks","tag-botnets","tag-cyber-attacks","tag-data-centres-2","tag-ddos","tag-iot","tag-networking-2"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/14445","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/comments?post=14445"}],"version-history":[{"count":1,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/14445\/revisions"}],"predecessor-version":[{"id":24846,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/posts\/14445\/revisions\/24846"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media\/14446"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/media?parent=14445"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/categories?post=14445"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/me\/wp-json\/wp\/v2\/tags?post=14445"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}