Attack Frequency Grows 12%, But Most Attacks Stay Small

▶ Watch (3:25)

Global DDoS attacks hit 8 million in H2 2024, up 12% from early 2024. 75% of attacks sat below 1 Gbps. 70% lasted under 15 minutes. Attackers target just enough bandwidth to clog a victim’s pipe. They launch short bursts to avoid detection and response. This optimization drives the volume. The largest attack of the period hit 995 Gbps, but that is an outlier. The real story is the frequency and the precision.

Amplification Attacks Wane; Direct Path Flag Attacks Dominate

▶ Watch (9:04)

SYN floods and other direct path flag attacks now top the attack vector list. Amplification attacks like DNS and NTP dropped because service providers deployed anti-spoofing and mitigations. Attackers switched to compromising high-power servers and launching unspoofed flag attacks. TCP, ACK, TCP SYN, ICMP attacks account for the top four vectors. DNS amplification remains only because it is still effective against DNS servers themselves. Everything old is new again.

DDoS-for-Hire Platforms Democratize Attack Complexity

▶ Watch (16:48)

Booter slash stresser portals let anyone launch attacks with a credit card. They now offer carpet bombing, which spreads traffic across a subnet to evade detection. Attackers can spoof source countries and rotate vectors every minute. These platforms also include conversational LLM interfaces for attack refinement. Automation is the key differentiator. The same platforms incorporate new vectors within six months of discovery, making advanced techniques available to everyone.

Mirai Botnet Still Dominates Despite Law Enforcement Takedowns

▶ Watch (21:58)

Mirai’s source code leak led to countless variants. New IoT devices get infected within five minutes of going online. Operation Power Off dropped botnet nodes temporarily, but the population recovered within a month. Botnets now generate application-layer attacks like DNS water torture, which is harder to block than volumetric floods. Attackers also use open DNS servers as proxies to hide their bot IPs. Law enforcement is treading water.

Attackers Use AI for Automation, Not Novel Vectors

▶ Watch (28:02)

AI has not produced a killer DDoS vector. It automates campaign coordination. One booter site already offers a conversational LLM to optimize attacks. Attackers can type “focus on API endpoints” and the AI adjusts. Defense vendors match this with their own automation, using ML to pre-identify bad IPs and profile normal traffic. The arms race continues. The defender’s advantage comes from knowing the attackers’ IPs before the attack starts.

Hybrid Defense and Preparation Beat Automation

▶ Watch (31:41)

NetScout advocates hybrid protection. On-premise devices learn normal behavior and block outliers. Cloud scrubbers handle volumetric attacks. Global threat intelligence feeds pre-identify attacker IPs. Preparation matters most. Successful customers run monthly simulations, train SOC teams, and coordinate with service providers. Without preparation, even good tools fail. Customers who prepare shrug off weekly attacks. Those who do not are rolling the dice.

Notable Quotes

“the archetypal direct path flag attack is a sin flood. You know, everything old is new. Sim floods have been around since the ’90s. They’re still incredibly impactful and they’re back, baby.” Andrew Cockburn · ▶ 12:14

“take a pinch of salt with or take with a pinch of salt the fact that you look at all of these guys claiming all of these successes. For every one of those successes, there are many failures.” Andrew Cockburn · ▶ 16:02

“if you turn up a device, a camera, IoT devices, whatever that that is vulnerable, it won’t even go 5 minutes before it gets infected.” Andrew Cockburn · ▶ 23:45

“the bootter stressor sites have been increasing their capabilities for automation. It’s a huge differentiator.” Andrew Cockburn · ▶ 29:02

Key Takeaways

  • DDoS attacks rose 12% to 8 million in H2 2024, with 75% under 1 Gbps and 70% under 15 minutes.
  • Attackers shifted from amplification to direct path flag attacks, using compromised servers instead of open resolvers.
  • Effective defense requires hybrid on-prem/cloud mitigation, global threat intel, and regular simulation training.