Summer plateau: Fewer DDoS attacks launched and some geographic shifts seen in Q2 2021

Alexey Kiselev of Kaspersky

In the second quarter of 2021, the total number of distributed denial of service (DDoS) attacks decreased by 38.8% compared to Q2 2020, and by 6.5% in comparison to the previous quarter in 2021.

China took the unenviable positions as the leader in the number of devices from which SSH attacks were carried out. At the same time, China continued to lose ground in terms of the total number of DDoS attacks (10.2%). According to research by Kaspersky, the USA remains the “leader” (36%) in this category for the second quarter in a row, while Poland and Brazil are new entries in the top five.

Recently, scammers have been looking for ways to amplify DDoS attacks the number of attacks through the Session Traversal Utilities for NAT (STUN) protocol has increased. Another visible trend, says Kaspersky, is the exploitation of the TsuNAME vulnerability in DNS resolvers to attack DNS servers. In particular, this led to interruptions in the work of Xbox Live, Microsoft Teams, OneDrive and other Microsoft cloud services. Internet service providers also fell victim to DDoS attacks.

The overall situation in Q2 was relatively calm. On average, the number of DDoS attacks fluctuated between 500 and 800 per day. On the quietest day, only 60 attacks were recorded, and on the most intense, this reached 1,164.

The geography of DDoS attacks has also changed slightly. The USA once again became the leader for the amount of DDoS attacks (36%). At the same time, China (10.2%), which until this year was regularly in first place, continues to lose ground its share has decreased by 6.3%.

Third place was taken by a newcomer to the rating Poland (6.3%), whose share increased by 4.3%. Brazil took fourth place, their share almost doubled, amounting to 6%. Canada (5.2%), which previously closed the top three, dropped to fifth place.

Kaspersky experts also analysed which countries had bots and malicious servers that attack IoT devices in order to expand botnets. Results show that the majority of devices that carried out attacks were in China (31.8%), the United States (12.5%) took second place, and Germany (5.9%) came in third.

“The second quarter of 2021 was calm, as we expected. There was a slight decrease in the total number of attacks compared to the previous quarter, which is typical for this period and is observed annually. We traditionally associate these numbers with the beginning of holidays and vacations.

In the third quarter of 2021, we also do not see any prerequisites for a sharp rise or fall in the DDoS attack market. The market will also continue to be highly dependent on the rate of cryptocurrencies, which has remained consistently high for a long time,” comments Alexey Kiselev, business development manager on the Kaspersky DDoS Protection team.

More information about the report can be found via this link.

To stay protected against DDoS attacks, Kaspersky experts offer the following recommendations:

  • Maintain web resource operations by assigning specialists who understand how to respond to DDoS attacks.
  • Validate third-party agreements and contact information, including those made with internet service providers. This helps teams quickly access agreements in case of an attack.
  • Implement professional solutions to safeguard your organisation against DDoS attacks. For example, Kaspersky DDoS Protection combines Kaspersky’s extensive expertise in combating cyberthreats and the company’s unique in-house developments.
  • It’s important to know your traffic. It’s a good option to use network and application monitoring tools to identify traffic trends and tendencies. By understanding your company’s typical traffic patterns and characteristics, you can establish a baseline to more easily identify unusual activity that is symptomatic of a DDoS attack.
  • Have a restrictive Plan B defensive posture ready to go. Be in a position to rapidly restore business-critical services in the face of a DDoS attack.

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. Its deep threat intelligence and security expertise has been used to develop security solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe.

Comment on this article below or via Twitter: @VanillaPlus OR @jcvplus

RECENT ARTICLES

Verizon partners with Ribbon for network modernisation initiative

Posted on: April 26, 2024

Ribbon Communications has announced plans for a major network modernisation programme with Verizon to retire legacy TDM switching platforms and replace their function with modern cloud-based technologies.

Read more

The emerging role of satellites in expanding cellular networks

Posted on: April 25, 2024

Satellites are rapidly gaining prominence in the world of cellular communication. However, the full extent of their potential to complement terrestrial networks as well as phone services and broadband is

Read more