SecurityBrief Asia logo
Story image

DDoS attacks almost doubled in the last year - Kaspersky

Analysis from Kaspersky has revealed that the number of attacks blocked by the security company's distributed denial-of-service (DDoS) protection in Q4 2018 amounts to only 56% of attacks detected in Q4 2019. 

Further investigation of botnet activity reveals that around 28% of attacks happened on weekends, with the share of attacks on Sundays growing by two and a half percentage points - reaching 13%. 
 
In Q4 2019, there were several large-scale DDoS attacks, including ones against financial institutions in South Africa, Singapore and Scandinavian countries. 

These cyberattacks were also targeted at the Labour party in the United Kingdom as an attempt to disrupt its digital systems, as well as against Minecraft servers set up in the Vatican. 

This demonstrates that DDoS is still a common attack method amongst cybercriminals seeking financial gain or driven by ideological motives, so organisations should be prepared for such attacks and understand how they evolve.
 
The report highlights that the main trend during the last quarter of 2019 was increased botnet activity on Sundays. 

While the growth may seem relatively small (2.5%), the share of DDoS attacks on this particular day of the week had otherwise been the lowest, and consistent, throughout the rest of the year (around 11% of attacks in Q1 and Q3, and 10% in Q2). 

In Q4, Thursday turned out to be the day with the least DDoS activity. In general, attacks became more evenly distributed over a week. 

Analysis shows that the difference between the most active and the calmest day was only about two and a half percentage points (in the previous quarter, the figure was seven percentage points).
 
Although the number of DDoS attacks detected by Kaspersky DDoS Protection has grown significantly compared to the same period of 2018, the growth in comparison to Q3 2019 is only marginal (attacks in Q3 2019 equate to 92% of Q4 2019). 

There was a more notable rise in so-called smart DDoS attacks, focusing on the application layer and carried out by skilled malefactors (as attacks in Q3 2019 were 73% of those in Q4 2019). 

Such an increase was predictable, since November to December is traditionally a popular time for online business and retail activity. However, Kaspersky experts did not identify a spike on Black Friday or Christmas holiday sales days.
 
“Despite the significant growth in general, the season turned out to be quieter than expected,” says Kaspersky business development manager Alexey Kiselev. 

“We didn’t see a storm of attacks on certain days because companies expand their activity to engage with customers for the entirety of the holiday period. So there is no need for cybercriminals to launch an attack to coincide with a specific event. 

“However, attackers can still find a way to spoil your leisure time, as cybercrime is not an ordinary nine-to-five job, so it is important to ensure that your DDoS prevention solution can automatically protect your web assets,” says Kiselev. 

Story image
iland and Cohesity form alliance, target data protection market
"Together with Cohesity, we will deliver elegant and cutting-edge solutions that will take our joint customers’ digital transformation projects to the next level."More
Story image
Video: 10 Minute IT Jams - Radware VP on the challenges of cloud security
In this interview, Techday speaks to Radware vice president of technologies Yaniv Hoffman, who discusses the primary challenges facing IT organisations in terms of their cloud security apparatus.More
Story image
Major firms disclose breaches in the wake of SolarWinds attack
Microsoft, Shell, GoDaddy, MobiKwik — these are just some of the high-profile company's on the receiving end of sophisticated attacks, writes Bitglass senior director of marketing Jonathan Andresen.More
Story image
Cybersecurity budgets still not keeping up with threats — report
Executive teams are failing to recognise the level of damage cyber-threats pose to organisations, according to Sophos — many of them taking a ‘conservative approach’ to cybersecurity expenditure.More
Story image
Why a more secure organisation is a collective responsibility
With vast volumes of data moving to the cloud, many IT professionals are frequently challenged to protect their enterprise environment, and there is a greater focus being placed on advancing cybersecurity strategies.More
Story image
Financial malware activity dropped in 2020 as creators honed their wares
Cybercriminals used the time to plan more malicious propagation techniques, both new and evolved from previous methods.More