{"id":27601,"date":"2017-02-06T14:01:00","date_gmt":"2017-02-06T06:01:00","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=27601"},"modified":"2017-02-06T14:01:00","modified_gmt":"2017-02-06T06:01:00","slug":"last-three-months-of-2016-witnessed-significant-advances-in-ddos-attacks-report-says","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2017\/02\/06\/last-three-months-of-2016-witnessed-significant-advances-in-ddos-attacks-report-says\/","title":{"rendered":"Last three months of 2016 witnessed significant advances in DDoS attacks, report says"},"content":{"rendered":"<p><strong><span id=\"yui_3_16_0_ym19_1_1486221439306_82468\">The last three months of 2016 witnessed significant advances in DDoS attacks. Methods are becoming more and more sophisticated, the array of devices being harnessed by botnets is increasingly diverse, while the attackers show off their capabilities by choosing bigger and more prominent targets. All this, and more, is covered by Kaspersky Lab\u2019s experts in the Q4 2016 DDoS attack <\/span><a href=\"https:\/\/securelist.com\/analysis\/quarterly-malware-reports\/77412\/ddos-attacks-in-q4-2016\/\" target=\"_blank\" rel=\"nofollow\">report<\/a>.<\/strong><\/p>\n<p><a href=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/02\/Kaspersky.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-27604\" src=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/02\/Kaspersky.jpg\" alt=\"\" width=\"642\" height=\"480\" srcset=\"http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/02\/Kaspersky.jpg 642w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/02\/Kaspersky-300x224.jpg 300w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/02\/Kaspersky-102x75.jpg 102w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/02\/Kaspersky-600x450.jpg 600w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/02\/Kaspersky-210x158.jpg 210w, http:\/\/www.upgrademag.com\/web\/wp-content\/uploads\/2017\/02\/Kaspersky-390x293.jpg 390w\" sizes=\"auto, (max-width: 642px) 100vw, 642px\" \/><\/a><\/p>\n<p id=\"yui_3_16_0_ym19_1_1486221439306_83320\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1486221439306_83319\">In the fourth quarter of 2016, Kaspersky Lab\u2019s DDoS Intelligence system reported bot-assisted DDoS attacks in 80 countries, compared to just 67 countries the previous quarter. <\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1486221439306_83328\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1486221439306_83327\">The top 10 countries with the largest number of DDoS victims also saw a change, with Germany and Canada replacing Italy and the Netherlands. Three countries from Western Europe (the Netherlands, the UK and France) remained among the top 10 countries with the largest number of hosted C&amp;C servers for a second quarter in a row, and were joined by Bulgaria and Japan in Q4.<\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1486221439306_83336\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1486221439306_83335\">The longest DDoS attack in the fourth quarter lasted for 292 hours (or 12.2 days), which was a record for 2016. The final quarter also saw the year\u2019s record number of DDoS attacks in one day \u2013 1,915 launched on 5 November.<\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1486221439306_83340\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1486221439306_83339\">Overall, Q4 2016 was rich in noteworthy DDoS attacks against a broad range of targets, including <\/span><a href=\"https:\/\/blog.kaspersky.com\/attack-on-dyn-explained\/13325\/\" target=\"_blank\" rel=\"nofollow\">Dyn\u2019s Domain Name System<\/a>, <a href=\"https:\/\/securelist.com\/blog\/incidents\/76791\/new-wave-of-mirai-attacking-home-routers\/\" target=\"_blank\" rel=\"nofollow\">Deutsche Telekom<\/a> and <a id=\"yui_3_16_0_ym19_1_1486221439306_83342\" href=\"https:\/\/securelist.com\/blog\/incidents\/76728\/ddos-attack-on-the-russian-banks-what-the-traffic-data-showed\/\" target=\"_blank\" rel=\"nofollow\"><span id=\"yui_3_16_0_ym19_1_1486221439306_83344\">some of Russia\u2019s largest banks<\/span><\/a><span id=\"yui_3_16_0_ym19_1_1486221439306_83347\">. These companies were among the first victims of a new trend \u2013 DDoS attacks launched via huge botnets made up of vulnerable IoT devices, of which <\/span><a href=\"https:\/\/securelist.com\/blog\/research\/76954\/is-mirai-really-as-black-as-its-being-painted\/\" target=\"_blank\" rel=\"nofollow\">Mirai<\/a> is one example.<\/p>\n<p id=\"yui_3_16_0_ym19_1_1486221439306_83349\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1486221439306_83351\">The approach used by the creators of Mirai has provided the basis for numerous other botnets made up of infected IoT devices. The increasing number of attacks involving IoT devices was just one of the major trends seen in Q4. <\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1486221439306_82433\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1486221439306_82432\">Throughout the quarter, there was a significant decrease in the number of amplified DDoS attacks, which were popular in the first half of 2016. This is down to improved protection against such attacks and fewer vulnerable servers available to cybercriminals.<\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1486221439306_83354\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1486221439306_83353\">The niche vacated by amplified attacks is being filled by application layer attacks, including WordPress Pingback attacks. Detection of application layer attacks poses a much greater challenge because they imitate the activities of real users. <\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1486221439306_83357\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1486221439306_83356\">The fact that these attacks are making more frequent use of <\/span><a href=\"https:\/\/www.kaspersky.com\/about\/press-releases\/2016_ddos-attacks-via-wordpress-now-come-with-encryption-kaspersky-lab-reports\" target=\"_blank\" rel=\"nofollow\">encryption<\/a><span id=\"yui_3_16_0_ym19_1_1486221439306_83359\"> only serves to increase the level of risk. Encryption dramatically increases the effectiveness of DDoS attacks, complicating the process of filtering out &#8220;junk&#8221; from among the many legitimate requests due to the need to decrypt them. <\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1486221439306_83362\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1486221439306_83361\">Kaspersky Lab\u2019s experts predict that the trends toward increasingly complex DDoS attacks and greater numbers of IoT botnets will continue in 2017.<\/span><\/p>\n<p id=\"yui_3_16_0_ym19_1_1486221439306_83364\" dir=\"ltr\"><span id=\"yui_3_16_0_ym19_1_1486221439306_83366\">\u201cIoT devices have the potential to launch DDoS attacks of any complexity, including application layer and encrypted attacks. Given the effectiveness of IoT botnets, as well as the growing number of poorly protected IoT devices, we can reasonably predict an increase in the number of such attacks as well as their power and complexity. That means companies need to take care of their protection in advance, and take a scrupulous approach to choosing their DDoS attack filtration service,\u201d<\/span> comments Kirill Ilganaev, head of Kaspersky DDoS Protection at Kaspersky Lab.<\/p>\n<p id=\"yui_3_16_0_ym19_1_1486221439306_83370\" dir=\"ltr\"><a href=\"http:\/\/www.kaspersky.com\/business-security\/ddos-protection\" target=\"_blank\" rel=\"nofollow\">Kaspersky DDoS Protection<\/a><span id=\"yui_3_16_0_ym19_1_1486221439306_83369\"> combines Kaspersky Lab\u2019s extensive expertise in combating cyber threats and the company\u2019s unique in-house developments. The solution protects against all types of DDoS attacks regardless of their complexity, strength or duration.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The last three months of 2016 witnessed significant advances in DDoS attacks. Methods are becoming more and more sophisticated, the array of devices being harnessed by botnets is increasingly diverse, while the attackers show off their capabilities by choosing bigger and more prominent targets. <\/p>\n","protected":false},"author":6,"featured_media":27604,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[388,4968,117,54],"class_list":["post-27601","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-ddos","tag-ddos-attacks","tag-kaspersky-lab","tag-security"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/27601","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=27601"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/27601\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/27604"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=27601"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=27601"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=27601"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}