q4 2014 web security report analysis and emerging trends summary

10
akamai.com [Q4 2014]

Upload: akamai

Post on 07-Aug-2015

138 views

Category:

Documents


2 download

TRANSCRIPT

Page 1: Q4 2014 web security report  analysis and emerging trends  summary

akamai.com

[Q4 2014 ]

Page 2: Q4 2014 web security report  analysis and emerging trends  summary

• 90% increase in total DDoS attacks

• 54% decrease in average attack bandwidth

• 121% increase in infrastructure layer attacks

• 16% decrease in application (Layer 7) attacks

• 31% increase in average attack duration

• 38% increase in multi-vector attacks

[Download the Q4 2014 Global DDoS Attack Report for

supporting data and analysis]

= compared to [Q3 2014]

2 / [The State of the Internet] / Security (Q4 2014)

Page 3: Q4 2014 web security report  analysis and emerging trends  summary

= multi-vector campaigns compared to [Q4 2013]

3 / [The State of the Internet] / Security (Q4 2014)

Figure1:Whilethenumberofmulti-vectorattackshassurgedthepasttwoquarters,thepercentageofmulti-

vectorcampaignshascontinuedtohoveraroundthe50percentmark

46.24

53.26

44.14

0

10

20

30

40

50

60

Q4 2013 Q3 2014 Q4 2014

Page 4: Q4 2014 web security report  analysis and emerging trends  summary

= peak bandwidth compared to [Q4 2013]

4 / [The State of the Internet] / Security (Q4 2014)

Figure2:Averagepeakbandwidthhasdroppedsincelastquarter,butremainshigherthanitwasayearago

4.21

13.93

6.41

0

2

4

6

8

10

12

14

16

Q42013 Q32014 Q42014

Page 5: Q4 2014 web security report  analysis and emerging trends  summary

= distribution of DDoS attack vectors

5 / [The State of the Internet] / Security (Q4 2014)

Figure3:InfrastructureattacksremainedpopularinQ4,makingupnearly90percentofallattackvectors

Page 6: Q4 2014 web security report  analysis and emerging trends  summary

• In late November 2014, a new attack vector, XMAS-DDoS with

Christmas tree packets, was observed for the first time.

/ This vector is featured in the Attack Spotlight of the Q4 2014 Security Report.

• Compared to Q3, SSDP accounted for a significant 214 percent

increase in number of attacks

/ SSDP was a newly observed attack in Q3

/ In Q4 2014, Akamai mitigated a 106 Gpbs SSDP-only DDoS attack

• NTP reflection increased by 181 percent compared to Q3, an indicator of

the larger number of DDoS attacks overall in Q4

/ DDoS-for-hire sites, a market with growing momentum, were a source for NTP

reflection attacks this quarter

= comparison of attack vectors since Q4 [2013]

6 / [The State of the Internet] / Security (Q4 2014)

Page 7: Q4 2014 web security report  analysis and emerging trends  summary

= targeted industries

7 / [The State of the Internet] / Security (Q4 2014)

Figure4:ThegamingindustryborethebruntofDDoSattacksinQ4,drivenbyasurgeinattackactivityattheend

ofDecember

Page 8: Q4 2014 web security report  analysis and emerging trends  summary

= total attacks per week [Q4 2014 vs Q4 2013]

8 / [The State of the Internet] / Security (Q4 2014)

Figure5:WeeklyDDoSattackssurgedinDecember2014comparedtoDecember2013,fueledbyattacksinthe

gamingindustry

Page 9: Q4 2014 web security report  analysis and emerging trends  summary

• Download the Q4 2014 State of the Internet Security Report

• The Q4 2014 report covers:

/ Analysis of DDoS attack trends

/ Breakdown of average Gbps/Mbps statistics

/ Year-over-year and quarter-by-quarter analysis

/ Types and frequency of application-layer attacks

/ Types and frequency of infrastructure attacks

/ Trends in attack frequency, size and sources

/ Where and when DDoSers launch attacks

/ Case study and analysis

= Q4 2014 global attack report

9 / [The State of the Internet] / Security (Q4 2014)

Page 10: Q4 2014 web security report  analysis and emerging trends  summary

• StateoftheInternet.com, brought to you by Akamai, serves as the home for

content and information intended to provide an informed view into online

connectivity and cybersecurity trends as well as related metrics, including

Internet connection speeds, broadband adoption, mobile usage, outages,

and cyber-attacks and threats.

• Visitors to www.stateoftheinternet.com can find current and archived

versions of Akamai’s State of the Internet (Connectivity and Security)

reports, the company’s data visualizations, and other resources designed to

put context around the ever-changing Internet landscape.

= about stateoftheinternet.com

10 / [The State of the Internet] / Security (Q4 2014)