跳到主体内容

Kaspersky Lab DDoS Intelligence Report Shows Decrease in Global Reach of Attacks, Increase in Sophistication

2016年1月28日

Kaspersky Lab has published its DDOS Intelligence Report for Q4 2015*. The reporting period was marked by a decrease in the number of countries where resources are targeted as well as by new attack channels used by cybercriminals to disable resources

Kaspersky Lab has published its DDOS IntelligenceReportfor Q4 2015*. The reporting period was marked by a decrease in the number of countries where resources are targeted as well as by new attack channels used by cybercriminals to disable resources. The fourth quarter also saw the longest botnet-based DDoS attack in 2015, which lasted more than two weeks.

Resources in 69 countries were targeted by botnet-assisted attacks (compared to 79 in Q3). As in the previous quarter, the vast majority of attacks (94.9%) took place in just 10 countries. There were some minor changes among the leaders in Q4, but China, South Korea and the US remained the worst-affected countries.

The longest DDoS attack in Q4 lasted 371 hours (or 15.5 days) – a record for 2015. During the reporting period cybercriminals launched attacks using bots from different families. In Q3, the proportion of such complex attacks was 0.7%, while in the final three months of the year it reached 2.5%. The popularity of Linux bots also continued to grow – from 45.6% to 54.8% of all DDoS attacks registered in Q4 2015.

Among other trends observed in Q4 were new channels for carrying out reflection DDoS attacks that exploit weaknesses in a third party’s configuration to amplify an attack. In particular, the fourth quarter saw cybercriminals send traffic to targeted sites via NetBIOS name servers, domain controller RPC services connected via a dynamic port, and to WD Sentinel licensing servers. The attackers also continued to use IoT devices – for example, researchers identified about 900 CCTV cameras around the world that formed a botnet used for DDoS attacks.

Kaspersky Lab experts also detected a new type of attack on web resources powered by the WordPress content management system (CMS). This involved JavaScript code being injected into the body of web resources that then addressed the target resource on behalf of the user's browser. The power of one such DDoS attack amounted to 400 Mbit/sec and lasted 10 hours. The attackers used a compromised web application running WordPress, as well as an encrypted HTTPS connection to impede any traffic filtering that may be used by the owner of the resource.

"We can see that the complexity and the power of DDoS attacks have not diminished with time, even if the number of attacked resources has fallen. Unfortunately, DDoS remains a convenient and affordable tool for online crime because there are still software vulnerabilities that attackers can use to penetrate servers. There are also users who fail to protect their devices, increasing the chances of those devices being infected by bots. For our part, we are committed to providing businesses with information about the DDoS threat and promoting the fight against it, because DDoS is a threat that can and should be combated," comments Evgeny Vigovsky, Head of Kaspersky DDoS Protection, Kaspersky Lab.

Kaspersky DDoS Protection combines Kaspersky Lab’s extensive experience in combating cyber threats and the company’s unique in-house developments. The solution protects against all types of DDoS attacks regardless of their complexity, power and duration. More information about the solution is available here.

*The Kaspersky DDoS Intelligence system (part of Kaspersky DDoS Protection) is designed to intercept and analyze commands sent to bots from command and control (C&C) servers, and does not have to wait until user devices are infected or cybercriminal commands are executed in order to gather data. It is important to note that DDoS Intelligence statistics are limited to those botnets that were detected and analyzed by Kaspersky Lab.

DDoS_Q4_2015-s.jpg

Kaspersky Lab DDoS Intelligence Report Shows Decrease in Global Reach of Attacks, Increase in Sophistication

Kaspersky Lab has published its DDOS Intelligence Report for Q4 2015*. The reporting period was marked by a decrease in the number of countries where resources are targeted as well as by new attack channels used by cybercriminals to disable resources
Kaspersky logo

关于卡巴斯基

卡巴斯基是一家成立于1997年的全球网络安全和数字隐私公司。卡巴斯基不断将深度威胁情报和安全技术转化成创新的安全解决方案和服务,为全球的企业、关键基础设施、政府和消费者提供安全保护。公司提供全面的安全产品组合,包括领先的端点保护解决方案以及多种针对性的安全解决方案和服务,以及用于应对复杂和不断变化的数字威胁的网络免疫解决方案。全球有超过4亿用户使用卡巴斯基技术保护自己,我们还帮助全球200,000家企业客户保护最重要的东西。要了解更多详情,请访问www.kaspersky.com.cn.

相关文章 企业新闻