Akamai-2018年夏季互联网现状-安全:Web_攻击(英文版)-2018.10-28页-3mb
报告摘要
SOTI SUMMER 2018: Web Attack Report Summary
Core Content
The Summer 2018 State of the Internet / Security: Web Attack report highlights the evolving landscape of web-based security threats, particularly focusing on DDoS (Distributed Denial of Service) attacks and credential abuse targeting the hospitality and travel industries. The report provides insights into the trends, new attack vectors, and the impact of law enforcement actions.
Main Points
DDoS Attack Trends
- Overall Increase: There was a 16% increase in total DDoS attacks compared to Summer 2017.
- Infrastructure Layer Attacks: These attacks increased by 16%, indicating a growing focus on lower-level network infrastructure.
- Reflection-Based Attacks: These attacks saw a 4% increase, with memcached becoming a notable new vector.
- Application Layer Attacks: These attacks surged by 38%, showing a shift towards more sophisticated, targeted methods.
Key Observations
- Memcached Reflection Vector: This new vector enabled attacks of unprecedented scale, with the largest attack recorded at 1.35 Tbps, breaking the 1 Tbps threshold.
- Mitigated Attacks: Akamai mitigated 7,822 DDoS attacks during the summer.
- New Attack Patterns:
- Multi-vector reflection attacks using obscure vectors like IPMI and IKE.
- Mirai attacks continued with new variants.
- Law Enforcement Action: Operation Power Off was a collaborative effort between the Dutch National High Tech Crime Unit and the UK National Crime Agency to take down the DDoS-for-hire site webstresser.org.
What You Need to Know
- The Web Attack report is now published twice a year, not quarterly.
- DDoS attacks are not only about volume, but also about advanced techniques.
- Operation Power Off resulted in the arrest of administrators and the seizure of infrastructure, though the overall number of attacks did not show a significant decline.
- Russia and China are major sources of credential abuse attacks against the hospitality and travel industries.
Key Information
DDoS Attack Statistics
- Total DDoS attacks: 16% increase.
- Infrastructure layer attacks: 16% increase.
- Reflection-based attacks: 4% increase.
- Application layer attacks: 38% increase.
- Largest attack: 1.35 Tbps using memcached.
- Mitigated attacks: 7,822 attacks.
Attack Vectors and Techniques
- Memcached: A new reflection vector that was not previously used in DDoS attacks.
- SYN Flood: Exceeded 170 Gbps and 65 Mpps.
- POST Flood: Used to target web servers.
- PSH/ACK Flood: A secondary vector used in DDoS attacks, peaking at 120 Gbps and 18.6 Mpps.
- DNS Attacks: Volumetric DNS queries peaked at 1.8 Gbps and 2.5 Mpps, with some attacks targeting DNS servers rather than web sites.
Credential Abuse
- Hotel and travel sites experienced the highest credential abuse connections.
- Impersonators of known browsers accounted for 40% of the traffic on these sites.
- "Other Bots" made up 20% of bot traffic, indicating evolving bot behaviors.
- Search engine bots (like Google and Bing) also contributed significantly to bot traffic.
Geographic Trends
- Russia, China, and Indonesia were the primary sources of credential abuse attacks.
- United States was the largest source and destination of DDoS attacks.
- Brazil and the Netherlands showed a long-term trend of being significant sources of malicious traffic.
Key Takeaways
- DDoS attacks are becoming more sophisticated, with new vectors like memcached and PSH/ACK being used.
- Credential abuse is a major threat, especially to the hospitality and travel industries, with Russia and China being the main sources.
- Law enforcement is actively combating DDoS-for-hire services, as seen in Operation Power Off.
- Security strategies must evolve to address these threats, emphasizing proactive measures, real-time monitoring, and collaboration between manufacturers and security professionals.
Recommendations
- Monitor network health and packet captures to identify attack vectors.
- Implement robust DDoS mitigation tools and web application firewalls.
- Coordinate with vendors to prioritize defense of core assets.
- Stay informed about emerging threats and new attack techniques.
- Secure credentials by preventing password reuse and monitoring login attempts.
Future Outlook
- The State of the Internet / Security report will continue to evolve, with a focus on timely and useful insights.
- New technologies like IoT and AI are being exploited by attackers, highlighting the need for advanced security measures.
- The next big threat could come from new network services or compromised IoT devices.
Conclusion
The report underscores the complexity and adaptability of modern cyber threats, especially DDoS attacks and credential abuse. It emphasizes the importance of proactive security strategies, collaboration, and real-time monitoring to stay ahead of these evolving threats.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载