DDoS attacks are getting more complex and harder to spot

Concept art representing cybersecurity principles
Nytt DDoS-rekord (Image credit: Shutterstock / ZinetroN)

Domain Name Server (DNS) Amplification attacks, a form of Distributed Denial of Service (DDoS) incidents, are on the rise, a new report from Lumen Technologies has claimed, adding that classic DDoS attacks are growing more complex, and harder to spot.

Lumen's report, based on data from company tools, as well as Lumen's API and application protection partner, ThreatX, claims 26% of all single-vector attacks in Q1 2023 leveraged DNS amplification. 

That equates to a 417% increase quarter-over-quarter. Of these, the most common DNS amplification method is also one of the most sophisticated ones - called “DNS water torture attack”.

Challenging mitigation

In a DNS Amplification attack, attackers would use publically accessible open DNS servers to flood a target with DNS response traffic. With DNS water torture attacks, the DNS server is prevented from responding to valid DNS queries, the researchers explained, saying that a comprehensive DDoS mitigation solution is needed to protect against these attacks.

DNS Amplification aside, the threat actors also used other vectors, such as ICMP, TCP RST, TCP SYN/ACK Amplification and UDP amplification.

“Because each vector targets specific ports, protocols and systems, these complex attacks are significantly more difficult to mitigate,” the report concludes.

Discussing DDoS attacks in general, Lumen says its volume continues to be high. The company mitigated more than 8,600 such attacks in the first quarter of the year, representing a 40% increase year-on-year. Furthermore, Q1 2023 was the second-busiest quarter in the last two years.

Most of the time, the threat actors would launch their attacks over holidays when the number of active staff in a company is generally lower. The busiest holiday in Q1 was Martin Luther King, Jr. Day, they concluded.

"The pace at which companies and other organizations have been expanding their digital footprints has increased over the past few years," said Peter Brecl, Lumen's director of product management for DDoS mitigation and application protection.

"The larger attack surface creates more opportunities for threat actors to launch attacks. The only way to protect that digital presence is to deploy a holistic solution that includes network protection, application-layer protection, and application acceleration capabilities. This type of comprehensive coverage – including DDoS mitigation, API protections, Web Application Firewalls and Bot Risk Management – helps ensure that critical business functions stay up and running – even when under an active attack."

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Web DDoS attacks see major surge as AI allows more powerful attacks
An image of network security icons for a network encircling a digital blue earth.
Standing strong against hyper-volumetric DDoS attacks
Android phone malware
Over 25 new malware variants created every single hour as smart device cyberattacks more than double in 2024
Fraud
Hackers are tricking victims into scam-yourself attacks with fake tutorials, CAPTCHAs, and updates
DDoS Attack
World's largest DDoS attack blocked, Cloudflare claims
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Dangerous new botnet targets webcams, routers across the world
Latest in Security
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Code Skull
US government warns Medusa ransomware has hit hundreds of critical infrastructure targets
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Latest in News
Man using iMessage on an iPhone
Apple will finally enable encrypted RCS messages between iOS and Android, and it's about time
Jason Sudeikis' Ted Lasso pointing at someone in Ted Lasso season 2
Believe it, baby: Ted Lasso season 4 is officially in development for Apple TV+ and Jason Sudeikis will reprise his role as the titular soccer coach
Quordle on a smartphone held in a hand
Quordle hints and answers for Saturday, March 15 (game #1146)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Saturday, March 15 (game #377)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Saturday, March 15 (game #643)
Wix automation
The world's leading website builder aims to save businesses time with new tool