UPDATED 09:00 EDT / APRIL 16 2024

SECURITY

Cloudflare reports 50% first-quarter increase in distributed denial-of-service attacks

A new report from content delivery network provider Cloudflare Inc. today details a disturbing rise in distributed denial-of-service attacks in the first quarter, including a surge of attacks against Sweden.

The Cloudflare DDoS Threat Report for 2024 Q1, based on traffic and attacks observed through Cloudflare’s network, found that DDoS attacks overall jumped 50% year-over-year from a year ago. During the quarter, Cloudflare mitigated 4.5 million DDoS attacks, including 1.7 million HTTP DDoS attacks, which shot up 93% year-over-year. The figures were notably higher than any quarter through 2023.

In total, Cloudflare systems mitigated 10.5 trillion HTTP DDoS attack requests, as opposed to attacks, in the first quarter and mitigated more than 59 petabytes of DDoS attack traffic, just on the network layer.

The largest single DDoS attack recorded so far this year involved a Mirai-variant botnet. The attack reached 2 terabits per second and targeted an Asian hosting provider.

The quarter also saw a surge in DNS-based DDoS attacks, with the report noting that they have become the most prominent attack vector. DNS-based DDoS attacks surged 80% year-over-year and now account for abut 54% of all DDoS attacks.

Sweden, not a country one would usually associate with cyberattacks, saw a huge increase in DDoS attacks, with Cloudflare observing a 466% increase in attacks targeting the country. The attacks are attributed to Sweden joining the North Atlantic Treaty Organization alliance, with the increase in attacks mirroring a pattern observed during Finland’s NATO accession in 2023.

Even with the increase in attacks, Sweden did not make the top 10 when it comes to countries targeted in the quarter. To no surprise, the most attacked country or territory was the U.S., followed by China, Canada, Vietnam, Indonesia, Singapore, Hong Kong, Taiwan, Cyprus and Germany.

By industry, the gambling and gaming industry was the most targeted. In the first quarter, the gaming and gambling industry was the most attacked by HTTP DDoS attacks, with seven out of every 100 DDoS requests that Cloudflare mitigated aimed at the industry.

“With four out of every 10 HTTP DDoS attacks lasting over 10 minutes and approximately three out of 10 extending beyond an hour, the challenge is substantial,” the report states.

Image: Wikimedia Commons

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.