2017年Q2互联网安全现状报告(英文版)_27页-5mb
报告摘要
2017 Q2 Internet Security Report Summary
Core Content Overview
This report provides an analysis of DDoS and web application attack trends observed in Q2 2017 by Akamai, highlighting changes in attack vectors, sources, and targets compared to previous quarters and years.
Key Statistics
Web Application Attacks
- Total Increase: 25% compared to Q2 2016.
- SQLi Increase: 44% compared to Q2 2016.
- U.S. Dominance: The U.S. remained the top source and target country for web application attacks.
- Brazil Decline: A 60% decrease in attacks from Brazil, which was previously the top source country.
- Asia-Pacific Shift: Singapore dropped off the top 10 source country list for web application attacks, while China remained the top source.
DDoS Attacks
- Total Increase: 28% compared to Q1 2017.
- Volumetric Attacks: 99% of DDoS attacks were volumetric, with a significant rise in the number of attacks per target.
- Attack Traffic Increase: A jump in attack traffic in late June.
- Average Attacks per Target: Rose to 32, up from 25 in Q1 2017.
Main Points
DDoS Attack Vectors
- Top Vectors: UDP fragment, DNS, and NTP remained the top three attack vectors.
- Application Layer Attacks: Represented only 1% of DDoS attacks, with a rare SSL POST attack observed.
- PBot Botnets: A new trend with mini-DDoS botnets capable of launching attacks up to 75 Gbps, using Apache Tomcat and PHP interpreters.
DDoS Sources
- Egypt's Rise: Egypt became the top source country for volumetric DDoS attacks, with 44,198 unique IPs.
- U.S. Decline: The number of U.S. source IPs dropped by 98% to 11,000.
- Gaming Targeted: 81% of DDoS attacks targeted the gaming industry, with one company receiving 558 attacks.
DDoS Targets
- Gaming Dominance: Gaming companies were the primary targets, especially due to their reliance on millisecond packet timing.
- Attack Frequency: One gaming company was targeted 558 times, averaging six attacks per day.
Reflection Attacks
- Dominance: Reflection attacks continued to dominate, with DNS, NTP, and CHARGEN as the top three vectors.
- Reflector IPs: The ratio of reflector IPs to total IPs was highest for ASN 22927 in Argentina at 1.62%.
Key Research Findings
PBot Botnets
- Attack Characteristics: PBot is a PHP-based botnet that uses fewer than 400 bots to launch attacks.
- Command and Control: PBot uses IRC for communication, with the attacker setting up an IRC server.
- Exploitation: PBot exploits Apache Struts vulnerabilities, allowing for code execution.
Malware and DGAs
- Malware Behavior: Networks infected by malware using domain generation algorithms (DGAs) show unique behavioral patterns.
- Patching Importance: The report emphasizes the importance of timely patching to prevent malware infections, highlighting the case of WannaCry and Petya.
Industry Insights
- Patching Challenges: Organizations often delay patching due to cost and risk considerations.
- Security Implications: The risk equation is dynamic, and past security decisions may no longer be valid.
- Akamai's Role: Akamai's Security Intelligence Response Team (SIRT) and other units contributed to the report's findings.
Additional Sections
Emerging Trends
- Smaller Attacks: A trend towards smaller, more targeted DDoS attacks.
- Attack Impact: Smaller attacks can still have a significant impact, especially when targeting specific ports.
- Geographic Shifts: A noticeable shift in the source countries for web application attacks, with Canada entering the top 10.
Cloud Security Resources
- Domain Generation Algorithms (DGAs): Used by malware to create command and control channels, detectable through network behavior.
- Mirai Botnets: Known for using IoT devices, but PBot shows a different approach by infecting web servers.
- Akamai's Research: Includes analysis of Mirai C&C clusters and insights into DDoS attack patterns.
Conclusion
The report underscores the evolving nature of DDoS and web application attacks, highlighting the need for continuous monitoring, timely patching, and improved network security configurations. It also notes the shift in attack sources and the re-emergence of PBot as a significant threat.
展开完整摘要
试读结束,高清完整版pdf/doc/ppt,请点下载