2023-06-07-Radware-2022年全球网络威胁分析报告_37页_1mb
报告摘要
2022 Global Threat Analysis Report Summary
Core Content
Radware’s 2022 Global Threat Analysis Report provides a comprehensive overview of the cybersecurity landscape, highlighting the evolution and increase in various types of attacks throughout the year. The report emphasizes the growing threat of DDoS attacks, web application attacks, and unsolicited network activity, and analyzes the impact across different regions and industries.
Main Points
DDoS Attack Activity
- Attack Trends: The number of DDoS attacks per customer increased significantly throughout 2022, with an average of 29.3 attacks per day in Q4, a 3.5x increase compared to 2021.
- Attack Sizes: The total attack volume reached 4.44PB, a 32% increase from 2021. The largest attack in 2022 was 1.46Tbps, 2.8 times larger than the largest in 2021.
- Regional Analysis:
- The Americas: A 328% increase in blocked malicious events and 212% increase in DDoS attacks. Finance and healthcare were the most targeted industries.
- EMEA: A 158% increase in blocked malicious events and 140% increase in DDoS attacks, despite a 44% decrease in attack volume. Finance remained the most targeted industry.
- APAC: A 207% increase in blocked malicious events and 51% increase in DDoS attacks. Technology was the most attacked industry, with a 9.9% YoY growth.
Web Application Attack Activity
- Growth: Web application and API attacks grew by 128% in 2022, significantly faster than the 88% growth in 2021.
- Attack Vectors: Predictable resource location attacks accounted for almost half of the attack activity. Code injection and SQL injection represented over a quarter of attacks.
- Industries Targeted: Retail & wholesale trade, high tech, and carriers represented 60% of all blocked web application attacks.
Unsolicited Network Activity
- Top Ports: TCP ports 80 and 443 were the most scanned and attacked. UDP ports 53 (DNS), 123 (NTP), and 19 (Chargen) were also heavily targeted.
- User Agents and Credentials: Common user agents and HTTP credentials were used by attackers to exploit vulnerabilities.
- SSH Usernames: Common SSH usernames were also identified as targets.
Key Information
Attack Protocols and Applications
- UDP Dominance: UDP was the most commonly used protocol for DDoS attacks, particularly for amplification and reflection attacks. It accounted for 78.1% of the top attack vectors.
- Top Applications:
- HTTPS: Targeted via TCP port 443, with UDP floods being the primary attack vector.
- HTTP: Targeted via TCP port 80, with SYN floods being the most common.
- DNS: Targeted via both TCP and UDP, with DNS amplification being the most volumetric attack vector.
- Amplification Vectors:
- DNS Amplification: 77.1% of the total amplification volume.
- NTP Amplification: 13% of the volume.
- Memcached: 50,000x amplification factor.
- SSDP, Chargen, ARMS, WSD, CLDAP, DHCP Discover (IPv6), SNMP, RDP, CoAP, mDNS: Smaller but still notable amplification vectors.
Attack Vector Characterization
- Attack Size Categories:
- Small Attacks (<1Gbps): Increased faster than exponentially, reaching over 5x compared to 2020.
- Mid-Sized Attacks (1Gbps–100Gbps): Showed a modest increase, with a 1.31x increase in 2021 and a 1.29x increase in 2022.
- Large Attacks (>100Gbps): Increased almost 3x in 2021 and continued to grow, albeit at a slower rate, to a 3.75x increase in 2022.
- Attack Duration:
- Attacks below 1Gbps lasted on average 4 minutes.
- Attacks between 50 and 100Gbps lasted 8.67 hours.
- The longest attacks occurred between 100 and 250Gbps, lasting an average of 66 hours or 2.75 days.
IPv6 Attack Vectors
- Usage: IPv6 attack vectors represented less than 1% of total attack activity.
- Common Vectors: DNS query floods and IPv6 Neighbor Discovery ICMP floods were the primary attack vectors.
Conclusion
The 2022 threat landscape was marked by a significant increase in both the number and complexity of DDoS and web application attacks. Cybercriminals leveraged new technologies and protocols, including UDP and IPv6, to conduct more sophisticated and impactful attacks. The financial sector remained the most targeted globally, with technology and healthcare following closely. Organizations must adopt comprehensive security strategies to counter these evolving threats and protect their digital assets.
试读结束,高清完整版pdf/doc/ppt,请点下载