2016年-数据局_Akamai:2016年Q1互联网安全报告_77页_7mb
报告摘要
Akamai State of the Internet / Security Report - Q1 2016 Summary
Core Content
This report provides an in-depth analysis of DDoS and web application attack trends observed by Akamai in Q1 2016, using data from its global infrastructure and routed DDoS solution. It highlights the evolving threat landscape, including the rise of multi-vector attacks, changes in attack sources and industries, and the impact of new technologies and vulnerabilities on attack patterns.
Main Points
-
Akamai's Security Infrastructure:
Akamai's Intelligent Platform™ offers cloud security solutions and uses a distributed network to absorb and mitigate attack traffic. The platform's Cloud Security Intelligence (cSI) engine stores over 2 PB of threat intelligence data, including 10 TB of application-layer attack data per day. -
DDoS Activity Overview:
- Total DDoS Attacks: Increased by 125.36% compared to Q1 2015 and 22.47% compared to Q4 2015.
- Infrastructure Layer (Layers 3 & 4) Attacks: Rose by 142.14% compared to Q1 2015 and 23.17% compared to Q4 2015.
- Attack Duration: The average attack duration dropped to 16.14 hours from 24.82 hours in Q1 2015.
- Large-scale Attacks (>100 Gbps): There were 19 such attacks in Q1 2016, up from 8 in Q1 2015 and 5 in Q4 2015. The largest attack measured 289 Gbps, targeting the software & technology, gaming, and media & entertainment sectors.
- Multi-vector Attacks: Represented 59% of all DDoS attacks in Q1 2016, showing a continued trend of increasing complexity in attack tools.
-
Attack Vectors:
- The top four vectors were UDP Fragment, NTP, DNS, and CHARGEN, accounting for nearly 70% of all DDoS attacks.
- UDP Fragment attacks increased by 6 percentage points, attributed to the amplification factors in reflection-based attacks.
- NTP attacks accounted for 30% of all DDoS attacks, while SYN floods represented 7%.
-
Attack Sources:
- China was the leading source country at 27%, followed by the US at 17% and Turkey at 10%.
- Brazil also increased its share, contributing 8.60% of attacks, likely due to the opening of new data centers by a global cloud provider.
- Attackers often use proxies or Virtual Private Servers (VPS) to obscure their true origin.
-
Industry Impact:
- The gaming industry was the most targeted, accounting for 55% of all DDoS attacks.
- Software & technology followed at 25%, then media & entertainment (5%), financial services (4%), Internet & telecom (4%), education (3%), and public sector (2%).
- The retail sector was the most affected by web application attacks, with 43.4% of attacks directed at it.
-
Web Application Attack Trends:
- Total web application attacks increased by 25.52% compared to Q4 2015.
- Attacks over HTTPS rose by 236%, while those over HTTP decreased by 2%.
- SQLi attacks increased by 87%, indicating a growing focus on application-layer vulnerabilities.
-
Key Threats and Trends:
- Booter/stresser tools are increasingly used to launch multi-vector attacks, often based on reflection techniques.
- The gaming sector continues to be a prime target, likely due to the availability of reflection-based tools and the presence of frustrated users.
- DNSSEC has contributed to increased amplification in DNS reflection attacks, even though early DNS attacks were more powerful.
- The use of botnets and scrapers has expanded, with some attacks involving large-scale bot interactions.
-
New Datasets and Visualizations:
- Includes new data on bot and scraper interactions.
- Introduces visualizations of DDoS and web application attack trends.
-
Threat Advisories and Updates:
- Akamai published 10 advisories and updates, covering topics such as DNSSEC, Glibc, DROWN, and the SLOTH vulnerability.
Key Information
-
DDoS Attack Vectors:
- UDP Fragment, NTP, DNS, and CHARGEN accounted for nearly 70% of all attacks.
- NTP reflectors were used in 30% of attacks, up from previous quarters.
- The use of DNSSEC domains increased the amplification factor in DNS reflection attacks.
-
Attack Source Countries:
- China, US, Turkey, Brazil, and South Korea were the top sources.
- Brazil's rise is linked to the opening of new data centers by a global cloud provider.
-
Attack Targets by Industry:
- Gaming, software & technology, and media & entertainment were the most affected sectors.
- Retail remained the most targeted for web application attacks.
-
Attack Duration and Bandwidth:
- The average attack duration decreased to 16.14 hours.
- Large attacks (>100 Gbps) increased significantly, but the largest attack dropped from 309 Gbps to 289 Gbps.
-
Mitigation and Response:
- Akamai's global scrubbing centers and incident responders play a critical role in mitigating attacks.
- The company responded to several new threats, including the BillGates malware, DNSSEC targeting, and SLOTH vulnerability.
-
Future Outlook:
- The report suggests a continued evolution of DDoS attack techniques, with a growing emphasis on reflection-based attacks and multi-vector frameworks.
- It also indicates the need for more advanced mitigation strategies as attackers become more sophisticated.
Conclusion
The Q1 2016 report highlights a significant increase in DDoS and web application attacks, driven by the evolution of attack tools and the commoditization of DDoS platforms. The gaming and software & technology sectors were particularly vulnerable, with China and the US remaining the primary sources of attack traffic. Akamai continues to enhance its security infrastructure and response capabilities to counter these evolving threats.
试读结束,高清完整版pdf/doc/ppt,请点下载