20160612-阿卡迈-Q1_2016_report__akamai_s__state_of_the_internet____security_77页_7mb
报告摘要
2016 Q1 Akamai State of the Internet / Security Report Summary
Core Content
This report provides an analysis of global internet security trends based on Akamai's threat intelligence data and DDoS mitigation activities during Q1 2016. It highlights the increasing sophistication of DDoS and web application attacks, the industries most affected, and the geographic distribution of attack sources.
Main Points
-
DDoS Attack Trends:
- A record 4,523 DDoS attacks were mitigated, up from 3,693 in the previous quarter.
- 19 attacks exceeded 100 Gbps, the largest targeting the software & technology, gaming, and media & entertainment sectors.
- The average attack duration decreased to 16.14 hours from 24.82 hours in Q1 2015.
- Multi-vector attacks increased, accounting for 59% of all DDoS activity, indicating more complex attack strategies.
- NTP reflectors were the most common source of reflection DDoS attacks, accounting for 30% of attacks, with a 72% increase compared to Q4 2015.
- The gaming industry remained the most targeted, accounting for 55% of all DDoS attacks.
-
Web Application Attack Trends:
- Web application attacks increased by 26% compared to Q4 2015.
- The retail sector remained the top target, receiving 43.4% of attacks.
- There was a 2% decrease in attacks over HTTP and a 236% increase over HTTPS.
- SQLi attacks increased by 87% compared to the previous quarter.
-
Geographic Distribution of DDoS Attacks:
- China was the top source country, accounting for 27% of all DDoS attacks.
- The US was second (17%), followed by Turkey (10%), Brazil (8.6%), and South Korea (7.47%).
- Attackers often use proxies or VPS to obscure their true origin, complicating source tracking.
-
Attack Vectors:
- The top four attack vectors were UDP Fragment, NTP, DNS, and CHARGEN, making up nearly 70% of all DDoS attacks.
- TCP Anomaly attacks decreased to 2% from 3% in the previous quarter.
- Reflection-based attacks became more prevalent, with the use of booter/stresser platforms enabling multi-vector attacks.
-
Industry-Specific Insights:
- The gaming industry has consistently been the most targeted for DDoS attacks since 2014.
- The software & technology industry saw the second-highest number of attacks, followed by media & entertainment, financial services, and internet & telecom.
- The financial sector was a focus of extortion attempts, notably by the Armada Collective.
-
Threat Intelligence and Mitigation:
- Akamai's Cloud Security Intelligence (cSI) engine stores over 2 PB of threat intelligence data.
- The report includes 10 new threat advisories, vulnerability updates, and attack case studies.
-
Key Threats and Vulnerabilities:
- DNSSEC domains were used in DNS reflection attacks, increasing amplification factors.
- The Glibc vulnerability (CVE-2015-7547) and the DROWN vulnerability were highlighted.
- The SLOTH vulnerability did not affect Akamai customers.
- Bot and scraper interactions were examined as part of the security landscape.
Key Information
-
Attack Volume:
- Total DDoS attacks increased by 125.36% compared to Q1 2015.
- Infrastructure layer (layers 3 & 4) attacks increased by 142.14%.
- Web application attacks increased by 25.52% compared to Q4 2015.
-
Attack Characteristics:
- Average peak bandwidth increased significantly.
- The largest attack measured 289 Gbps, down from 309 Gbps in Q1 2015.
- Six attacks exceeded 30 Mpps, and two peaked at over 50 Mpps.
-
Mitigation Efforts:
- Akamai's global scrubbing centers and incident response teams play a critical role in mitigating DDoS attacks.
- The platform uses heuristics and data analysis to improve cloud security solutions.
-
Trends and Implications:
- The rise in multi-vector attacks and the use of booter/stresser tools indicates a growing sophistication in attack methods.
- The shift in attack vectors (e.g., from sSDP to NTP) suggests attackers are adapting to new vulnerabilities and mitigation strategies.
- The commoditization of DDoS platforms allows for low-cost, high-impact attacks.
Conclusion
The Q1 2016 report highlights a growing trend in DDoS and web application attacks, with an increasing reliance on reflection-based techniques and multi-vector attacks. The gaming and software & technology sectors were the most affected, with China and the US being the primary sources of malicious traffic. Akamai continues to enhance its threat intelligence and security solutions to counter these evolving threats.
试读结束,高清完整版pdf/doc/ppt,请点下载