2017年Q2互联网安全现状报告(英文版)_25页_5mb
报告摘要
Q2 2017 State of the Internet / Security Report Summary
Core Content
This report provides an analysis of DDoS and web application attack trends based on data from Akamai's global infrastructure and routed DDoS solution. It highlights the ongoing challenges in cybersecurity, particularly around patching and the evolving nature of attack vectors.
Main Points
-
Patching Challenges: Despite the availability of patches for WannaCry and Petya malware, many organizations still failed to apply them, leading to continued vulnerabilities. Patching involves both direct and indirect costs, and while it is a rational decision, it is often neglected due to business priorities.
-
DDoS Trends:
- The number of IP addresses involved in DDoS attacks dropped significantly in Q2, with Egypt surpassing the U.S. as the top source country for volumetric attacks.
- The median attack size decreased, but the number of attacks increased by 28% compared to previous quarters.
- PBot Botnets: These botnets, using older PHP code, were reused more frequently and launched attacks up to 75 Gbps. They target web servers rather than IoT devices, making them more efficient.
- Reflection Attacks: Continued to dominate, with DNS, NTP, and CHARGEN being the top vectors. These attacks are often amplified by misconfigured systems.
-
Web Application Attacks:
- Application layer attacks increased by 5% quarter-over-quarter and 28% year-over-year.
- SQL injection (SQLi) was the most common attack vector, accounting for 51% of all attacks.
- The U.S. remained the top source and target country for web application attacks, with a notable drop in attack traffic from Singapore.
-
Industry Targets:
- The gaming industry was the primary target for DDoS attacks, accounting for 81% of all DDoS traffic.
- One gaming company was hit with 558 attacks during the quarter, indicating a high level of targeting in this sector.
Key Information
DDoS Activity
- Attack Vectors: UDP fragment, DNS, and NTP were the top three DDoS attack vectors, accounting for 99% of the traffic.
- Sources: Egypt was the leading source of DDoS traffic in Q2 with 44,000 IP addresses, a significant drop from the U.S. in Q1.
- Targeted Industries: Gaming was the most targeted industry, with 81% of DDoS traffic directed at its operations.
- Attack Frequency: The average number of attacks per target reached 32, up from 25 in Q1, largely due to the high frequency of attacks on one gaming company.
- PBot Analysis: PBot botnets use PHP-based code and Apache Tomcat, potentially exploiting Apache Struts vulnerabilities. They are capable of launching large-scale attacks despite their smaller bot count.
- Reflection Attacks: DNS reflectors accounted for 33% of all reflection-based attacks in Q2. The U.S. had the highest number of reflection sources, but the overall reflector count was lower than in the same period last year.
Web Application Attack Activity
- Attack Vectors:
- SQLi was the most common vector, followed by LFI, XSS, RFI, and PHPi.
- Java injection attacks saw an 800% increase since Q2 2016.
- Source Countries:
- The U.S. (33.8%), China (10.2%), and Brazil (8.2%) were the top sources of web application attacks.
- The Netherlands, Ukraine, and Russia were significant sources in Europe, the Middle East, and Africa (EMEA).
- Canada moved into the top 10 source countries, with a notable increase in attack traffic compared to previous quarters.
- Target Countries:
- The U.S. was the most targeted country with over 218 million attack triggers.
- The U.K. and Brazil followed, with Singapore rising to fifth place after a significant drop in attack traffic from Q1 to Q2.
Cloud Security Resources
- Domain Generation Algorithms (DGAs): Akamai used DNS traffic analysis to detect anomalous behavior associated with DGAs, a technique that helps identify malware infections.
- Mirai C&C Clusters: Mirai botnets were linked to a large number of IoT devices, but PBot botnets are more efficient due to their use of web servers.
- Additional Research: Akamai conducted further analysis on DDoS and web application attacks, including the use of machine learning for detecting malware-related DNS activity.
Looking Forward
The report emphasizes the importance of continuous monitoring and timely patching to mitigate security risks. It also highlights the need for system administrators to be vigilant about open ports and services, especially in light of the increasing sophistication of DDoS attacks. The report suggests that the security landscape is dynamic and that organizations must adapt their strategies accordingly.
试读结束,高清完整版pdf/doc/ppt,请点下载