This page was machine-translated and may differ from the original. View original
In Q2 2017, DDoS attacks increased by 28% compared to the previous quarter.
Akamai Korea (CEO Son Bu-han) has released the '2017 Q2 Internet Security Status Report', which analyzes the global cloud security and threat environment based on the Akamai Intelligent Platform.
The increase in DDoS and web application attacks in Q2 was largely due to the resurgence of the PBot DDoS malware. PBot, a small DDoS botnet leveraging decades-old PHP code, was used in the largest DDoS attack observed by Akamai in Q2, reaching 75 Gbps. Despite comprising a relatively small network of 400 nodes, PBot generated a significant amount of attack traffic.
In the second quarter, 4,051 DDoS attacks occurred globally, a 28% increase from the previous quarter. For the first time in years, no large-scale DDoS attacks exceeding 100 Gbps were observed. Targeted sites experienced an average of 32 DDoS attacks during the quarter, with infrastructure attacks (Layer 3 and 4) accounting for 99% of all DDoS attacks. The top sources of DDoS attacks were Egypt (32%), the United States (8%), and Turkey (5%). The most common DDoS attack techniques in the second quarter were UDP fragmentation (27%), DNS (15%), and NTP (15%).
The number of web application attacks increased by 5% compared to the previous quarter. The United States (33.8%) continued to be the leading source of web application attacks, followed by China (10.2%), Brazil (8.2%), the Netherlands (6.4%), and India (3.3%). SQLi, LFI, and XSS accounted for approximately 93% of web application attack techniques.
“Attackers are constantly looking for vulnerabilities in enterprise security systems,” said Martin McKeay, senior security analyst and editor of the Akamai State of the Internet / Security report. “They are pouring more effort and resources into vulnerabilities that are more effective and frequently discovered. The Mirai botnet, WannaCry, Petya attacks, the continued rise of SQLi attacks, and the resurgence of Pivot demonstrate that attackers are using not only new tools, but also tools that have proven effective in the past.”
Akamai's threat research team analyzed the way malware command and control (C2) infrastructure utilizes the Domain Generation Algorithm (DGA), a reuse of existing technology. DGA was first discovered in the Conficker worm in 2008 and has been widely used as a malware communication technique ever since.
Akamai's threat research team has confirmed that infected networks generate approximately 15 times more DNS lookup traffic than legitimate networks. The majority of domains randomly generated by malware on infected networks are unregistered, resulting in a massive amount of traffic when attempting to access these domains. Analyzing the characteristics of infected and legitimate networks is a key method for identifying malware activity.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.















