DDoS attacks sizes continue to swell during 2013, Arbor says

Larger attacks a particular concern

The average size of DDoS attacks is still climbing with the number breaching 20Gbps around four times the level seen a year ago, according to Arbor Networks.

The firm's numbers of the first three quarters of 2013 show a rising curve with average attack sizes reaching 3-3.5Gbps, compared to 1.48Gbps for the same period in 2012. For the year as a whole, the average was now 2.64Gbps.

Although no attack in the third quarter reached the extreme scale of March's humungous 300Gbps Spamhaus super-DDoS, the firm's Atlas system did record one of 191Gbps in August, which suggests that the new traffic ceiling is shifting from 100Gbps to 200Gbps.

Probably more significant was the more than fourfold rise in the number of attacks over the 20Gbps threshold compared to 2012 with three months of the year still left to run, Arbor said.

Away from the notion of size, other trends are now well established, including that for packets per second (PPS) sizes, which are now on a downward path after major growth in the previous two years; IP fragmentation attacks had risen sharply from around one in ten attacks to more than a quarter.

Arbor also found that almost nine out of ten DDoS attacks lasted for less than an hour although larger ones usually went on for much longer.

Spamhaus hasn't been the only significant incident. A major DDoS of unknown size on the China's .cn country code top level domain in August briefly disrupted Internet access in the country.

"While we didn't witness a Spamhaus-sized 300Gbps attack this quarter, the largest attack size we did see in ATLAS was still pretty remarkable at 191Gbps," said Arbor's solutions architect, Darren Anstee.

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Follow our new CSO Australia LinkedIn
Follow our new social and we'll keep you in the loop for exclusive events and all things security!
Have an opinion on security? Want to have your articles published on CSO? Please contact CSO Content Manager for our guidelines.

Tags hardware systemsSpamhausarbor networksConfiguration / maintenance

More about Arbor NetworksArbor Networks

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Brand Page

Stories by John E Dunn

Latest Videos

More videos

Blog Posts