Lumen research reveals a rise in sophisticated, complex DDoS attacks in Q1 2023
Lumen Technologies (NYSE: LUMN) has released its Q1 2023 DDoS and Application Threat Report, highlighting a significant rise in sophisticated DDoS attacks. The report, which now includes data from ThreatX, reveals that Lumen mitigated over 8,600 DDoS attacks in Q1, a 40% increase year-over-year. Notably, the use of DNS water torture attacks surged by 417%, while a complex multi-vector attack was recorded using six different vectors. The telecommunications sector remains a primary target, accounting for 85% of the largest DDoS attacks. ThreatX blocked 25 billion requests, with bots responsible for over 30% of blocked traffic, underscoring the need for advanced security measures across digital platforms.
- Lumen mitigated over 8,600 DDoS attacks in Q1 2023, a 40% increase year-over-year.
- The report shows the rise of complex multi-vector attacks, highlighting Lumen's advanced mitigation capabilities.
- ThreatX successfully blocked 25 billion application requests, indicating robust API protection.
- 85% of the largest DDoS attacks targeted the telecommunications industry, indicating high vulnerability.
Quarterly DDoS report expanded to include data from API and application protection partner ThreatX
Read the Lumen Q1 2023 DDoS and Application Threat Report, and visit us at RSA (booth 2145-S) to hear Lumen experts talk about research findings during an in-booth "lightning talk."
"The pace at which companies and other organizations have been expanding their digital footprints has increased over the past few years," said
Notable Findings: Complex Attacks on the Rise
- Domain Name System (DNS) water torture attacks
- Twenty six percent of all single-vector attacks in Q1 utilized DNS amplification – a
417% increase over the same quarter last year. Of these, a sophisticated form of DNS amplification known as a "DNS water torture attack" was the most common. - DNS water torture is a complex attack vector designed to overwhelm the resources of an authoritative DNS server and prevent it from responding to valid DNS queries. A comprehensive DDoS mitigation solution is necessary to defend against DNS water torture attacks.
- Complex, multi-vector mitigations
- Multi-vector attacks are not new, and threat actors deploy different combinations of vectors because they are more difficult to mitigate. In Q1, Lumen mitigated an attack that utilized a record six different vectors including DNS Amplification, ICMP, TCP RST, TCP SYN/ACK Amplification and UDP amplification. Because each vector targets specific ports, protocols and systems, these complex attacks are significantly more difficult to mitigate.
Other Highlights
- The volume of DDoS attacks continues to be high. Lumen mitigated more than 8,600 DDoS attacks in Q1 – a
40% increase year-over-year and the second-busiest quarter in two years. - Consistent with previous observations, DDoS attack activity increased around
U.S. holidays. In Q1, the busiest holiday for threat actors wasMartin Luther King , Jr. Day. Lumen researchers theorize that attackers focus their efforts on or around holidays because staffing levels are typically lower. - Real-time bot protection. ThreatX blocked 25 billion application requests in Q1, representing
42% of all its customers' traffic. Of the blocked traffic, more than30% came from bots. This volume underscores the need for real-time API and application protection and tightly integrated bot mitigations solutions as part of a comprehensive security strategy. - The telecommunications industry continues to be highly targeted. Eighty-five percent of the largest 1,000 DDoS attacks that Lumen mitigated in Q1 targeted the telecommunications industry. In addition, more than 700,000 of the application requests that ThreatX blocked targeted telecom customers – the third most-targeted industry after banking and advertising.
"As we monitor our customers for attacks targeting their APIs and applications, we have seen a consistent increase in both the volume and complexity of attacks. More and more, these attacks are powered by very large botnets and leverage a combination of techniques," said
Additional resources
- Read the full Q1 2023 DDoS and Application Threat Report.
- Visit the Lumen Quarterly DDoS report archive.
- See how Lumen and ThreatX combine to offer API and Web Application Protection.
- Learn about Lumen's comprehensive DDoS mitigation and Next-gen WAF/WAAP services.
- See how Lumen Rapid Threat Defense uses global threat intelligence from Black Lotus Labs® as a countermeasure to block DDoS bots on the network as traffic hits a scrubbing center.
About
Lumen connects the world. We are dedicated to furthering human progress through technology by connecting people, data, and applications – quickly, securely, and effortlessly. Everything we do at Lumen takes advantage of our network strength. From metro connectivity to long-haul data transport to our edge cloud, security, and managed service capabilities, we meet our customers' needs today and as they build for tomorrow. For news and insights visit news.lumen.com, LinkedIn: /lumentechnologies, Twitter: @lumentechco, Facebook: /lumentechnologies, Instagram: @lumentechnologies, and YouTube: /lumentechnologies.
About ThreatX
ThreatX is managed API and application protection that lets you secure them with confidence, not complexity. It blocks botnets and advanced attacks in real time, letting enterprises keep attackers at bay without lifting a finger. Trusted by companies in every industry across the globe, ThreatXprofiles attackers and blocks advanced risks to protect APIs and applications 24/7. Learn more at https://www.threatx.com.
View original content to download multimedia:https://www.prnewswire.com/news-releases/lumen-research-reveals-a-rise-in-sophisticated-complex-ddos-attacks-in-q1-2023-301806139.html
SOURCE
FAQ
What does Lumen Technologies' Q1 2023 DDoS report indicate?
How did DNS water torture attacks change in Q1 2023?
Which sector was most targeted by DDoS attacks in Q1 2023?