UK becomes the world's number two target for DDoS hackers

'Boredom and spite' behind 220% increase in DDoS attacks, finds Imperva

Hacking

DDoS attacks have increased more than 220%, with the UK becoming the second most popular target in the world, according to research conducted by security firm Imperva.

The company's annual DDoS threat landscape report found that DDoS - or Distributed Denial of Service - attacks rose by 221% between 1 April 2015 and 31 March 2016.

This uptick was fuelled by the increasing availability of IP stressers and booters, which can effectively act as a 'DDoS-for-hire' service, Imperva said. Use of these tools comprised over 90% of all DDoS attacks in Q1 2016.

Booters and stressers are commonly used to stress-test websites' ability to cope with massive traffic volumes, but can also be used by malicious hackers as a cheap and easy way to take a site offline by flooding it with traffic.

Advertisement
Advertisement - Article continues below
Advertisement - Article continues below

The US fared worst in the number of DDoS attacks suffered, experiencing 50.3% of all attacks in Q1 2016, followed by the UK at 9.2%, then Japan at 6.7%, while the Germany suffered 3.1% of attacks and the Netherlands counted 2.9%.

UK businesses suffered a huge 23.2% of all attacks in the last three months of 2015, Its report read: "While the majority of attacks in the UK targeted small and medium sized organizations, this trend also translated into several high-profile assaults, including the takedowns of the BBC, HSBC UK and the Irish National Lottery."

"Distributed Denial of Service (DDoS) attacks are now readily available as a subscription service for the price of a deli Sandwich," said ESET security specialist Mark James, "and these services enable you to have all the benefits of large traffic based attacks without the need of the hardware to back it up.

Sadly many small businesses will not have any measures in place to mitigate these types of attacks, seeking help through professional services and expertise should be on your list when taking the multi-layered security approach you need in protecting the modern digital business."

"The fact that DDoS-for-hire now accounts for over 90 percent of all assaults paints a new profile of top bad actors," the report added. "These are non-professionals who use DDoS for racketeering or to instigate attacks out of boredom or spite. The existence of such unpredictable offenders poses a new threat to many online entities that traditionally didn't consider themselves a potential target."

This "hobbyist" activity means that most of the DDoS activity observed by Imperva was brief and unsophisticated, with 66% of attacks using just one attack vector and almost 90% lasting less than an hour.

Advertisement - Article continues below

However, the figures also revealed how hackers can use DDoS attacks as part of a wider breach strategy. According to Imperva, experienced hackers sometimes launch multiple short DDoS attacks, spaced out over weeks.

This has the effect of exhausting security and response teams by keeping them on high alert around the clock. DDoS attacks can also be used as a smokescreen, distracting security operatives from a hackers's real goal, such as sabotage or data exfiltration.

Imperva's research also revealed that attackers are becoming more persistent. In the first quarter of 2016, half of all targets were hit by more than one attack, with nearly 20% hit by almost five.

Featured Resources

How inkjet can transform your business

Get more out of your business by investing in the right printing technology

Download now

Journey to a modern workplace with Office 365: which tools and when?

A guide to how Office 365 builds a modern workplace

Download now

Modernise and transform your sales organisation

Learn how a modernised sales process can drive your business

Download now

Your guide to managing cloud transformation risk

Realise the benefits. Mitigate the risks

Download now
Advertisement

Recommended

Visit/security/internet-security/354417/avast-and-avg-extensions-pulled-from-chrome
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019
Visit/security/29068/is-your-company-taking-enough-accountability-on-cybersecurity
Security

Are you taking enough accountability on cyber security?

18 Dec 2019
Visit/security/354156/google-confirms-android-cameras-can-be-hijacked-to-spy-on-you
Security

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019
Visit/security/29204/how-can-you-protect-your-business-from-crypto-ransomware
Security

How can you protect your business from crypto-ransomware?

4 Nov 2019

Most Popular

Visit/cloud/cloud-computing/354767/google-cloud-snaps-up-multi-cloud-analytics-platform-for-26bn
cloud computing

Google Cloud snaps up multi-cloud analytics platform for $2.6bn

13 Feb 2020
Visit/mobile/28299/how-to-use-chromecast-without-wi-fi
Mobile

How to use Chromecast without Wi-Fi

5 Feb 2020
Visit/operating-systems/27717/how-to-fix-a-stuck-windows-10-update
operating systems

How to fix a stuck Windows 10 update

12 Feb 2020
Visit/cloud/microsoft-azure/354771/microsoft-azure-is-a-testament-to-satya-nadellas-strategic-nouse
Microsoft Azure

Microsoft Azure is a testament to Satya Nadella’s strategic nouse

14 Feb 2020