Skip to content
Research

Trojan horse DDoS attacks on the rise

By Wei Zhang
2 min read
hacking ss img
hacking ss img
In this article (5)

The greatest DDoS risk for organisations is the barrage of short, low volume attacks which mask more serious network intrusions,  Corero Network Security has warned.

According to new Corero research, which highlights DDoS attack attempts against its customers, short, frequent, low-volume DDoS attacks continue to dominate.

Despite several headline-dominating, high-volume DDoS attacks over the past year, the vast majority (98%) of the DDoS attack attempts against Corero customers during Q1 2017 were less than 10 Gbps per second in volume. In addition, almost three quarters (71%) of the attacks mitigated by Corero lasted 10 minutes or less.

Due to their small size, these sub-saturating attacks tend to go undetected by IT security staff and many DDoS protection systems. However, they are just disruptive enough to knock a firewall or intrusion prevention system (IPS) offline so that the hackers can target, map and infiltrate a network to install malware and engage data exfiltration activity.

“Short DDoS attacks might seem harmless, in that they don’t cause extended periods of downtime. But IT teams who choose to ignore them are effectively leaving their doors wide open for malware or ransomware attacks, data theft or other more serious intrusions,”Corero Network Security CEO Ashley Stephenson explained.

Most cloud-based scrubbing solutions will not detect DDoS attacks of less than 10 minutes in duration, so the damage is done before the attack can even be reported,” Stephenson said.

“Just like the mythological Trojan Horse, these attacks deceive security teams by masquerading as a harmless bystander – in this case, a flicker of internet outage – while hiding their more sinister motives.”

In total, Corero customers experienced an average of 124 DDoS attack attempts per month, equivalent to 4.1 attacks per day during Q1 of 2017. This is a 9% increase in attacks over Q4 2016.

“Rather than showing their capabilities in full view, through large, volumetric DDoS attacks that cripple a website, using short attacks allows bad actors to test for vulnerabilities within a network and monitor the success of new methods without being detected. Most cloud-based scrubbing solutions will not detect DDoS attacks of less than 10 minutes in duration, so the damage is done before the attack can even be reported,” Stephenson said.

“As a result, the raft of sub-saturating attacks observed at the beginning of this year could represent a testing phase, as hackers experiment with new techniques before deploying them at an industrial scale.”

While low volume attacks remain the norm, Corero recorded a significant (55%) increase in large DDoS attacks of more than 10 Gbps per second, in Q1 of 2017, compared to the previous quarter. In addition, while the majority of attacks recorded lasted less than 10 minutes, the data also revealed a slight increase in attacks lasting 20 minutes or longer, with these attacks now accounting for nearly a quarter (22%) of all the attacks recorded.

Questions & Answers

Q.

What is the primary danger posed by these short, low-volume DDoS attacks?

A.

These attacks mask more serious network intrusions, allowing hackers to target, map, and infiltrate a network. They can install malware and engage in data exfiltration activity once a firewall or IPS is knocked offline.

Q.

Why do these smaller DDoS attacks often go unnoticed by security teams?

A.

Due to their small size, these sub-saturating attacks tend to go undetected by IT security staff and many DDoS protection systems. Most cloud-based scrubbing solutions also won't detect attacks under 10 minutes.

Q.

What proportion of DDoS attacks against Corero customers were of a low volume in Q1 2017?

A.

The vast majority, 98%, of DDoS attack attempts against Corero customers during Q1 2017 were less than 10 Gbps per second in volume. Almost three quarters of these attacks also lasted 10 minutes or less.

Q.

What was the average frequency of DDoS attack attempts experienced by Corero customers?

A.

Corero customers experienced an average of 124 DDoS attack attempts per month during Q1 2017. This is equivalent to 4.1 attacks per day and represents a 9% increase over the previous quarter.

Reader pulse

How concerned are you about 'Trojan Horse' DDoS attacks?

20,111 votes so far

Weekly Briefing

Asia's retail intelligence, in your inbox

Tuesday, Thursday and a Saturday Weekly Wrap: the retail stories, numbers and moves that mattered across Asia. Nothing else, and you can unsubscribe in one click.

  • Top industry moves and market shifts
  • Weekly data-driven analysis from across Asia
  • Tuesday, Thursday and the Saturday Weekly Wrap

Read by retail operators, investors and brand teams across Asia.

Protected by a quick human check. No spam, ever. Unsubscribe in one click.

SecureGDPR ready