1 Five percent of Web traffic caused by DDoS attacks - Security - News - ZDNet Australia

Five percent of Web traffic caused by DDoS attacks

After analysing traffic from 68 ISPs around the globe, a security researcher claims that as much as five percent of all Internet traffic is from DDoS-attacks.

Since beginning the research, Arbor Network's chief research officer Danny McPherson claims there were over one million denial of service attacks — roughly 1,300 per day — across the ISP networks involved in the study, which has already run for 18 months.

Information collected during the study was shared anonymously between the 68 ISPs and Arbor. McPherson said the data helped better understand Internet traffic and attack characteristics such as packet size distributions, attack vectors, the frequency and scale of attacks, as well as source and target distributions.

The system looks specifically at traffic on Transport Layer 3 and 4, which, according to McPherson, is the equivalent of looking at "details on an envelope" but not the content inside.

"We look at how big [an attack] is, where it's from, and who it's being sent to — basically the addressing and transaction information," McPherson told ZDNet.com.au.

"No one has ever [conducted research] at this speed. A couple of gigabytes per second was the maximum and they have only looked at single links on a network. Here we're covering 68 ISPs at speeds of around 1.5 terabytes per second," he said.

But the study is not just about speed, explained McPherson: "We want to understand the characteristics behind the biggest and most distributed attacks."

"If you understand how many packets of what protocol-type and how big those packets are, [ISPs] can engineer their networks more effectively," said McPherson.

The data may also help router manufacturers improve their designs to better meet network traffic demands, he said.

The monitoring system has already helped reveal which organisations are being targeted and has even uncovered interactions between the more nefarious participants on the Internet: botnet operators.

"Some of the biggest attacks are on the root name server infrastructure, and there are many extortion attacks. 99 percent of these attacks aren't that interesting but one percent is really interesting.

"We like to look at attack data ... We have our own malware database and monitor control channels to see where people launch attacks from, such as which botnets are attacking which targets," he said.

Early last year, McPherson noticed a high frequency of cyber-attacks that looked remarkably similar.

"It turned out that MPack was attempting to steal bots from Storm," he said.

"The Storm guys figured out that MPack was stealing bots and started attacking Mpack distribution sites so they couldn't compromise each others hosts."

But besides understanding that everything is an enemy to a botnet operator, McPherson said the study helped explain the significance of DDoS attacks for the average corporate network.

"What has surprised me the most is that this [DDoS] traffic bottoms out consistently at around two percent of total traffic. The best is one percent of all traffic and the worst is around five percent — when you factor in spam. If you think about it, that's quite a lot and there's a lot of room for improvement. So for an organisation, if you can find one to two percent more efficiency out of your network resources, that's important," he said.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Quick Poll

What is the biggest data management challenge in your organisation?

ZDNet Australia Live

Social business success: Burberry | ZDNet http://t.co/BpBMXRYw #socbiz

The mining industry run around telling us about wht great employment gererators they are when they are trying to avoid taxation, as soon ...

4 minutes ago by Kevin Cobley on Robotic mining worth its high cost: Rio

Pilot sues Virgin for being iPad Luddite: A pilot allegedly damaged his back carrying a 18kg flight bag full of ... http://t.co/ksT5JJ37

VeriSign Authentication Services provides solutions that allow companies & consumers to engage in communications & commerce online with c...

12 minutes ago by santla on Hackers stole data from VeriSign in 2010

RT @zdnetaustralia: Telstra reveals cause behind compromised BigPond email accounts http://t.co/V5cYJMcN

Robotic mining worth its high cost: Rio - ZDNet Australia http://t.co/SirHOAuw

In defense of the Galaxy Note's stylus http://t.co/GiBQHPjT

Pilot sues Virgin for being iPad Luddite http://t.co/B3lTvulR

Phishing scam causes Telstra email woe http://t.co/kcXa15Tm

by http://t.co/vmlQ0Ecb: Pilot sues Virgin for being iPad Luddite: A pilot allegedly damaged his back carrying a ... http://t.co/aHx5vxkg

Phishing scam causes Telstra email woe:
http://t.co/nNSQWX96

I've delt with developers daily for 2 decades and I am astounded at the arrogance that new grads possess, combined in no fundamentals and...

24 minutes ago by Dr_Truth on IT lumped with 'arrogant, ignorant' grads

Every mobile phone we should have a good mobile security downloaded so that we can be aware of this malwares!!!

28 minutes ago by santla on Google scans Android apps for malware

Oh nice to know about this article!!!

29 minutes ago by santla on Ex-Firefox exec plans Facebook for Android

Its good if they get it!!

29 minutes ago by santla on Will Android get a root store?

Android is good!!! i too have android mobile ..

32 minutes ago by santla on Android features better than iPhone: Woz

ZDNet: Did Google withhold malware protection details from partners? http://t.co/nblEvOYc

Thanks for the artilcle i too have android mobile phone!! and its so good and i have comodo mobile security in my phone

33 minutes ago by santla on Android to be developer platform of choice

Thanks for the artilcle i too have android mobile phone!! and its so good and i have comodo mobile security in my phone

33 minutes ago by santla on Android to be developer platform of choice

Great to know about it. along with this we can have some good mobile security so that we can remain safe with our mobiles tooo such a com...

34 minutes ago by santla on iPhone 4S wins Android, BlackBerry users

Android mobile very cheap and good now a days more than ipad !!!

35 minutes ago by santla on Android closes in on iPad market share

Android mobileare getting lot of malware now a days its better to have some good mobile securities like Comodo Mobile Security !!!

37 minutes ago by santla on Google scans Android apps for malware

RT @zdnetaustralia: Telstra reveals cause behind compromised BigPond email accounts http://t.co/Xbkfy5OK

This has been a serious problem now a days!!!

38 minutes ago by santla on Microsoft settles with alleged botnet host

This has been a serious problem now a days!!!

38 minutes ago by santla on Microsoft settles with alleged botnet host

"I agree that their products have gotten a lot better. How insecure they still are says a lot about how hard this problem really is

38 minutes ago by santla on Has Microsoft fixed its security issues?

Yeah i accept with myron!!

40 minutes ago by santla on Microsoft halts another botnet: Kelihos

the Kelihos botnet has not crawled out of the grave, ... new botnet is being assembled using a variant of the original malware.

41 minutes ago by santla on Antivirus employee named in botnet case

Thanks to know about it the artile was good

42 minutes ago by santla on 2011: security's most spectacular stuff-ups

Thanks to know about it the artile was good

42 minutes ago by santla on 2011: security's most spectacular stuff-ups

Kelihos, according to the researchers, has been found in new variants and they quite resemble the earlier build.

42 minutes ago by santla on Kelihos variants slipped Microsoft's noose

Google's answer to EU as succinct as its privacy policy - ZDNet (blog): Telegraph.co.ukGoogle's answer to EU as ... http://t.co/uA9aOxQD

Beware of hoaxes. Facebook does not donate money based on the number of shares or likes for "sick babies".... http://t.co/MeXFoUbe

Phishing scam causes Telstra email woe http://t.co/BYZTvadN via @zdnetaustralia

Did Google withhold malware protection details from partners? http://t.co/SHGePNhK

Govt caught in internet-security time warp http://t.co/4st8GIcj

Phishing scam causes Telstra email woe: A phishing scam has led to a number of compromised BigPond email account... http://t.co/PXvZo1no

Phishing scam causes Telstra email woe - Communications - News - ZDNet Australia http://t.co/ikFfPLE1

Pilot sues Virgin for being iPad Luddite: A pilot allegedly damaged his back carrying a 18kg flight bag full of ... http://t.co/mjzcTBWi

Pilot sues Virgin for being iPad Luddite - A pilot allegedly damaged his back carrying a 18kg flight bag full of cha... http://t.co/0NcvLleE

3D printer produces new titanium jaw - ZDNet Australia: BBC News3D printer produces new **** http://t.co/Odgv46l8 #3DPrinting #DoYou3D

Why Windows 8 will be DOA:
http://t.co/yq26BIFr

Govt caught in internet-security time warp - ZDNet Australia (blog): http://t.co/a8ARfbg4

Did Google withhold malware protection details from partners? http://t.co/iLlp0Q5E

Robotic mining worth its high cost: Rio http://t.co/5NMJMDR7

Govt caught in internet-security time warp http://t.co/JVv81vzC

Telstra reveals cause behind compromised BigPond email accounts http://t.co/V5cYJMcN

“@scanman: The Apple fanboy problem http://t.co/ZxuB04OS” This article seems a bit strange.

That Bigpond phishing scam last year caused a number of email addresses to be blacklisted. http://t.co/gMvEmLHx

ZDNet App Wrap: 6 February 2012 - ZDNet Australia http://t.co/oWvIL5RD

by http://t.co/vmlQ0Ecb: Govt caught in internet-security time warp: Today is Safer Internet Day, the day when th... http://t.co/H2x7LRRf

RT @zdnetaustralia: Govt caught in internet-security time warp: http://t.co/nIj6MGJE

Govt caught in internet-security time warp: Today is Safer Internet Day, the day when the government likes to sh... http://t.co/5AcbMvu0

RT @JLLLOW: RT @zdnetaustralia: Govt caught in internet-security time warp: http://t.co/nIj6MGJE

Why you need to be careful about whose SSL certificate you install on your website: http://t.co/MmAs6rvo #security #li

This story has been voted 5 times in the last 24 hours!

3 days ago, Abbott paving a telecoms road to nowhere

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar