omniture

High-Bandwidth NTP Amplification DDoS Attacks Escalate 371 Percent in the Last 30 days

Prolexic
2014-03-12 15:00 1814
 

-- Prolexic Issues High Alert DDoS Attack Threat Advisory

FORT LAUDERDALE, Fla., March 12, 2014 /PRNewswire/ -- Prolexic Technologies the global leader in Distributed Denial of Service (DDoS) protection services, now part of Akamai (NASDAQ: AKAM), today issued a high alert threat advisory on NTP amplification DDoS attacks. This attack method has surged in popularity this year, fueled by the availability of new DDoS toolkits that make it simple to generate high-bandwidth, high-volume DDoS attacks against online targets. A complimentary copy of the threat advisory is available at prolexic.com/ntp-amplification.

"During the month of February, we saw the use of NTP amplification attacks surge 371 percent against our client base," said Stuart Scholly, SVP/GM Security, Akamai Technologies. "In fact, the largest attacks we've seen on our network this year have all been NTP amplification attacks."

While NTP amplification attacks have been a threat for many years, a number of new DDoS attack toolkits have made it easier for malicious actors to launch attacks with just a handful of servers. With the current batch of NTP amplification attack toolkits, malicious actors could launch 100 Gbps attacks – or larger – by leveraging just a few vulnerable NTP servers.

A troubling DDoS attack trend

In just one month (February 2014 vs. January 2014):

  • The number of NTP amplification attacks increased 371.43 percent
  • Average peak DDoS attack bandwidth increased 217.97 percent
  • The average peak DDoS attack volume increased 807.48 percent

Unlike the largest attacks of the past two years, the NTP amplification attacks were not focused on any particular sector. Industries targeted by NTP amplification attacks in February included finance, gaming, e-Commerce, Internet and telecom, media, education, software-as-a-service (SaaS) providers and security.

In the Prolexic Security Engineering & Response Team (PLXsert) lab environment, simulated NTP amplification attacks produced amplified responses of 300x or more for attack bandwidth and 50x for attack volume, making this an extremely dangerous attack method.

PLXsert's NTP Amplification Attack threat advisory provides a detailed analysis of the threat, sample payloads, recommended DDoS protection and mitigation techniques, as well as case studies on two NTP amplification attack campaigns directed against Prolexic clients. A complimentary download of the threat advisory is available at prolexic.com/ntp-amplification.

Prolexic Threat Advisories
Designed to provide early warnings of new or modified DDoS denial of service attack signatures and scripts, recently observed by PLXsert, each threat advisory contains a detailed description of the type of DDoS attack, a list of attack signatures, and the specific network infrastructure or application that it targets. In addition, Prolexic's DDoS mitigation experts also offer insight into the nature of each type of attack, as well as provide specific warnings as to how the attack will affect businesses and enterprises of different sizes and infrastructures.

About the Prolexic Security Engineering & Response Team (PLXsert)
PLXsert monitors malicious cyber threats globally and analyzes DDoS attacks using proprietary techniques and equipment. Through data forensics and post attack analysis, PLXsert is able to build a global view of DDoS attacks, which is shared with customers. By identifying the sources and associated attributes of individual attacks, PLXsert helps organizations adopt best practices and make more informed, proactive decisions about DDoS threats.

Details of Prolexic's DDoS mitigation activities and insights into the latest tactics, types, targets and origins of global DDoS attacks are provided in quarterly reports published by the company. Prolexic's global DDoS attack reports are available at prolexic.com/attackreports.

Source: Prolexic
collection