
Q2 2017 Akamai State of the Internet / Security Report Analyzes Re Emergence of PBOT Malware; Domain Generation Algorithms; Relationship Between Mirai Command & Control Attack Targets Report also highlights web application and DDoS attack statistics
Cambridge, MA | August 22, 2017
Newly released data shows that distributed denial of service (DDoS) and web application attacks are on the rise once again, according to the Second Quarter, 2017 State of the Internet / Security Report released by Akamai Technologies, Inc. (NASDAQ: AKAM). Contributing to this rise was the PBot DDoS malware which re-emerged as the foundation for the strongest DDoS attacks seen by Akamai this quarter.
In the case of PBot, malicious actors used decades-old PHP code to generate the largest DDoS attack observed by Akamai in the second quarter. Attackers were able to create a mini-DDoS botnet capable of launching a 75 gigabits per second (Gbps) DDoS attack. Interestingly, the Pbot botnet was comprised of a relatively small 400 nodes, yet still able to generate a significant level of attack traffic.
Another entry on the everything old is new again list is represented by the Akamai Enterprise Threat Research Team's analysis of the use of Domain Generation Algorithms (DGA) in malware Command and Control (C2) infrastructure. Although first introduced with the Conficker worm in 2008, DGA has remained a frequently used communication technique for todays malware. The team found that infected networks generated approximately 15 times the DNS lookup rate of a clean network. This can be explained as the outcome of access to randomly generated domains by the malware on the infected networks. Since most of the generated domains were not registered, trying to access all of them created a lot of noise. Analyzing the difference between behavioral characteristics of infected versus clean networks is one important way of identifying malware activity.
When the Mirai botnet was discovered last September, Akamai was one of its first targets. The company's platform continued to receive and successfully defended against attacks from the Mirai botnet thereafter. Akamai researchers have used the company's unique visibility into Mirai to study different aspects of the botnet, most specifically in the second quarter, its C2 infrastructure. Akamai research offers a strong indication that Mirai, like many other botnets, is now contributing to the commoditization of DDoS. While many of the botnet's C2 nodes were observed conducting dedicated attacks against select IPs, even more were noted as participating in what would be considered pay-for-play attacks. In these situations, Mirai C2 nodes were observed attacking IPs for a short duration, going inactive and then re-emerging to attack different targets.
Attackers are constantly probing for weaknesses in the defenses of enterprises, and the more common, the more effective a vulnerability is, the more energy and resources hackers will devote to it, said Martin McKeay, Akamai senior security advocate. Events like the Mirai botnet, the exploitation used by WannaCry and Petya, the continued rise of SQLi attacks and the re-emergence of PBot all illustrate how attackers will not only migrate to new tools but also return to old tools that have previously proven highly effective.
By the Numbers: Other key findings from the report include:
The number of DDoS attacks in Q2 increased by 28 percent quarter over quarter following three quarters of decline.
DDoS attackers are more persistent than ever, attacking targets an average of 32 times over the quarter. One gaming company was attacked 558 times or approximately six times a day on average.
Egypt was the origin of the greatest number of unique IP addresses used in frequent DDoS attacks with 32 percent of the global total. Last quarter, the United States held that spot and Egypt was not among the top five.
Fewer devices were used to launch DDoS attacks this quarter. The number of IP addresses involved in volumetric DDoS attacks dropped 98 percent from 595,000 to 11,000.
The incidence of Web application attacks increased five percent quarter-over-quarter and 28 percent year-over-year.
SQLi attacks were used in more than half (51 percent) of web application attacks this quarter-up from 44 percent last quarter-generating nearly 185 million alerts in the second quarter alone.
A complimentary copy of the Q2 2017 State of the Internet / Security Report is available for download at http://akamai.me/2i9vrdz. Download individual charts and graphs, including associated at http://akamai.me/2w6mI1v.
Methodology The Akamai Second Quarter, 2017 State of the Internet / Security Report combines attack data from across Akamai's global infrastructure and represents the research of a diverse set of teams throughout the company. The report provides analysis of the current cloud security and threat landscape, as well as insight into attack trends using data gathered from the Akamai Intelligent Platform. The contributors to the State of the Internet / Security Report include security professionals from across Akamai, including the Security Intelligence Response Team (SIRT), the Threat Research Unit, Information Security, and the Custom Analytics group.
About Akamai As the world's largest and most trusted cloud delivery platform, Akamai makes it easier for its customers to provide the best and most secure digital experiences on any device, anytime, anywhere. Akamai's massively distributed platform is unparalleled in scale with over 200,000 servers across 130 countries, giving customers superior performance and threat protection. Akamai's portfolio of web and mobile performance, cloud security, enterprise access, and video delivery solutions are supported by exceptional customer service and 24/7 monitor
Most recent headlines
13/03/2025
(L-R) Stephanie Suganami, Tatanka Means, John Malkovich, Ayo Edebiri, and Juliette Lewis attend the premiere of Opus at Eccles Theatre in Park City. (Photo by...
13/03/2025
Spotify took center stage at the London Book Fair this week, reaffirming our commitment to the audiobook market and showcasing our impact on the publishing indu...
13/03/2025
At Spotify, we work every day to lift up new voices, giving creators the opportunity to live off their art. Through Spotify Audiobooks, our in-house publishing ...
13/03/2025
Every time airborne law enforcement (ALE) teams fly, they expect their equipment to perform. Whether airborne units are conducting support for ground teams, bor...
13/03/2025
Sunday February 9 saw the annual return of the US' biggest television event, the Super Bowl LIX. Jamie McCombs, Fox Sports Audio Consultant / Sr. Audio capt...
13/03/2025
On Sunday March 2, stars across the film industry gathered at the Dolby Theatre in Los Angeles for the 97th Academy Awards. Production Sound Mixer Paul Sandweis...
13/03/2025
WUPPERTAL, Germany Riedel Communications will feature its new StageLink family of smart edge devices, Smart Audio and Mixing Engine (SAME) and Virtual Smart Pan...
13/03/2025
TAG Video Systems and Harmonic Partner to Deliver Enhanced Real-Time Monitoring ...
13/03/2025
DigitalGlue Invites NAB Visitors to Experience New Features in Managed Storage P...
13/03/2025
FOR-A America Theme - Connecting the Present, Building the Future - Comes to Lif...
13/03/2025
CTIA, the wireless industry association, has named former FCC Chairman Aji Pai as its President and Chief Executive Officer, effective April 1. He replaces Mere...
13/03/2025
he National Association of Broadcasters is urging the FCC to end its investigation of that controversial CBS interview with Kamala Harris stating there is no ...
13/03/2025
MIAMI CBS News & Stations continues to expand its use of augmented and virtual reality technologies with the planned launch of an augmented reality/virtual real...
13/03/2025
Srividhya Srinivasan, co-founder and chief customer success & innovation Officer at Amagi, tells TVBEurope how staying ahead of the latest trends is essential f...
13/03/2025
WASHINGTON FCC Chairman Brendan Carr announced that the agency has launched a massive, new deregulatory initiative that could potentially subject virtually all ...
13/03/2025
SUNNYVALE, Calif. SDVI has announced that it has integrated its Rally media supply chain management platform with the Spectra Vail multi-cloud data management s...
13/03/2025
ATLANTA Gray Media has announced that the Federal Communications Commission (FCC) has granted a waiver of its local ownership rules to permit Gray Media to acqu...
13/03/2025
TV Tech: What do you anticipate will be the most significant technology trends at the 2025 NAB Show?...
13/03/2025
Watch Student Naomi Soleils Folk Pop Performance on The Voice The songwriting major sang Stars by Grace Potter and the Nocturnals during the blind auditions.
...
13/03/2025
Roku Debuts NWSL Zone' Within Roku Sports to Spotlight Live Games, Content Feature marks Rokus first women's league-branded zone within service By Bra...
13/03/2025
Pixels, Images, Video, AI - and Us: A Perspective on AI from NDI Inventor Andrew...
13/03/2025
SVG New Sponsor Spotlight: Lighting Design Group's Steve Brill, Dennis Size ...
13/03/2025
IOC, Comcast NBCU Ink $3B Media-Rights Extension for Olympic Games Through 2036;...
13/03/2025
NCAA March Madness Live Returns with Expanded Availability of MultiView Vertical...
13/03/2025
SVG Sit-Down: Cosm's Devin Poolman on What It Takes To Deliver the Immersive...
13/03/2025
Sky Business, Sky's B2B division, providing connectivity and content to busi...
13/03/2025
Rohde & Schwarz launches R&S NRP140TWG(N) thermal power sensor: A new benchmark ...
13/03/2025
We asked the questions, analysed the answers and now we're excited to share the results of the fifth edition of the ICG Marketing Survey.
Our 2025 survey p...
13/03/2025
SAN JOSE, Calif. - March 13, 2025 Harmonic (NASDAQ: HLIT) today announced a breakthrough in video streaming innovation with the launch of new origin capabilitie...
13/03/2025
Haivision Showcases Mission-Critical Video Solutions at SOF Week 2025
Haivision's video wall systems, ISR technology, and DoDIN APL-certified video distri...
13/03/2025
Company Leads the Way with New Software-Based Production Platform, 12G Switcher,...
13/03/2025
A new Apple Immersive concert experience, Metallica, is coming to Apple Vision Pro this Friday, March 14. Filmed in Mexico City during the sold-out second-year ...
13/03/2025
Here is your host, Patrick Kielty!
Shake your Shamrocks, Patrick Kielty will be...
13/03/2025
This St. Patrick's weekend, RT invites you to celebrate all things Irish, showcasing the very best of Irish sport, entertainment and live coverage from the...
13/03/2025
What's next in AI is at GTC 2025. Not only the technology, but the people and ideas that are pushing AI forward - creating new opportunities, novel solution...
13/03/2025
Facebook
Twitter
LinkedIn
By combining T-Mobile's robust network, Thal...
13/03/2025
Bundle up - GeForce NOW is bringing a flurry of Blizzard titles to its ever-expanding library.
Prepare to weather epic gameplay in the cloud, tackling the genr...
13/03/2025
AI is leveling up the world's most beloved games, as the latest advancements...
13/03/2025
PC game modding is massive, with over 5 billion mods downloaded annually. Mods p...
12/03/2025
O Spotify acaba de lan ar o relat rio Loud & Clear deste ano, uma vis o transpar...
12/03/2025
Spotify acaba de presentar el informe Loud & Clear de este a o, una mirada trans...
12/03/2025
Ramadan, a period of profound spiritual significance for Muslims worldwide, is a time for fasting, prayer, reflection, and community. Enrich your experience thi...
12/03/2025
Spotify has just unveiled this year's Loud & Clear report, a transparent loo...
12/03/2025
More than 70% of FAST programming has been produced since 2010, according to new Gracenote report
NEW YORK March 12, 2025 Gracenote, the content data busin...
12/03/2025
GEONA, Nev. Independent digital and linear advertising rep firm Viamedia will adopt cloud-based ShowSeeker Pilot as its primary ad campaign and order management...
12/03/2025
BRUSSELS Mediagenix has announced that Wael Yasin has joined the company as sales director Central Europe....
12/03/2025
LONDON A new study highlights opportunities for shoppable TV and the massive impact online consumer spending is having on the economy, with Omdia predicting tha...
12/03/2025
CUPERTINO, Calif. Interra Systems has announced that Comcast Technology Solutions has integrated recent updates to BATON Version 9 into its operations....
12/03/2025
Nevion announces new 400G addition to its eMerge SDN media fabric offering
Brie Clayton March 12, 2025
0 Comments
High-capacity switch enhances existi...
12/03/2025
DaVinci Resolve Studio Delivers Cinematic Sound for Adam Bol
Brie Clayton March 12, 2025
0 Comments
Feature film relies on DaVinci Resolve Studio for ...