May 7, 2019 By Shane Schick 2 min read

Security researchers said they fended off a distributed denial-of-service (DDoS) attack in January of more than 500 million packets per second, which might constitute the largest of its kind ever publicly disclosed.

In a blog post, Imperva said the incident involved a syn flood, otherwise known as a series of Transmission Control Protocol (TCP) connection requests, which overloaded the capabilities of the machine or network in question. This was followed by an even larger syn flood containing packets of between 800 and 900 bytes.

Though the identities of those responsible aren’t known, researchers said they believe the DDoS attack was launched by two people who wrote tools that spoofed and randomized the traffic involved.

Measuring DDoS Attack Intensity

While the attack was mitigated and the customer was not mentioned by name, the researchers suggested that the incident offered a case for rethinking the way DDoS attacks are measured. Network bandwidth that reached 1.35 Tbps, for example, led several experts to classify an attack on Github as the largest-ever DDoS incident in 2018.

Given that mitigation requires inspecting every single packet head, however, the researchers argued that the volume of packets per second, not their size, becomes the bigger issue because of the network resources required. The Github incident, for example, involved a relatively low rate of 1.26 million packets per second and is something that could therefore be potentially contained by traffic filtering or an appliance, the researchers said.

The incident in January, meanwhile, put researchers on alert because packets were malformed as their parameters were randomized. This was likely a mistake caused by the attackers’ tools that were supposed to replicate real operating systems.

DDoS Attack Mitigation in the Cloud

As more organizations shift their IT infrastructure from on-premises servers to those hosted in a private, public or hybrid cloud, the potential impact of DDoS attacks could be even greater.

In fact, IBM experts pointed out that volume-based, protocol and application-layer attacks are all among the potential DDoS variants. Fortunately, these can be mitigated through a number of different means, from DDoS traffic scrubbing to the use of next-generation firewalls or content delivery networks.

More from

What Telegram’s recent policy shift means for cyber crime

4 min read - Since its launch in August 2013, Telegram has become the go-to messaging app for privacy-focused users. To start using the app, users can sign up using either their real phone number or an anonymous number purchased from the Fragment blockchain marketplace. In the case of the latter, Telegram cannot be linked to the user’s real phone number or any other personally identifiable information (PII).Telegram has also long been known for its hands-off moderation policy. The platform explicitly stated in its…

Skills shortage directly tied to financial loss in data breaches

2 min read - The cybersecurity skills gap continues to widen, with serious consequences for organizations worldwide. According to IBM's 2024 Cost Of A Data Breach Report, more than half of breached organizations now face severe security staffing shortages, a whopping 26.2% increase from the previous year.And that's expensive. This skills deficit adds an average of $1.76 million in additional breach costs.The shortage spans both technical cybersecurity skills and adjacent competencies. Cloud security, threat intelligence analysis and incident response capabilities are in high demand. Equally…

Cyberattack on American Water: A warning to critical infrastructure

3 min read - American Water, the largest publicly traded United States water and wastewater utility, recently experienced a cybersecurity incident that forced the company to disconnect key systems, including its customer billing platform. As the company’s investigation continues, there are growing concerns about the vulnerabilities that persist in the water sector, which has increasingly become a target for cyberattacks. The breach is a stark reminder of the critical infrastructure risks that have long plagued the industry. While the water utility has confirmed that…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today