SmartStateIndia
Reports

Radware H1 2023 Report: Malicious Web Application Transactions Skyrocket 500%

Radware®, a leading provider of cyber security and application delivery solutions, released its First Half 2023 Global Threat Analysis Report. The comprehensive report leverages intelligence provided by network and application attack activity sourced from Radware’s Cloud and Managed Services, Global Deception Network, and threat intelligence research team. In addition, it draws from information found on Telegram, a public messaging platform often used by cybercriminals.

Radware’s director of threat intelligence Pascal Geenens commented, “The narrative for the threat landscape in 2023 is clear: a significant shift is taking place in Denial-of-Service attack patterns. The message to organizations is equally as clear: the focus now lies on proactively adapting to these evolving cyber threats.

“Increasing numbers of bad actors are moving up the network stack from layers 3 and 4 to layer 7 with their sights set on compromising online applications and APIs as well as essential infrastructure. To launch attacks with even greater impact, control, and scale, also look for them to continue a steady transition from compromised IoT devices to cloud-based operations.”

SHIFTING DDOS ATTACK PATTERNS
The global threat landscape continues to evolve at a rapid pace. In 2023, the profile of Denial-of-Service attacks is being redefined in terms of tactics, vector, size, complexity, and hacktivist offensives.

According to Radware’s attack activity during the first half of 2023:
• Changing tactics: The number of malicious web application transactions skyrocketed by 500% compared to the first half of 2022, while the total number of DDoS events decreased 33%. This points to a change in DDoS attack patterns as attacks shift from the network layer to the application layer.

• Surging vectors: There has been a considerable surge in DNS query floods. In the second quarter of 2023, the proportion of attacks featuring a DNS Flood vector climbed almost twofold compared to the ratio of attacks in 2021 and most of 2022.

• Bigger attacks: The relative number of large attacks (greater than 100Gbps) rose sharply, increasing from 3.75x in 2022 to 10.5x in 2023, considerably outpacing the growth in small (less than 1Gbps) and mid-sized (1Gbps to 100Gbps) attacks.

• Increasing complexity: The average complexity of attacks increased with attack size. Attacks above 1Gbps on average had more than two dissimilar attack vectors per attack, while attacks above 100Gbps had on average more than eight dissimilar attack vectors.

• Escalating hacktivist offensives: NoName057(16) was the most active hacker group on Telegram, claiming 1459 DDoS attacks, followed by Anonymous Sudan with 660 attacks, and Team Insane PK with 588 attacks.

HACKTIVIST INFLUENCES
“Hacktivists are a major contributor to the dramatic increase in the volume and intensity of layer 7 attacks, and organizations across the globe are getting caught in the crosshairs,” continued Geenens. “The effectiveness of these attacks has been significantly amplified as hacktivists rally patriotic volunteers and provide them access to crowd-sourced botnets, custom attack tools, and detailed attack tutorials.”

According to attacks claimed by hacktivists on Telegram, politically motivated and religious groups waged multiple DDoS campaigns during the first half of 2023:

• Geographic targets: Most of the hacktivist claimed DDoS attacks targeted India (674 attacks), followed by the United States (507 attacks), Israel (459 attacks), Ukraine (376 attacks), and Poland (297 attacks).

• Website targets: Government (1112 attacks), business/economy (1036 attacks), and travel (628 attacks) websites faced the most hacktivists attacks, followed by financial services (420 attacks) and health/medicine (329 attacks).

GEOGRAPHIES UNDER ATTACK
Various regions across the globe emerged as DDoS hot spots. According to Radware’s attack activity during the first half of 2023:

• EMEA shouldered the largest number of the DDoS attacks, blocking 66% of the attacks and facing 48% of the attack volume.

• The Americas blocked 25% of the DDoS attacks. While the Americas blocked a smaller share of attacks compared to EMEA, the Americas experienced a threat level on par with EMEA bearing nearly equal attack volumes (47%).

• The APAC region blocked 9% of the DDoS events and faced 5% of the global attack volume.

INDUSTRIES UNDER ATTACK
Radware’s global attack activity revealed that research and education bore almost a third (32%) of the DDoS attack volume, while service providers and technology accounted for 20% and 12%, respectively. On a regional basis, however, the distribution of DDoS attack volume varied.
During the first half of 2023:

• In the Americas, service providers (39%) and research and education (38%) drew the majority of the DDoS attack volume, followed by healthcare (7%) and energy (6%).

• In EMEA, technology (32%) experienced the biggest share of the DDoS attack volume, followed by gaming (15%) and telecom (15%).

• In APAC, service providers (50%) bore the brunt of the DDoS attack volume, followed by retail (21%), gaming (9%), and transportation and logistics (6%).

SURGE IN WEB APPLICATION ACTIVITY

While there was near linear growth in the number of web transactions per quarter in 2022, there was exponential growth in the first half of 2023.

According to Radware’s attack activity during the first six months of 2023:

• The number of malicious web application transactions grew by a staggering 500% compared to the first half of 2022. The sharp rise underscores the significant shift in DDoS attack patterns as attacks increasingly progress to layer 7.

• The most significant security violation was predictable resource location attacks (34%), followed by SQL (20%) and code injection attacks (10%), together generating 64% of total web application attack activity.

• The most attacked industry was retail (36%), followed by carriers (11%) and SAAS providers (8%).

Related posts

IDC Reveals its Top Predictions for Security and Trust for India in 2023 and Beyond

SSI Bureau

Indium Software, a Fast-Growing Digital Engineering Company, Records 78% Revenue Growth in FY21-22

SSI Bureau

Online payment fraud increases by 208% amid the Black Friday season

SSI Bureau

5 comments

Anastasiat June 29, 2024 at 12:08 am

Fantastic perspective! I found myself nodding along. For additional info, click here: LEARN MORE. What’s everyone’s take?

Reply
SandraLew August 19, 2024 at 11:09 pm

cbd creams have been a game-changer fit me! They’re at the ready, shattered, and a passionate direction to take the benefits of CBD discreetly. I’ve set that they aid me unwind after a big epoch and even put my sleep quality. Extra, shrewd particularly how much CBD I’m getting in each gummy makes it easy to manage my dosage. If you’re strange involving maddening CBD, gummies are a pronounced starting point. Just be certain to on a virtuous maker with high-quality ingredients inasmuch as the best bib observation!

Reply
Ericawag November 10, 2024 at 7:41 pm

organic cbd gummies acquire fit a go-to for me, present a available, rags means to enjoy CBD’s benefits. I admire how discreet they are, so I can procure them anytime, anywhere. Personally, they’ve helped me relax and improved my siesta quality. I also like that each gummy has a synchronize amount of CBD, which makes it easy to track my intake. As far as something anyone interested in tiresome CBD, gummies become in the interest a uncluttered starting point. Just a douceur: communicate to on a reputable mark to secure distinction and effectiveness!

Reply
Gordonclida December 4, 2024 at 11:50 pm

Trying https://www.nothingbuthemp.net/products/mood-gummies has been totally the journey. As someone rapier-like on spontaneous remedies, delving into the in every respect of hemp has been eye-opening. From THC tinctures to hemp seeds and protein competency, I’ve explored a miscellany of goods. Despite the misunderstanding adjoining hemp, researching and consulting experts have helped pilot this burgeoning field. Inclusive, my undergo with hemp has been optimistic, offering holistic well-being solutions and sustainable choices.

Reply
Charlesamava February 28, 2025 at 2:41 am

https://joyorganics.com/collections/usda-certified-cbd-oil-tinctures make available a convenient and enjoyable feeling to sustain the effects of this compound. These gummies fingers on in various flavors, potencies, and formulations, providing users with controlled dosing and long-lasting effects. Many consumers rise them championing moderation, note relief. However, it’s portentous to consume them responsibly, as effects may take longer to recoil in compared to smoking or vaping. Usually make sure of dosage guidelines and certify compliance with adjoining laws sooner than purchasing or consuming.

Reply

Leave a Comment

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More