DDoS Threat Landscape: Q4 2022 in Review

Cloudflare’s global network mitigated millions of DDoS attacks during the final quarter of 2022, a period marked by persistent and increasingly sophisticated threats despite year-long declines in some metrics. While holiday traffic surged, so did attack frequency and volume, with notable spikes in both volumetric and ransom-driven campaigns.

HTTP DDoS attack traffic rose 79% year-over-year (YoY) in Q4, even as quarterly figures trended downward throughout 2022. Although many attacks remained small, Cloudflare observed terabit-scale attacks, traffic in the hundreds of millions of packets per second, and HTTP attacks peaking in the tens of millions of requests per second—all launched by sophisticated botnets.

  • Volumetric attacks increased: the number of attacks exceeding 100 gigabits per second (Gbps) grew 67% quarter-over-quarter (QoQ), and the number exceeding three hours in duration climbed 87% QoQ.
  • Ransom DDoS attacks remained prevalent: 16% of surveyed Cloudflare customers reported receiving a threat or ransom demand alongside an attack in Q4, up 14% QoQ but down 16% YoY.

Industry Targeting and Regional Breakdown

Attack traffic represented a significant share of all traffic to specific sectors. HTTP DDoS traffic alone comprised 35% of all traffic to Aviation and Aerospace properties. Network-layer attacks accounted for roughly one-third of all traffic to Gaming/Gambling and Finance industries. The Education Management sector saw 92% of its traffic as network-layer attack traffic, while Information Technology and Services and Public Relations & Communications industries saw 73% each.

Regional patterns for HTTP attacks varied widely. In North America and Oceania, the Telecommunications industry was most targeted. South America and Africa saw the Hospitality industry hit hardest. Europe and Asia both faced the most pressure on Gaming & Gambling, while the Middle East's Education sector led in attacks.

Geographic Sources and Targets of Attacks

On the network layer, 93% of traffic to China-based properties behind Cloudflare was attack traffic. Lithuania saw 86% and Finland 80% of traffic similarly classified. In terms of network-layer data center traffic, Botswana recorded 52% attack traffic, with Azerbaijan, Paraguay, and Palestine each at approximately 40%.

On the application layer, Georgia topped the list with 42% of traffic being HTTP attack traffic. Belize followed at 28%, and San Marino just below 20%. The largest source of application-layer attack traffic was Libya, where almost 20% of all traffic originated.

It is important to note that source countries are not necessarily the location of attackers. Attackers often operate remotely to obscure their location, so high source percentages typically indicate the presence of botnet nodes, hijacked servers, or IoT devices within those regions.

Ransom DDoS Attacks: A Persistent Tactic

Unlike ransomware, which requires tricking a victim into executing malicious code, Ransom DDoS attacks are easier to execute. Attackers need no email phishing or network foothold—only enough traffic to disrupt internet-facing services. After flooding a target, the attacker demands a ransom, typically in Bitcoin, under threat of further attacks.

Cloudflare's data comes from automated surveys sent to customers after each DDoS mitigation. Of respondents in Q4, 16% reported receiving a threat or ransom note, reflecting a 14% increase from Q3 2022 but a 16% decrease from Q4 2021. On average, these surveys collected 187 responses per quarter over the past two years.

Application-Layer Attack Metrics

Application-layer attacks target web servers by overwhelming them with HTTP/S requests, which can force the server to drop legitimate requests or crash. In Q4, Aviation and Aerospace was the most attacked industry, with roughly 35% of traffic classified as HTTP DDoS attacks. Events Services came next at over 16%, followed by Media and Publishing, Wireless, Government Relations, and Non-profit industries.

By customer billing address, Georgia experienced the highest proportion of HTTP attack traffic at 42%. Belize was second with almost a third of traffic as attack traffic, and San Marino at just below 20%. Libya was the top source country, where nearly 20% of all HTTP traffic was attack traffic, followed by Timor-Leste (18%), the British Virgin Islands (17%), and Afghanistan (14%).

Methodology Changes

Starting with this report, Cloudflare revised how it calculates the percentage of attack traffic when bucketing by dimension—such as target country, target industry, or source country. Previously, attack traffic to a given dimension was divided by total traffic to all dimensions. Now, it is divided only by total traffic to that same dimension. This change aligns application- and network-layer calculations and improves representation of the attack landscape.

For instance, the previous method would divide HTTP attack requests to a target industry by all HTTP requests to all industries, making the Gaming and Gambling industry look like the most attacked. The new method instead divides attack requests to a particular industry by total requests to that industry, which moves Aviation and Aerospace to the top at 35%, with Gaming and Gambling falling to 14th at 2.4%.

The revised calculations apply only to: target industries of application-layer attacks, target countries of application-layer attacks, source of application-layer attacks, target industries of network-layer attacks, and target countries of network-layer attacks. No other sections—including ransom DDoS attacks, attack rate, duration, vectors, or emerging threats—saw methodology changes. Those metrics never factored legitimate traffic into the calculation.

Network-layer DDoS attacks target the infrastructure itself — routers, servers, and the internet link — rather than the application layer. The total number of network-layer attacks dropped 14% quarter-over-quarter and 13% year-over-year in Q4. But that broad decline hides a shift toward more intense and longer-lasting events.

Attacks exceeding 100 Gbps jumped 67% QoQ, while those in the 1–100 Gbps range rose roughly 20% and the 500 Mbps–1 Gbps band climbed 108%. One example: a 1 Tbps ACK flood aimed at a Korean hosting provider the week after Thanksgiving. It lasted about a minute and was automatically detected and mitigated via Cloudflare’s Magic Transit L3 protection.

The picture for attack duration was similar. Sub-10-minute attacks fell 76% QoQ, while 1–3-hour attacks rose 349% and over-3-hour attacks grew 87%. Still, more than two-thirds of attacks lasted between 10 and 20 minutes.

A Graph of a 1 Tbps DDoS attack

SYN floods keep the top vector spot

SYN floods remained the dominant network-layer attack method, accounting for nearly half of all attacks. The technique exploits the stateful nature of the TCP three-way handshake: the attacker sends spoofed SYN packets, the server replies with SYN/ACKs and allocates memory for connections that never complete, eventually exhausting resources. A sufficient volume can make the server unable to process legitimate connections or even crash.

DNS floods and amplification attacks were a distant second at roughly 15% of attacks, followed by UDP-based floods at 9%.

Memcached and other older exploits resurface

The fastest-growing attack types this quarter were all amplification methods built on legacy protocols. Memcached-based attacks surged 1,338% QoQ. Memcached is a database caching system whose UDP support can be abused for reflection attacks, with amplification factors up to 51,200x. In second place, SNMP-based attacks rose 709% QoQ, using the UDP-based network management protocol on port 161 to bounce spoofed queries off devices. Third was VxWorks-based DDoS traffic, up 566%, exploiting a debug service enabled by default in the real-time OS used across networking gear and IoT devices — a vulnerability (CVE-2010-2965) documented since 2010 but still active in the wild.

Targets by industry and geography

The Education Management industry absorbed the highest share of network-layer attack traffic at 92%. Information Technology and Services and Public Relations and Communications each saw about 73%, with Finance, Gaming/Gambling and Medical Practice following at roughly a third.

Grouped by customer billing country, Chinese internet properties behind Cloudflare saw 93% of their traffic classified as network-layer DDoS attack traffic. Lithuania followed at 87%, then Finland, Singapore and Taiwan.

Graph of the top countries targeted by network-layer DDoS attacks in 2022 Q4

Because source IPs can be spoofed at the network layer, Cloudflare instead uses the locations of its 275+ data centers where attack packets were ingested to infer origins. In Q4, over 52% of traffic ingested in the Botswana data center was attack traffic, followed by Azerbaijan at over 43%, then Paraguay, Palestine, Laos and Nepal. Note that ISP routing decisions — for example, hauling China-bound traffic through California — can skew these figures.

Bigger, longer, and still automated

The quarter’s pattern is consistent: attacks grew in both size and duration, while Ransom DDoS campaigns continued. Application-layer attacks during the holiday season concentrated on Aviation/Aerospace and Events Services, while network-layer attacks targeted Gaming/Gambling, Finance and Education Management. Among emerging threats, Memcached-based attacks led the growth.

DDoS defense requires automation. Attacks are executed by bots, and human-only response puts defenders at a disadvantage. Cloudflare’s mitigation systems detect and respond automatically, and the company has offered unmetered and unlimited DDoS protection to all customers since 2017. Responding to the lowered barrier for attackers requires keeping the barrier for defenders equally low.