The Shape of DDoS in 2023: Cloudflare's Q4 Review
Cloudflare’s latest DDoS report covers the final quarter of 2023 and sets it against a full year of attack trends. As always, the numbers come from Cloudflare’s automated mitigation systems, which defend its entire network.
DDoS attacks generally fall into three categories. HTTP request-intensive attacks overwhelm application servers. IP packet-intensive attacks target network appliances like routers and firewalls. Bit-intensive attacks saturate the internet link itself. The report covers insights into all three types.
Hyper-Volumetric Attacks and the HTTP/2 Exploit
2023 was defined by a persistent, deliberate campaign of hyper-volumetric DDoS attacks at unprecedented scale. These exploited a vulnerability in the HTTP/2 protocol. Cloudflare built purpose-built technology to mitigate the effect and worked with industry peers to responsibly disclose the flaw.
The largest attack Cloudflare mitigated in 2023 peaked at 201 million requests per second (rps), nearly eight times the previous 2022 record of 26 million rps. After this campaign subsided, HTTP DDoS activity dropped unexpectedly.

A Split in Attack Trends
Over the entire 2023, Cloudflare's automated defenses mitigated more than 5.2 million HTTP DDoS attacks, which consisted of over 26 trillion requests. That averages out to 594 HTTP DDoS attacks and 3 billion mitigated requests every hour. Yet HTTP DDoS attack requests declined 20% compared to 2022. Q4 alone saw a 7% YoY decrease and an 18% QoQ decrease in the number of HTTP DDoS attack requests.
Network-layer trends headed in the opposite direction. Cloudflare mitigated 8.7 million network-layer DDoS attacks in 2023 — an 85% increase over 2022. In Q4 specifically, automated systems mitigated over 80 petabytes of network-layer attacks, averaging 996 attacks and 27 terabytes every hour. The number of these attacks was up 175% YoY and 25% QoQ.

Environmental Services Under Fire at COP 28
The biggest shift in Q4 attack targets happened in Environmental Services. While the Cryptocurrency sector initially led in the volume of HTTP DDoS attack requests, Environmental Services websites became the primary victim as the quarter progressed. These attacks made up half of all HTTP traffic to these sites.
This represented a staggering 618-fold increase in HTTP DDoS traffic directed at Environmental Services websites compared to the previous year. The surge coincided with the 28th United Nations Climate Change Conference (COP 28), which ran from November 30th to December 12th, 2023. The pattern wasn't unique to this event. Similar spikes were observed around COP 26 and COP 27, and other UN environmental announcements — including the UN resolution on climate justice and the launch of the UN Environment Programme’s Freshwater Challenge in early 2023 — each of which saw a corresponding bump in attacks on Environmental Services sites.
Cyber Attacks in the Israel-Hamas Conflict
Armed conflict continues to trigger DDoS activity. Following Operation “Iron Swords,” the Israeli military operation launched after the Hamas-led attack on 7 October, DDoS attacks targeted both sides of the conflict throughout Q4.
The Palestinian territories saw a massive spike. Relative to regional traffic, it was the second most attacked region by HTTP DDoS attacks. Over 10% of all HTTP requests towards Palestinian websites were DDoS attacks — a total of 1.3 billion requests — representing a 1,126% increase quarter-over-quarter. The targets were highly concentrated: 90% of these DDoS attacks targeted Palestinian Banking websites, with another 8% aimed at Information Technology and Internet platforms.

Cloudflare also mitigated over 2.2 billion HTTP DDoS requests targeting Israeli websites. While lower than the prior quarter and previous year in absolute volume, this figure represented a larger percentage of all Israel-bound traffic — a 27% increase QoQ but a 92% decrease YoY when normalized. The primary targets were Newspaper & Media sites, receiving nearly 40% of all Israel-bound HTTP DDoS attacks, followed by Computer Software and the Banking/Financial Services industry.

At the network layer, the impact on Palestinian networks was even more dramatic. Palestinian networks were targeted with 470 terabytes of attack traffic, which accounted for over 68% of all traffic toward them. This placed the Palestinian territories as the second most attacked region globally, normalized against its own traffic — surpassed only by China. By absolute volume, it ranked third globally, with those 470 terabytes representing approximately 1% of all DDoS traffic Cloudflare mitigated.
Israeli networks saw 2.4 terabytes of attack traffic, making it the 8th most attacked country when normalized. This represented almost 10% of all traffic toward Israeli networks.
The geographic emphasis was also visible inside Cloudflare's infrastructure. In Israeli data centers, 3% of all ingested bytes were network-layer DDoS attacks; in Palestinian data centers, that figure jumped to approximately 17%. On the application layer, 4% of HTTP requests originating from Palestinian IPs were DDoS attacks, and roughly 2% of those from Israeli IPs were too.
Who Is Sending the Attacks?
Since Q4 2022, the United States has been the largest source of HTTP DDoS attack traffic, holding that position for five consecutive quarters after displacing China. US data centers also ingest the most network-layer DDoS attack traffic — over 38% of all attack bytes. Together, China and the US account for a little over a quarter of all global HTTP DDoS traffic.

Viewing attack sources relative to a country’s own outbound traffic tells a different story — one dominated by smaller markets. In Q4, 40% of Saint Helena’s outbound traffic was HTTP DDoS attacks, placing it at the top. Libya came in second, followed by Swaziland, Argentina, and Egypt.

On the network layer, Zimbabwe came in first, with almost 80% of all traffic in Cloudflare's Zimbabwe-based data center classified as malicious. Paraguay followed, with Madagascar in third place.

Q4’s most-targeted industries
By raw HTTP attack traffic, Cryptocurrency was the top target in Q4, absorbing over 330 billion requests — more than 4% of all HTTP DDoS traffic for the quarter. Gaming & Gambling ranked second, continuing its history as a frequent target.

At the network layer, the Information Technology and Internet industry was hit hardest, accounting for over 45% of all network-layer DDoS attack traffic. Banking, Financial Services and Insurance (BFSI), Gaming & Gambling, and Telecommunications followed at a distance.

Normalizing attack traffic against each industry’s own total traffic tells a different story. Environmental Services was the most attacked relative to its size, with Packaging and Freight Delivery in second — a pattern that tracks with the shopping surge around Black Friday and the winter holidays. Retail DDoS attacks were also up 16% year-over-year.

On the network layer, Public Relations and Communications saw 36% of its traffic classified as malicious, the highest of any industry. The timing is telling: with end-of-year reporting and holiday communications in full swing, disruption in that sector can have immediate reputational fallout.

Geographic targets: a shifting map
Singapore was the primary HTTP DDoS target in Q4, with over 317 billion requests — 4% of all global HTTP DDoS traffic — aimed at its websites. The US placed second, Canada third, and Taiwan fourth, the latter amid its general elections and ongoing tensions with China. Taiwan-bound attack traffic surged 847% year-over-year and 2,858% quarter-over-quarter. Normalized against total Taiwan-bound traffic, the share of attacks grew 624% QoQ and 3,370% YoY.

China, while ninth in HTTP attacks, was the clear leader in network-layer targets, with 45% of all network-layer DDoS traffic Cloudflare mitigated going to the country. Other nations lagged far behind.

After normalizing by total inbound traffic, Iraq, the Palestinian territories, and Morocco lead the HTTP rankings, with Singapore fourth — meaning it faced both the largest raw volume and a disproportionate share of malicious traffic. The US, by contrast, fell to 50th place on that normalized scale.

China’s dominance is even more dramatic at the network layer: nearly 86% of all China-bound traffic was mitigated as DDoS. The Palestinian territories, Brazil, Norway, and Singapore followed in the normalized rankings.

Attack sizes and standout events
Most DDoS attacks remain short and small — 91% ended within 10 minutes, 97% peaked below 500 Mbps, and 88% stayed under 50 Kpps. Only 2% exceeded one hour and 1 Gbps, and just 1% surpassed 1 million pps. Still, the number of attacks exceeding 100 million pps rose 15% QoQ.

Q4’s largest network-layer attack was a Mirai-botnet assault peaking at 1.9 Tbps and 160 million pps, aimed at a known European cloud provider. While the pps rate didn’t surpass the record 754 million pps attack from 2020, the bit rate was notable. The attack was multi-vector — including UDP fragments flood, UDP/Echo flood, SYN Flood, ACK Flood, and TCP malformed flags — and originated from over 18,000 assumed spoofed IPs. Cloudflare’s automated defenses detected and mitigated it.

Mirai-variant botnets remain a common tool, behind nearly 3% of attacks. DNS-based methods are the most favored overall: DNS Floods and DNS Amplification together made up almost 53% of all Q4 attacks, with SYN Flood second and UDP floods third.
DNS floods vs. DNS amplification
DNS floods and amplification attacks both exploit the Domain Name System, but in different ways. A DNS flood overwhelms a DNS server with a torrent of queries from a botnet, leaving it unable to respond to legitimate requests. A DNS amplification attack sends small queries with a spoofed victim IP to open DNS resolvers; the large responses are then redirected at the victim, amplifying traffic volume and potentially congesting entire networks. Both exploit DNS’s central role, with mitigation typically involving server hardening, rate limiting, and malicious traffic filtering.

Rising attack vectors
Among emerging threats, ACK-RST Floods jumped 1,161% quarter-over-quarter, CLDAP floods rose 515%, and SPSS floods grew 243%.

ACK-RST floods abuse TCP by sending a flood of ACK and RST packets, forcing the victim to consume resources on every response. Because they mimic legitimate traffic, they are difficult to filter.
CLDAP floods leverage the connectionless, UDP-based CLDAP protocol. With no handshake required, attackers spoof the source IP and use open servers to reflect amplified response traffic at the victim.
SPSS floods send packets from many random or spoofed source ports to various destination ports. This overwhelms the target’s processing capacity and can also serve as a scan for open ports and vulnerable services, exhausting firewalls and intrusion detection systems.
Defense at scale: how Cloudflare positions itself for the next wave
Cloudflare frames its DDoS mitigation as an always-on, network-level capability rather than a product toggle. Since introducing unmetered mitigation in 2017, the company has extended its protection across all plan tiers—including the free tier—and says this posture is sustainable because of its autonomous detection systems and distributed network architecture.
That granular, always-on approach is paired with what Cloudflare describes as complementary layers in the security stack. The bundled features include a web application firewall (Cloudflare WAF), bot management, API endpoint protection, and edge caching. The intent, per the company, is to expand the attack surface beyond request-volume filtering into a broader posture that reduces the impact of a volumetric event should filtering be bypassed.
Operational response and best practices
Cloudflare emphasizes that protection is a process rather than a single configuration change. It advises customers to:
- Review the firm's security center guidance on responding to DDoS events.
- Walk through the available application security and DDoS prevention learning paths to tune WAF rules, rate limits, and bot protection.
- Keep detection systems running continuously—even during quiet periods—to catch low-and-slow cases that don't trigger threshold alerts.
In the event of an active attack, Cloudflare directs users to its cyber emergency hotline for rapid response. Onboarding and mitigation remain available on the free plan, consistent with the unmetered philosophy introduced seven years ago.



