Cloudflare Q1 2024 DDoS Report: Attack Volumes Up 50% Year Over Year

Cloudflare's automated defenses mitigated 4.5 million DDoS attacks during the first quarter of 2024, a 50% increase compared to the same period last year. That figure already represents roughly a third of all attacks the company mitigated throughout all of 2023.

The growth was broad-based across both major attack categories. HTTP-based DDoS attacks rose 93% year over year and 51% quarter over quarter, while network-layer (L3/4) attacks increased 28% year over year and 5% sequentially. Combined, the two categories pushed total mitigated attack traffic to 10.5 trillion HTTP requests and more than 59 petabytes of network-layer attack traffic during the quarter.

BLOG-2367 Embedded Image - LoMBy9

Mirai Variant Delivers 2 Tbps Attack

Several network-layer attacks during Q1 exceeded 1 terabit per second, occurring on an almost weekly basis. The largest attack of the quarter peaked at 2 Tbps and targeted a Magic Transit customer, an Asian hosting provider. Cloudflare attributed the attack to a Mirai-variant botnet and said its systems detected and mitigated it automatically.

Mirai botnet targets Asian hosting provider with 2 Tbps DDoS attack

The original Mirai botnet, built from compromised IoT devices and made infamous by its 2016 attack on DNS infrastructure in the US, remains a persistent threat. Since the source code was publicly released, numerous variants have emerged. Today, Mirai variants account for roughly four out of every 100 HTTP DDoS attacks and two out of every 100 L3/4 attacks.

DNS Attacks Grow Into the Top Vector

DNS-based DDoS attacks were the most prominent network-layer attack vector in Q1, growing their share by 80% year over year to approximately 54% of all L3/4 attacks. The increase comes as Cloudflare launched its Advanced DNS Protection system in March, designed to defend against sophisticated DNS-based DDoS attacks.

DNS-based DDoS attacks by year and quarter

Despite the sharp rise in DNS attacks, the overall attack-type distribution across all DDoS attacks remained stable compared to Q4 2023. HTTP DDoS attacks held at 37% of all attacks, DNS DDoS attacks at 33%, and all other L3/4 categories—including SYN Floods and UDP Floods—made up the remaining 30%.

Attack type distribution

Within the L3/4 layer, SYN Floods were the second most common vector, followed by RST Floods and then UDP Floods with a 6% share.

Jenkins Flood Exploit Sees Massive Growth

Among emerging threats, the Jenkins Flood attack vector experienced the largest quarter-over-quarter growth at over 826%. This attack exploits a 2020 vulnerability (CVE-2020-2100) in the Jenkins automation server's UDP multicast, broadcast, and DNS multicast services. Attackers send small crafted requests to a publicly exposed UDP port, triggering disproportionately large responses that can overwhelm the target. Although Jenkins disabled these services by default in later versions, the vulnerability remains actively abused four years later.

Attack vectors that experienced the largest growth QoQ

HTTP/2 Continuation Flood Vulnerability Detailed

Cloudflare also highlighted a newly disclosed HTTP/2 vulnerability. The HTTP/2 Continuation Flood, reported publicly by researcher Bartek Nowotarski on April 3, 2024, targets HTTP/2 implementations that mishandle HEADERS and CONTINUATION frames. By sending a sequence of CONTINUATION frames without the END_HEADERS flag, an attacker can trigger out-of-memory crashes or CPU exhaustion on vulnerable servers. Notably, the attack can be launched from a single machine and leaves no visible trace in HTTP access logs, making detection difficult.

Cloudflare sees this as potentially more damaging than the HTTP/2 Rapid Reset vulnerability that fueled the massive attack campaign in Q3 2023. During that campaign, Cloudflare recorded attack rates averaging 30 million requests per second, with roughly 89 attacks peaking above 100 million rps and the largest reaching 201 million rps.

HTTP/2 Rapid Reset campaign of hyper-volumetric DDoS attacks in 2023 Q3

Cloudflare's own HTTP/2 implementation, network, and WAF/CDN customers are not affected by the Continuation Flood vulnerability, and the company stated it is not currently aware of any exploitation in the wild. Multiple CVEs have been assigned to impacted HTTP/2 implementations across various vendors.

Gaming and Gambling Lead Global Attack Targets

Globally, the Gaming and Gambling industry was the top target of HTTP DDoS attacks, absorbing just over seven of every 100 DDoS requests Cloudflare mitigated. The Information Technology and Internet industry ranked second, followed by Marketing and Advertising in third.

Top attacked industries by HTTP DDoS attacks

Regional patterns for HTTP DDoS attacks varied considerably. Marketing and Advertising led in North America, Information Technology and Internet topped the list in Africa and Europe, Computer Software was most targeted in the Middle East, Gaming and Gambling led in Asia, BFSI (Banking, Financial Services and Insurance) was most attacked in South America, and Telecommunications led in Oceania.

Top attacked industries by HTTP DDoS attacks, by region

At the network layer, the Information Technology and Internet industry was overwhelmingly the top target, capturing 75% of all L3/4 DDoS attack bytes. Cloudflare noted this may reflect "super aggregator" companies receiving attacks actually aimed at their end customers. Telecommunications, BFSI, Gaming and Gambling, and Computer Software followed.

Top attacked industries by L3/4 DDoS attacks

Normalized Data Reveals Different Targets

When attack traffic is measured as a share of total traffic received, an entirely different set of industries emerges. On the HTTP side, Law Firms and Legal Services were most heavily attacked, with over 40% of their traffic being DDoS attack traffic. Biotechnology ranked second at 20%, followed by Nonprofits at 13%. Aviation and Aerospace, Transportation, Wholesale, Government Relations, Motion Pictures and Film, Public Policy, and Adult Entertainment rounded out the top ten.

Top attacked industries by HTTP DDoS attacks (normalized)

For network-layer attacks, the normalized view shows Information Technology and Internet still topping the list, with nearly a third of its traffic classified as attacks—likely reflecting the aggregator effect. Textiles ranked second at 4%, followed by Civil Engineering, BFSI, Military, Construction, Medical Devices, Defense and Space, Gaming and Gambling, and Retail.

Top attacked industries by L3/4 DDoS attacks (normalized)

Top Attack Sources

The United States was the largest source of HTTP DDoS attack traffic in Q1, with a fifth of all attack requests originating from US IP addresses. China followed in second, with Germany, Indonesia, Brazil, Russia, Iran, Singapore, India, and Argentina making up the rest of the top ten.

The top sources of HTTP DDoS attacks

Because network-layer source IP addresses can be spoofed, Cloudflare instead uses its data center locations—spanning over 310 cities—to geographically attribute L3/4 attacks. Using this method, over 40% of network-layer attack traffic was ingested at US data centers. Germany was a distant second at 6%, followed by Brazil, Singapore, Russia, South Korea, Hong Kong, the United Kingdom, Netherlands, and Japan.

The top sources of L3/4 DDoS attacks

Normalized Source Rankings Shift

When accounting for total traffic volume, the source picture changes substantially. Almost a third of all HTTP traffic originating from Gibraltar was DDoS attack traffic, making it the largest normalized source. Saint Helena, the British Virgin Islands, Libya, Paraguay, Mayotte, Equatorial Guinea, Argentina, and Angola followed.

The top sources of HTTP DDoS attacks (normalized)

At the network layer, Zimbabwe-based data centers saw nearly 89% of ingested traffic classified as L3/4 DDoS attacks. Paraguay followed at over 56%, with Mongolia approaching 35%. Moldova, the Democratic Republic of the Congo, Ecuador, Djibouti, Azerbaijan, Haiti, and the Dominican Republic also ranked high on the normalized list.

The top sources of L3/4 DDoS attacks (normalized)

Most Attacked Locations

By customer billing country, the US was the most attacked location by HTTP DDoS attacks, absorbing one out of every 10 mitigated requests. China ranked second, followed by Canada, Vietnam, Indonesia, Singapore, Hong Kong, Taiwan, Cyprus, and Germany.

Top attacked countries and regions by HTTP DDoS attacks

On a normalized basis, Nicaragua was the most attacked, with over 63% of its HTTP traffic consisting of DDoS attacks. Albania, Jordan, Guinea, San Marino, Georgia, Indonesia, Cambodia, Bangladesh, and Afghanistan completed the top ten.

Top attacked countries and regions by HTTP DDoS attacks (normalized)

At the network layer, China was the dominant target, with 39% of all mitigated L3/4 DDoS bytes aimed at Chinese customers. Hong Kong, Taiwan, the United States, and Brazil followed.

Top attacked countries and regions by L3/4 DDoS attacks

The normalized network-layer data shows Hong Kong as the most heavily targeted location, with L3/4 DDoS traffic accounting for over 78% of all Hong Kong-bound traffic. China followed at 75%, ahead of Kazakhstan, Thailand, Saint Vincent and the Grenadines, Norway, Taiwan, Turkey, Singapore, and Brazil.

Top attacked countries and regions by L3/4 DDoS attacks (normalized)

Attack Duration and Intensity

DDoS attacks continue to vary widely in duration and intensity. Four out of every 10 HTTP DDoS attacks lasted over 10 minutes, with approximately three out of 10 extending beyond an hour. On the intensity side, one out of every 10 attacks exceeded 100,000 requests per second, and attacks above one million requests per second appeared in roughly four out of every 1,000 cases.

Cloudflare attributed its ability to absorb these attacks to its automated defense systems and its policy, in place since 2017, of providing unmetered DDoS protection to all customers at no additional cost.