Q3 2020 Network-Layer DDoS Report: Attack Volume Quadruples

Network-layer distributed denial-of-service (DDoS) attacks surged dramatically in Q3 2020. After doubling between Q1 and Q2, the total number of L3/4 attacks observed on Cloudflare's network doubled again in Q3 — a fourfold increase compared to pre-COVID levels in the first quarter. The quarter also brought an unprecedented variety of attack vectors. While SYN, RST, and UDP floods remain dominant, protocol-specific attacks saw explosive growth, including mDNS, Memcached, and Jenkins DoS attacks.

Key findings from Q3 include:

  • Most attacks remain under 500 Mbps and 1 Mpps, yet these sizes are still sufficient to disrupt services
  • The majority of attacks continue to last under one hour
  • Ransom-driven DDoS (RDDoS) campaigns are increasing, with groups claiming to be Fancy Bear, Cozy Bear, and the Lazarus Group targeting organizations worldwide. The campaign remains ongoing.

Attack Frequency and Size Distribution

The total volume of L3/4 attacks continues to climb steadily. Q3 accounted for over 56% of all attacks observed this year — double the Q2 total and four times the Q1 total. Monthly attack counts increased progressively throughout the quarter.

Network-layer DDoS attack trends for Q3 2020 Embedded Image - piFY1k

September recorded the highest overall attack count, but August stood out for large-scale attacks (exceeding 500 Mbps). Ninety-one percent of all large attacks in Q3 occurred in August, while the monthly distribution of smaller attack sizes was much more balanced.

Network-layer DDoS attack trends for Q3 2020 Embedded Image - uuFkbw

Botnet-Driven Campaigns

Although the number of attacks in the 200-300 Gbps range declined in September, the overall number of global attacks on the network increased. This points toward a growing reliance on distributed botnets to launch attacks. In early July, Cloudflare mitigated one of the largest attacks ever observed on its network, generated by Moobot, a Mirai-based botnet. The attack peaked at 654 Gbps and originated from 18,705 unique IP addresses, each believed to be a Moobot-infected IoT device. The campaign lasted nearly 10 days, but the targeted customer remained protected with no reported downtime or service degradation.

Smaller floods dominate Q3 Layer 3/4 attack data

Layer 3/4 DDoS attacks can be measured in two primary ways: bit rate (Gbps), which aims to saturate an Internet link, and packet rate (pps), which targets routers and other inline hardware. The majority of attacks observed in Q3 were small by both metrics — over 87% fell below 1 Gbps, a notable jump from Q2 when roughly 52% of attacks were that small.

Network-layer DDoS attack trends for Q3 2020 Embedded Image - 7VTR8e

It's worth noting that even attacks under 500 Mbps can cause significant disruption for unprotected properties. Many organizations rely on ISP uplinks far below 1 Gbps, and when those same links carry legitimate traffic, even a "small" flood can take a site down. Packet rates tell a similar story: 47% of attacks in Q3 were under 50k pps, compared to just 19% in Q2.

Network-layer DDoS attack trends for Q3 2020 Embedded Image - zwmp8c

This prevalence of smaller attacks could point to amateur attackers using easily accessible tools against exposed IPs and networks. Alternatively, small attacks may act as a distraction, drawing security teams' attention away from other simultaneous cyberattacks.

Short bursts remain the norm

Network-layer DDoS attack trends for Q3 2020 Embedded Image - Irbhp3

Short attacks dominated Q3, accounting for nearly 88% of all attacks. This continues the trend seen in prior reports: Layer 3/4 DDoS attacks are getting shorter. Brief bursts can evade detection systems, particularly those relying on manual analysis — by the time an analyst identifies the traffic, the attack is over.

Short attacks also serve as reconnaissance. Widely available load-testing and automated DDoS tools on the dark web can fire a quick SYN flood, then follow up with a different vector. This lets attackers probe a target's defenses before committing to larger, more expensive attacks. In other cases, small attacks are used as a proof-of-capability warning, often followed by a ransom demand threatening a more crippling attack if payment isn't made.

Regardless of motivation, DDoS attacks of any size or duration remain a persistent threat. Automated, real-time defense is essential for online businesses, as even brief attacks can cause real harm.

Vector mix: TCP still leads, UDP on the rise

SYN floods made up nearly 65% of all attacks in Q3, followed by RST floods and UDP floods. TCP-based vectors remain the top choice, consistent with previous quarters. However, UDP-specific protocols like mDNS, Memcached, and Jenkins saw a dramatic surge compared to the prior quarter.

Network-layer DDoS attack trends for Q3 2020 Embedded Image - JRIOvF
Network-layer DDoS attack trends for Q3 2020 Embedded Image - XfFzLD

mDNS (Multicast DNS), a UDP-based protocol for local network service discovery, is being exploited through spoofed unicast queries from outside the local network, creating amplification attacks. Q3 saw a 2,680% increase in mDNS attacks compared to Q2. Memcached attacks exploit UDP requests with spoofed source addresses, with the amplification factor tied to stored values. Jenkins attacks leverage a vulnerability in version 2.218 and earlier (CVE-2020-2100), fixed in 2.219 by disabling UDP multicast/broadcast by default — yet many vulnerable devices remain exposed. NTP, Ubiquity, and other UDP protocols also saw increases due to UDP's stateless nature.

Geographic distribution

Network-layer DDoS attack trends for Q3 2020 Embedded Image - HgDIld
Network-layer DDoS attack trends for Q3 2020 Embedded Image - JVmBHw

The United States saw the most Layer 3/4 DDoS attacks, followed by Germany and Australia. Attack data is bucketed by the Cloudflare edge data center where traffic was ingested, not by source IP — source addresses are frequently spoofed, making geographic attribution unreliable. With data centers in over 200 cities, Cloudflare can display attack data by ingestion location for accurate geography.

Network-layer DDoS attack trends for Q3 2020 Embedded Image - Dc8jdw
Network-layer DDoS attack trends for Q3 2020 Embedded Image - zE239n
Network-layer DDoS attack trends for Q3 2020 Embedded Image - opoHuA
Network-layer DDoS attack trends for Q3 2020 Embedded Image - 1TP1KM
Network-layer DDoS attack trends for Q3 2020 Embedded Image - TtLIrI
Network-layer DDoS attack trends for Q3 2020 Embedded Image - nvNK3M
Network-layer DDoS attack trends for Q3 2020 Embedded Image - L11qL4

Ransom-driven DDoS gains ground

A disturbing trend has emerged in recent months: extortion and ransom-based DDoS (RDDoS) attacks targeting organizations globally. While threats don't always translate into attacks, recent cases show attacker groups following through with large-scale DDoS attacks capable of overwhelming unprotected organizations. Even the initial "teaser" attack can cause impact without cloud-based DDoS protection.

Groups claiming to be Fancy Bear, Cozy Bear, and Lazarus have threatened DDoS attacks against websites and infrastructure unless ransoms are paid by deadlines. These threats are typically accompanied by a demonstration attack — usually a UDP reflection attack using various protocols, lasting roughly 30 minutes or less.

If you receive a threat:

  1. Do not pay the ransom: Payment encourages bad actors and funds illegal activity, with no guarantee against future attacks.
  2. Notify local law enforcement: They will likely request a copy of the ransom letter.
  3. Contact Cloudflare: Assistance is available to safeguard websites and network infrastructure.

Why always-on mitigation is needed

On-premises hardware and cloud-scrubbing centers struggle with modern volumetric DDoS attacks. Appliances get overwhelmed, Internet links saturate, and rerouting to scrubbing centers adds latency. Cloudflare's cloud-native, always-on, automated DDoS protection avoids these issues entirely, stemming from the 2017 decision to offer unmetered DDoS mitigation across all plans, including the free tier. Every server in the network can detect and block threats, absorbing attacks of any size without latency impact.

Key advantages include:

  • 51 Tbps of DDoS mitigation capacity and under 3-second TTM: Each data center detects and mitigates attacks locally via the dosd system. A dynamically crafted rule with real-time signature is generated and applied in under 3 seconds on average — one of the fastest in the industry. Firewall rules and static configurations take effect immediately.
  • No latency penalty: Mitigation happens at every data center, closest to the attack source, rather than at legacy scrubbing centers. Traffic is analyzed out-of-path, ensuring no added latency for legitimate requests. Rules are applied at the most efficient point in the Linux stack.
  • Global threat intelligence: Attacks against any single customer inform protections for all. Threat intelligence powers automated blocking and customer-facing features like Bot Fight mode, Firewall Rules, and Security Level, using ML-generated threat and bot scores.