Network-layer DDoS patterns in the fourth quarter of 2020 broke with several norms seen earlier in the year. For the first time in 2020, Cloudflare observed a rise in the number of large attacks—specifically, those exceeding 500Mbps and 50K pps. Attack vectors also shifted, with protocol-based attacks increasing 3-10x from the prior quarter. Attackers showed greater persistence, as nearly 9% of all attacks in October through December lasted more than 24 hours.

Key observations from Q4 2020 include:

  • Attack volume: Total network-layer attacks declined for the first time in 2020, dropping to 15% of the year's attacks versus Q3's 48%.
  • Duration: 73% of attacks lasted under one hour, a decline from 88% in Q3.
  • Vectors: SYN, ACK, and RST floods remained dominant, but NetBIOS-based attacks surged 5400%, followed by ISAKMP and SPSS.
  • Geographic hotspots: Cloudflare data centers in Mauritius, Romania, and Brunei recorded the highest share of attack traffic relative to non-attack traffic.
  • Ransom DDoS (RDDoS): Extortion campaigns continued to target organizations globally, with attackers demanding Bitcoin payments under threat of network downtime.

Attack Volume Declines, But Large Attacks Multiply

Q4 marked the first quarterly drop in total network-layer DDoS attacks for 2020. The quarter accounted for just 15% of all attacks observed during the year, compared with 48% in Q3. In fact, the total number of attacks in Q4 was 60% lower than the count seen in September alone. December was the busiest month of the quarter.

While the majority of attacks remained small—under 1 Gbps and 1M pps—the share of larger attacks grew. Attacks over 500Mbps and 50K pps made up a bigger percentage of the total than in prior quarters. Notably, attacks exceeding 100 Gbps increased 10x from Q3, and those over 10M pps rose 3.6x.

Most small attacks are likely launched by amateur attackers using low-cost, easy-to-use tools. They may also serve as decoys to distract security teams or as tests of network defenses. The uptick in bigger attacks, however, signals more brazen attackers wielding more powerful tools—with consequences that can extend beyond the immediate target to downstream service providers.

The "Beat" Attack: An Acoustics-Inspired Method

One distinctive large attack Cloudflare auto-mitigated was an ACK flood that ran for over 19 hours. Its packet rate followed a wave-shaped pattern, suggesting the attacker drew from the acoustics concept of a "beat"—the interference pattern created by two differing wave frequencies. Cloudflare codenamed the assault "Beat" and detailed it in a separate post.

Attacks Last Longer

Attack duration shifted significantly in Q4. While 73% of attacks ended within an hour—down from 88% in Q3—the proportion of long-lasting assaults grew. Nearly 9% of attacks continued for more than 24 hours, versus just 1.5% in the previous quarter. This trend underscores the need for always-on, real-time mitigation systems capable of handling attacks of any size and duration.

Shifting Attack Vectors

SYN floods remained the most common vector, accounting for roughly 42% of attacks. In a notable shift, ACK floods jumped from ninth place in Q3 to second, a 13x quarter-over-quarter increase, displacing RST floods. TCP-based vectors such as SYN and RST persisted, but UDP-protocol-specific attacks exploded: NetBIOS and ISAKMP-based assaults grew dramatically compared to the prior quarter.

NetBIOS enables application communication and shared resource access over a LAN, while ISAKMP is used to establish Security Associations and cryptographic keys in IPsec VPN setups via the Internet Key Exchange (IKE) protocol. Cloudflare continues to observe both protocol-specific and multi-vector attacks aimed at taking networks offline, making robust, adaptive DDoS protection increasingly critical.

Global Hotspots and Regional Breakdowns

To gauge geographic attack origins, Cloudflare analyzes traffic at its edge data centers rather than source IPs, since IP spoofing is common in L3/4 attacks. The company measures attack traffic relative to non-attack traffic at each facility to improve accuracy, leveraging a network spanning 200+ cities across 100+ countries.

In Q4, data centers in Mauritius, Romania, and Brunei logged the highest attack-to-benign ratios, with DDoS traffic comprising 4.4-4.9% of all bytes—meaning roughly 5 out of every 100 bytes were attack-related. This points to increased botnet activity in those regions.

Possible explanations vary by country. Mauritius experienced significant political unrest following an August oil spill and subsequent anti-government protests, which continued into the quarter alongside accusations of media suppression. Romania, meanwhile, held parliamentary elections in early December and was selected to host the European Cybersecurity Industrial, Technology and Research Competence Centre (ECCC). Additionally, Romania boasts some of the world's cheapest high-speed broadband, potentially lowering the barrier for launching volumetric attacks.

Regional DDoS activity during Q4 is broken down by continent and, for the United States, by state in the following charts.

Ransom DDoS Campaigns Persist

Extortion-based DDoS (RDDoS) attacks continued to plague organizations in Q4, building on a trend first highlighted in the Q3 report. In these schemes, attackers threaten to knock networks, websites, or applications offline unless a ransom is paid. Cloudflare assisted numerous organizations of varying sizes that received ransom notes, including a Fortune Global 500 company. The firm continues to monitor the trend closely.

For organizations that receive a ransom threat, Cloudflare recommends:

  1. Do not pay the ransom. Paying encourages criminal activity and offers no guarantee against future attacks.
  2. Notify local law enforcement. Authorities may request a copy of the ransom letter.
  3. Contact Cloudflare. The company can help secure websites and network infrastructure against such attacks.

How Cloudflare Approaches Network-Layer DDoS Defense

Cloudflare positions its DDoS protection as a comprehensive L3-L7 solution, anchored in an architectural bet against the traditional scrubbing center model. The company eliminated surge pricing for DDoS attacks back in 2017, offering unmetered and unlimited mitigation, a move that has since attracted a wide range of enterprise customers, including Wikimedia, Panasonic, and Discord.

Three core principles underpin this approach:

Edge-Based Mitigation, Not Scrubbing Centers

Cloudflare argues that scrubbing centers represent a fundamentally flawed defense mechanism. Their primary weakness is the asymmetric nature of attacks; a single scrubbing facility will always be outgunned by the bandwidth available to attackers. Additionally, routing traffic to these centers introduces unnecessary latency and incurs high operational costs.

Instead, Cloudflare's network is built so that every machine across every data center is capable of performing inline DDoS mitigation. This Anycast-based architecture means the network's total capacity directly equals its scrubbing capacity—currently stated at 51 Tbps. By detecting and stopping attacks at the edge, close to the source, Cloudflare aims to mitigate at scale without compromising performance. The distributed nature of this model also feeds a global threat-intelligence loop, where machine learning models learn from attacks on any single customer to protect the entire network.

Latency and Time-to-Mitigation

For enterprises migrating from on-prem infrastructure, a common hurdle to cloud adoption is the latency introduced by security services. Traditional cloud-based DDoS providers rely on routing traffic to specialized data centers, which can add significant delay based on the physical distance between the user, the destination server, and the scrubbing site. The problem is compounded for organizations using multiple providers for different network functions, as traffic hops can push latency into the hundreds of milliseconds.

Cloudflare's widely distributed network is designed to avoid this backhauling problem. The company states that its global presence allows for attacks to be detected and mitigated in an average of under three seconds, positioning it as one of the fastest mitigation timelines available.

Beyond Attack Mitigation

DDoS defense is increasingly viewed as just one component of a broader security posture. As organizations adopt Zero Trust frameworks, they encounter threats related to network access and a rising volume of sophisticated bot-related attacks. Cloudflare emphasizes that its security products are designed for integration, with its Cloudflare One solution serving as a Zero Trust offering that unifies device, data, and application protection with the broader platform's existing security and DDoS capabilities.