
10/11/2016 · Marek Majkowski
What this post added
This post details a significant shift in DDoS attack vectors, highlighting the emergence of large-scale attacks originating from IoT botnets, specifically mentioning the Mirai botnet and similar threats. It provides concrete data on two major L7 HTTP-based DDoS attacks, one peaking at 1.75 million requests per second and another generating 360Gbps of inbound traffic with large HTTP payloads. The post analyzes the geographical distribution of these attacks, the Autonomous Systems (AS) involved, and provides evidence suggesting the compromised devices are primarily IoT cameras and potentially NAS devices. It also discusses the evolution of DDoS mitigation strategies to counter these new L7 threats, including the deployment of a new system that recognizes and blocks these attacks across the network.