DDoS Threat Report 2017 Q3

A significant rise in network time protocol (NTP) amplification attacks – 10 times more than the same period in last year.

  • The volume of NTP Amplification attacks rose some 425% over Q2, with the largest recorded size of 25Gbps and 7Mpps.
  • Overall, the number of attacks increased 15.6% compared to Q2.
  • UDP-based attacks jumped sharply (68.7%) over Q2, a finding consistent with the focus of last quarter’s threat report.
  • UDP-based Flood, NTP Amplification, and HTTP Flood were the three most common vectors, respectively constituting 21.6, 15.2, and 12.8% of total attack vectors in the quarter.
  • Multi-vector attacks were predominant with 54.7% of the total. The most popular multi-vectors combined two vectors, most notably UDP-Flood blended with NTP Amplification, TCP SYN Flood, and ICMP Flood.


The sharp rise in UDP-based attacks (3,069 in Q2 vs. 5,176 in Q3 — a 68.7% increase) contributed largely to the rise in total attacks. The upsurge was in line with the quarterly focus in our Q2 threat report. UDP-based attacks, including
NTP Amplification, SSDP Amplification, and DNS Amplification also showed upward trends, accounting for an increase of approximately 425.4, 353.6, and 101.0%, respectively, between Q2 and Q3.

