New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home Cybersecurity

Malicious web application requests skyrocketing, bad actors stealthier than ever before

New York Tech Editorial Team by New York Tech Editorial Team
March 15, 2022
in Cybersecurity
0
API attacks are both underdetected and underreported
Share on FacebookShare on Twitter

Radware released report findings which underscore 2021 as the year of the web application attack. Between 2020 and 2021, the number of malicious web application requests climbed 88%, more than double the year-over-year growth rate in distributed denial-of-service (DDoS) attacks, which were up 37% over 2020.

malicious web application requests

The unprecedented increase in web application attacks did not, however, prevent DDoS from making a name for itself in 2021. The report details how last year saw multiple record-breaking DDoS attacks and ransom denial-of-service (RDoS) earn its place in the threat landscape. At the same time that big attacks were making headlines, the volume of micro floods, attacks which often go undetected, rose nearly 80% compared to 2020.

“The statistics tell a story about bad actors. They are getting smarter, more organized, and more targeted in pursuing their objectives — whether that be for money, fame, or a political cause,” said Pascal Geenens, director of threat intelligence for Radware.

“In addition, cybercriminals are shifting their attack patterns — from leveraging larger attack vectors to combining multiple vectors in more complex-to-mitigate campaigns. Ransomware operators and their affiliates, which now include DDoS-for-hire actors, are working with a whole new level of professionalism and discipline — something that we have not seen before.”

The report reviews the most important cybersecurity events in 2021 and provides detailed insights into DDoS and web application attack developments as well as unsolicited network scanning trends.

Key takeaways

  • Cloud-scale DDoS attacks are in the forecast: As more businesses migrate critical resources and applications to the public cloud, attackers are adapting their tactics and techniques to match the scale of public cloud providers. While enterprises should not be immediately alarmed by reports of huge attacks, they do need to be aware that DDoS attacks are a part of their threat landscape, irrespective of their geography or industry. Companies hosting services in the public cloud need to be prepared for cloud-scale attacks.
  • Ransom DoS (RDoS) gangs take charge: In 2020, there was an uptick in DDoS attacks against organizations that did not pay a ransom demand on time. In 2021, RDoS confirmed its pervasive presence in the DDoS threat landscape with several campaigns. This included attacks targeting VoIP providers worldwide, which sparked concern for critical infrastructure.
  • Ransomware operators turn to triple extortion: In 2021, more sophisticated and better organized operators advanced their tactics, adding more extortion capabilities to their arsenal. To bring reluctant victims back to the negotiating table, they launched triple extortion campaigns by combining not only cryptolocking and data leaks, but also DDoS attacks. As a result, the flourishing underground economy supported by ransomware operators is seeing a new demand for DDoS-for-hire services.
  • Micro floods make a big showing: While the number of large attack vectors (above 10Gbps) declined 5% between 2020 and 2021, micro floods (less than 1Gbps) and application-level attacks rose nearly 80% higher. By shrewdly combining a large number of micro floods over longer periods of time, attackers put organizations at greater risk of having to constantly increase infrastructure resources, such as bandwidth, and network and server processing, until the service can become cost prohibitive.

DDoS attacks

In 2021, the number of malicious DDoS events increased by 37% per customer compared to 2020. Europe, the Middle East, and Africa (EMEA) and the Americas each accounted for 40% of the attack volume in 2021, while the Asia Pacific region accounted for 20%.

Average 2021 DDoS attack volumes per customer grew by 26% in 2021 compared to 2020.

The top attacked industries in 2021 were gaming and retail, each accounting for 22% of the attack volume on a normalized basis. These two industries were followed by the government (13%), healthcare (12%), technology (9%), and finance (6%).

Web application attacks

The number of malicious web application requests grew 88% from 2020 to 2021. Broken access control and injection attacks represented more than 75% of web application attacks.

The most attacked industries in 2021 were banking and finance, along with SaaS providers, together accounting for more than 28% of web application attacks. Retail and high-tech industries ranked third and fourth, each with almost 12% of the web security events, followed by manufacturing (9%), government (6%), carriers (6%), and transportation (5%).

Credit: Source link

Previous Post

Top threats for the financial sector

Next Post

The massive impact of vulnerabilities in critical infrastructure

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
The massive impact of vulnerabilities in critical infrastructure

The massive impact of vulnerabilities in critical infrastructure

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
10 Raunchy Movies on Netflix You Won’t Regret Watching

10 Raunchy Movies on Netflix You Won’t Regret Watching

May 20, 2024
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
laptop on glass table

Automat-it Cuts Deployment Friction as Monce Scales AI Order Processing on AWS

April 13, 2026
Lee's Famous Recipe Chicken

Why Lee’s Famous Recipe Chicken Is Betting on Hi Auto to Quietly Rewire the Drive-Thru

April 9, 2026
computer generated image of letters

San Francisco Tribune Lists 11 HumanX Startups Moving AI Closer to the Operating Core

April 8, 2026
Impala CEO and Highrise AI CEO

The Industrialization of AI Infrastructure: What Impala and Highrise AI Reveal About the Next Scaling Frontier

April 7, 2026
Employee Time Tracking

What is an Employee Time Tracking Solution? A Definite Guide for 2026

March 31, 2026
Voltify founders

Voltify Raises $30 Million Seed Round as It Challenges $1 Trillion Rail Electrification Model

March 31, 2026

Recommended

laptop on glass table

Automat-it Cuts Deployment Friction as Monce Scales AI Order Processing on AWS

April 13, 2026
Lee's Famous Recipe Chicken

Why Lee’s Famous Recipe Chicken Is Betting on Hi Auto to Quietly Rewire the Drive-Thru

April 9, 2026
computer generated image of letters

San Francisco Tribune Lists 11 HumanX Startups Moving AI Closer to the Operating Core

April 8, 2026
Impala CEO and Highrise AI CEO

The Industrialization of AI Infrastructure: What Impala and Highrise AI Reveal About the Next Scaling Frontier

April 7, 2026

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

AI AI QSRs Allseated Automat-it AWS B2B marketing Business CISO CISO Whisperer Collaborations Companies To Watch cryptocurrency Cybersecurity Entrepreneur Fetcherr Finance FINQ Fintech Funding Announcement hi-tech Hi Auto Impala Investing Investors investorsummit Israel israelitech Leaders LinkedIn Leaders Metaverse Mindset Minnesota omri hurwitz PointFive PR QSR Real Estate start- up startupnation Startups Startups On Demand Tech Tech leaders Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media