State of the Internet: Attack traffic, DDoS, IPv4 and IPv6

Akamai today released its latest State of the Internet report, which provides insight into key global statistics such as connection speeds and broadband adoption across fixed and mobile networks, overall attack traffic, global 4K readiness, and IPv4 exhaustion and IPv6 implementation.

Attack traffic and security

Akamai maintains a distributed set of unadvertised agents deployed across the Internet to log connection attempts that the company classifies as attack traffic. Based on the data collected by these agents, Akamai is able to identify the top countries from which attack traffic originates, as well as the top ports targeted by these attacks. It is important to note, however, that the originating country as identified by the source IP address may not represent the nation in which an attacker resides.

In the third quarter of 2014, Akamai observed attack traffic originating from 201 unique countries/regions, which was up significantly from 161 in the second quarter, and more in line with the 194 seen in the first quarter. As demonstrated in past reports, the highest concentration of attacks (50%) came from China, nearly three times more than the United States, which saw observed traffic grow by approximately 25% quarter-over-quarter. China and the United States were the only two countries to originate more than 10% of observed global attack traffic. Indonesia was the only country among the top 10 to see observed attack traffic decline, dropping from 15% of global attack traffic in the second quarter to 1.9% in the third.

The overall concentration of observed attack traffic decreased slightly in the third quarter, with the top 10 countries/regions originating 82% of observed attacks, down from 84% last quarter. Furthermore, 64% of attack traffic originated from the Asia Pacific region, down from 70% last quarter, while the lowest volume (1%) originated from Africa.

The volume of observed traffic targeting Ports 80 (HTTP/WWW), 443 (HTTPS/SSL) and 880 (HTTP Alternate) dropped significantly in the third quarter, with all three ports seeing a fraction of the attack volume seen in previous quarters. Port 23 remained the most popular target of attacks observed to be originating in China, accounting for more than three times more volume than Port 80, the second-most attacked port within the country.

Reported DDoS attack traffic

Akamai customers reported 270 DDoS attacks for the second quarter in a row. Overall, this represents a 4.5% reduction in attacks since the beginning of 2014 and a 4% decrease in comparison to the third quarter of 2013.

In contrast to the second quarter’s report, the number of attacks fell in both of the Americas, with 142 attacks, and in the EMEA region, with 44 attacks. However, the number of attacks in the APAC region rose by 25% from the previous quarter to 84. The distribution of industries did not change in comparison to the previous quarter; commerce, enterprise, high tech, media and entertainment, and the public sector all saw the same number of attacks as the previous quarter, even though the actual targets of these attacks changed. Compared with the same quarter of 2013, enterprise attacks have fallen by more than a third from 127 to 80. At the same time, attacks against high tech companies have tripled from 14 to 42.

Akamai saw an increase in the number of repeated attacks against the same target in the third quarter, returning to the 25% chance of a subsequent attack targeting the same organization. This represents a drop in unique targets from 184 in the second quarter to 174 in the third.

IPv4 and IPv6

In the third quarter of 2014, more than 790 million IPv4 addresses connected to the Akamai Intelligent Platform from more than 246 unique countries/regions. The global number of unique IPv4 addresses making requests to Akamai grew by nearly two million quarter-over-quarter, a nominal increase after a loss of seven million in the second quarter. Looking at the top 10 countries in the third quarter, the unique IP count in the United States saw a small gain of approximately 20,000 addresses.

In addition to the United States, Brazil, France and Russia saw nominal increases in unique IPv4 address counts, while the remaining six countries saw unique IPv4 address counts slightly decline from the second quarter. Fifty-eight percent of countries saw a quarter-over-quarter increase in unique IPv4 address counts, with 28 countries/regions growing by 10% or more.

Cable and wireless providers continued to drive the number of IPv6 requests made to Akamai, many of which are leading the way for IPv6 adoption in their respective countries. Verizon Wireless and Brutele saw more than half of their requests to Akamai made over IPv6, with Telenet close behind.