DDoS: The Next Generation

Andrew Cockburn (NetScout)

DEF CON 33 · Day 1 · Main Stage

Overview

In "DDoS: The Next Generation," Andrew Cockburn from NetScout delivers a compelling and data-driven presentation on the evolving landscape of Distributed Denial of Service (DDoS) attacks. Drawing from NetScout's extensive global threat intelligence, Cockburn dissects current trends, highlights the shift in attack methodologies, and projects future challenges, particularly concerning the integration of Artificial Intelligence (AI) into attacker toolsets. The talk is a critical examination of how threat actors are adapting to defensive measures, optimizing their campaigns for maximum impact and monetization, and leveraging new technologies to democratize sophisticated attack capabilities.

Watch on YouTube

Visual summary for DDoS: The Next Generation by Andrew Cockburn
Visual summary for DDoS: The Next Generation by Andrew Cockburn

Key moments

  1. 0:00 Speaker introduction and NetScout's DDoS expertise
  2. 1:18 NetScout's extensive DDoS data collection capabilities
  3. 2:00 AI/ML processing for identifying DDoS attackers
  4. 3:15 Why maximum DDoS bandwidth numbers are misleading
  5. 4:22 Attack frequency: the true growing DDoS threat
  6. 4:53 Analysis: Most DDoS attacks are small and short
  7. 6:07 Attackers monetize resources, tailoring attack size
  8. 6:45 Short attack duration for testing defenses and responses

DDoS: The Next Generation

Speakers: Andrew Cockburn, NetScout

Conference: DEF CON

YouTube: https://www.youtube.com/watch?v=VlOUGECw6kc

Overview

In "DDoS: The Next Generation," Andrew Cockburn from NetScout delivers a compelling and data-driven presentation on the evolving landscape of Distributed Denial of Service (DDoS) attacks. Drawing from NetScout's extensive global threat intelligence, Cockburn dissects current trends, highlights the shift in attack methodologies, and projects future challenges, particularly concerning the integration of Artificial Intelligence (AI) into attacker toolsets. The talk is a critical examination of how threat actors are adapting to defensive measures, optimizing their campaigns for maximum impact and monetization, and leveraging new technologies to democratize sophisticated attack capabilities.

Cockburn's insights are particularly valuable due to NetScout's unique position as a leading provider of DDoS detection and mitigation solutions. The company gathers data from two-thirds of the routable IP address space and observes half of the internet's traffic, providing an unparalleled vantage point into global DDoS activity. This deep visibility allows NetScout to track emerging attack vectors, identify key motivations, and understand the lifecycle of DDoS campaigns from initial testing to widespread adoption through DDoS-for-hire services.

The presentation underscores the persistent and growing threat posed by DDoS, emphasizing that while the largest attacks grab headlines, the true challenge lies in the sheer frequency and increasing sophistication of smaller, shorter, and more targeted assaults. It serves as a vital call to action for defenders, stressing the importance of automation, layered protection strategies, and proactive preparation to counter an adversary that is constantly innovating and leveraging every available technological edge.

Background

▶ Watch: Speaker introduction and NetScout's DDoS expertise (0:00)

NetScout's understanding of the DDoS landscape is built upon a robust data collection and analysis infrastructure. By deploying solutions within numerous service providers, NetScout effectively monitors a vast segment of the internet's traffic, making it highly probable that any significant DDoS attack will pass through their monitored network segments. This raw data is then fed into a sophisticated cloud-based AI/ML system that crunches the information, detects outliers, corroborates findings, and cross-references data from third-party sources and honeypots. The outcome is a continuously updated threat intelligence feed that identifies malicious IP addresses and emerging attack patterns, which is then engineered into NetScout's products to proactively defend against attacks.

Historically, the public perception of DDoS attacks often fixated on headline-grabbing volumetric assaults, measured in hundreds of gigabits or even terabits per second. While these large-scale attacks do occur—with one notable example reaching 995 Gbits/sec in the latter half of 2024—Cockburn clarifies that these are outliers. The true and more insidious threat lies in the overwhelming frequency of attacks. NetScout's data reveals an alarming trend: nearly 9 million DDoS attacks were recorded in the second half of 2024, representing an increase of over 12% compared to the previous period. This consistent year-over-year growth in attack frequency highlights the escalating challenge faced by organizations worldwide.

Further analysis of attack characteristics reveals a strategic shift by attackers. The vast majority of DDoS incidents—approximately 75%—are relatively small, falling below 1 Gigabit per second (Gbps). Similarly, about 70% of attacks are short-lived, lasting less than 15 minutes. This trend is not indicative of a decrease in attacker capability but rather a deliberate optimization strategy. Attackers understand that "enough is enough"; a 1.1 Gbps attack is sufficient to saturate a 1 Gbps pipe. By launching smaller attacks, they conserve resources, which are often monetized through DDoS-for-hire services. The short duration of attacks is designed to exploit the typical response window of defenders. By the time a victim detects an attack, mobilizes a response, and diverts traffic to a scrubber, the attack may already be over, only to resume an hour later, creating a "whack-a-mole" scenario that exhausts defensive teams.

Key Findings

▶ Watch: AI/ML processing for identifying DDoS attackers (2:00)

The presentation highlights several critical shifts and persistent trends in the DDoS threat landscape:

  1. Shift to Direct Path Flag Attacks: A significant change in DDoS methodology has occurred over the last three to four years. Previously, amplification attacks (e.g., DNS, SNMP, NTP amplification) dominated, leveraging open resolvers and servers to magnify attack traffic. However, improved anti-spoofing measures by responsible operators and enhanced mitigation capabilities by service providers have diminished their effectiveness. Attackers have pivoted to direct path flag attacks, primarily state exhaustion attacks. The top four vectors observed are TCP ACK, TCP SYN, ICMP, and TCP RST floods. These attacks utilize compromised bots with significant horsepower and connectivity to directly target victims, making them harder to trace and mitigate. DNS amplification remains prevalent only because mitigating attacks against DNS servers themselves is particularly challenging.
  1. Rise of Geopolitical Motivations: Beyond financial gain (extortion, DDoS-for-hire), geopolitical motivations are rapidly becoming a dominant driver for DDoS campaigns. NetScout observes clear correlations between specific geopolitical events and spikes in attack activity. Examples cited include a massive increase aligned with the "Dark Storm" group (attributed to Iran) during Israel's Rafa operations, peaks during political turmoil in the UK, national elections in Mexico, and protests in Mozambique. These events demonstrate how nation-states and hacktivist groups leverage DDoS as a tool for digital warfare and protest.
  1. Sophistication of DDoS-for-Hire Services: The "booter/stressor" market continues to evolve, making sophisticated DDoS capabilities accessible to a wider audience. These services now offer advanced options beyond simple IP targeting, including carpet bombing attacks and spoofed source IP addresses. Carpet bombing distributes attack traffic across a large subnet, keeping individual IP traffic low but overwhelming aggregate links, making detection and blocking difficult. Attackers can also spoof traffic to appear from specific countries or service providers, attempting to mislead defenders. These platforms act as the "long tail" of attack vectors, quickly incorporating new techniques identified by highly motivated hackers into user-friendly menus, driving sustained prevalence of these attack types.
  1. Botnets as the Backbone: Botnets remain central to modern DDoS attacks, particularly for powering direct path attacks and DDoS-for-hire services. While various botnets like Dynis exist, Mirai is noted for its widespread prevalence. Mirai's source code release led to numerous variants, and its self-propagating nature—where compromised IoT devices scan for and infect other vulnerable devices using common passwords—makes it incredibly resilient. A vulnerable device can be reinfected within minutes of being power-cycled. Law enforcement efforts like "Operation Power Off" can cause temporary plunges in botnet populations, but operators quickly recover by activating spare hosts, underscoring the need for mitigation over source eradication.
  1. Application Layer Attacks and DNS Water Torture: Beyond network-layer floods, application-layer attacks are a growing concern. Notable examples include HTTPS GET floods and DNS water torture. DNS water torture involves attackers sending queries for random, non-existent hostnames to a victim's DNS server. If it's a recursive server, it attempts to resolve these queries, consuming significant resources and eventually leading to overload. Attackers are also observed using legitimate open DNS servers as proxies to obscure their bots' IP addresses, adding another layer of obfuscation and making request-by-request mitigation necessary.

Technical Deep Dive

▶ Watch: Attack frequency: the true growing DDoS threat (4:22)

The shift from volumetric amplification attacks to direct path flag attacks represents a fundamental change in DDoS tactics. Amplification attacks, such as those leveraging DNS or NTP, relied on sending small, spoofed requests to open, internet-facing servers. These servers would then respond with much larger replies to the victim's spoofed IP address, effectively amplifying the attacker's bandwidth. The success of these attacks hinged on the prevalence of open resolvers and the ability to spoof source IP addresses. However, widespread implementation of BCP 38 (anti-spoofing) and improved network hygiene have reduced the pool of exploitable reflectors and amplifiers.

In response, attackers have migrated to direct path state exhaustion attacks, which utilize compromised botnets to directly flood a target. These attacks don't rely on amplification but rather on overwhelming a target's resources by initiating a large number of legitimate-looking, but ultimately unfulfillable, connections or by consuming system resources.

  • TCP SYN Floods: This classic attack involves sending a flood of TCP SYN (synchronize) packets to a target server. Each SYN packet initiates a half-open connection, consuming resources in the server's connection table. If enough SYN packets are sent without the corresponding SYN-ACK (synchronize-acknowledgment) and ACK (acknowledgment) handshakes completing, the server's connection table fills up, preventing legitimate users from establishing new connections.
  • TCP ACK Floods: While less common than SYN floods, ACK floods can also be effective. Attackers send a high volume of TCP ACK packets, often with random sequence numbers, to a target. The target server expends resources processing these packets, attempting to match them to existing connections, which can lead to CPU exhaustion or firewall state table overload.
  • TCP RST Floods: Similar to ACK floods, a flood of TCP RST (reset) packets can be used to tear down existing connections or consume resources by forcing the target to process invalid reset requests.
  • ICMP Floods: Internet Control Message Protocol (ICMP) floods, such as ping floods, involve overwhelming a target with ICMP echo requests. While ICMP is typically rate-limited, a sufficiently large flood can still consume bandwidth and processing power.

The rise of carpet bombing attacks further illustrates attacker ingenuity. Traditional DDoS detection often focuses on traffic spikes to a single IP address. Carpet bombing subverts this by distributing relatively small amounts of attack traffic across a broad range of IP addresses within a target's subnet (e.g., a /24 or /22 range). While no single IP address experiences a severe attack, the aggregate traffic destined for that subnet can saturate the ingress link to the organization. This requires more sophisticated detection mechanisms that can correlate traffic patterns across entire IP ranges rather than just individual addresses.

DNS water torture attacks target the DNS infrastructure itself, which is critical for all internet services. Attackers generate a high volume of unique, non-existent domain name queries (e.g., randomstring.victimdomain.com). When these queries hit a recursive DNS server, it attempts to resolve them. Since the domains don't exist, the server must perform multiple recursive lookups, contacting authoritative servers higher up the DNS hierarchy, consuming CPU cycles, memory, and network bandwidth. This continuous, resource-intensive process can overload the DNS server, rendering it unresponsive for legitimate queries. Attackers also use legitimate open DNS resolvers as proxies, sending their direct path attack requests to these resolvers, which then forward them to the victim's DNS server. This obfuscates the true source of the attack, making it harder for defenders to block the originating botnet IPs.

The underlying infrastructure for many of these attacks is botnets, particularly the Mirai variant. Mirai is infamous for its ability to self-propagate, scanning the internet for vulnerable IoT devices (e.g., cameras, DVRs, routers) that still use default or weak credentials. Once compromised, a Mirai bot not only participates in DDoS attacks but also actively seeks out and infects other vulnerable devices, creating a rapidly expanding network. This decentralized, self-sustaining propagation makes Mirai highly resilient to takedowns, as new bots are constantly being added, and operators can quickly reconstitute their forces.

Looking ahead, the integration of AI and Machine Learning (ML) into attacker toolsets is not expected to immediately generate entirely new attack vectors. Instead, its primary impact will be in automation. AI will enable attackers to:

  • Automate entire campaigns: Coordinating target selection, attack vector rotation, and timing.
  • Target refinement: Intelligently identify vulnerable services (e.g., API endpoints) or less protected data centers for focused attacks.
  • Conversational attack refinement: DDoS-for-hire platforms will offer natural language interfaces, allowing non-technical users to describe desired attack outcomes (e.g., "attack their API endpoints in Europe, rotating vectors every minute") and have the AI translate these into complex, multi-vector, adaptive attacks. This democratization of advanced DDoS capabilities will significantly lower the bar for launching sophisticated campaigns.

Demo / Proof of Concept

▶ Watch: Analysis: Most DDoS attacks are small and short (4:53)

While the talk itself did not feature a live technical demonstration of a DDoS attack or a NetScout solution, Andrew Cockburn concluded by inviting attendees to participate in red and blue team simulations at the DOS community booth. These simulations offered a practical, hands-on opportunity for individuals to experience the feeling of being under attack and to practice defensive strategies, providing a direct "proof of concept" for the challenges and mitigation techniques discussed in the presentation.

Defensive Implications

▶ Watch: Short attack duration for testing defenses and responses (6:45)

Given the evolving nature of DDoS attacks, defenders must adopt a multi-faceted and highly automated approach to protection. The core principle is to "fight fire with fire," matching attacker automation with defensive automation.

  1. Automated Threat Intelligence: Leveraging AI/ML-driven global threat intelligence, like that provided by NetScout, is crucial. This proactive intelligence identifies malicious IP addresses and emerging attack patterns before an attack hits. By pre-processing and feeding this data into defensive systems, a significant proportion (up to 90%) of incoming attack traffic can be blocked simply by knowing the source, reducing the load on other mitigation layers.
  1. Hybrid/Layered Protection Architecture: A single defense mechanism is no longer sufficient. The recommended best practice is a hybrid protection or layered protection model:
  • On-Premise Devices: These devices, situated within the organization's network, are essential for mitigating application-layer attacks and smaller direct path attacks. Their proximity to the protected assets allows them to learn "normal" network behavior using machine learning. This baseline understanding enables them to accurately detect and block outliers and abnormal traffic patterns indicative of an attack, often with very low latency.
  • Cloud Scrubbing: For large-scale volumetric attacks that threaten to saturate internet links, cloud-based scrubbing services are indispensable. These services operate higher up in the network hierarchy (either through a service provider or a third-party DDoS mitigation provider) and can absorb and clean massive amounts of malicious traffic before it reaches the victim's network. This offloads the burden of handling overwhelming traffic volumes from the local infrastructure.
  1. Proactive Preparation and Training: Technical solutions alone are not enough. Organizational readiness, training, and established procedures are paramount for successful defense:
  • Network Hardening: Implementing best practices for securing network infrastructure.
  • SOC Staff Training: Training Security Operations Center (SOC) personnel not only on specific tools but also on general DDoS attack dynamics, current threat intelligence, and response protocols.
  • Regular Simulations: Conducting frequent (e.g., monthly) simulated DDoS attacks. These "fire drills" test the entire response chain, from detection to mitigation, communication, and recovery.
  • Established Procedures: Clear, documented procedures for who opens communication bridges, who is on the bridge, how executives are informed, and how service providers are engaged during an attack.
  • Up-to-Date Intelligence: Continuously monitoring the latest threat intelligence to understand attack campaigns targeting specific industry segments or regions.
  1. Focus on Mitigation, Not Just Source Eradication: While law enforcement efforts to take down botnets (like "Operation Power Off") are valuable, they provide only temporary relief. Botnet operators are agile and quickly recover. Therefore, defenders must prioritize robust, automated mitigation strategies that can effectively counter attacks regardless of their source or how quickly new botnets emerge.

In essence, defending against "DDoS: The Next Generation" requires a blend of advanced technology, intelligent automation, and human preparedness. It's a continuous arms race where vigilance, adaptability, and proactive measures are the keys to maintaining operational resilience.

Key Takeaways

  • DDoS Frequency and Sophistication are Escalating: The number of DDoS attacks is consistently rising (over 12% increase), driven by both financial monetization (DDoS-for-hire) and geopolitical motivations, making them a persistent and growing threat.
  • Shift to Direct Path State Exhaustion Attacks: Attackers have moved away from volumetric amplification attacks, increasingly favoring direct path flag attacks (e.g., TCP SYN/ACK/RST floods, ICMP floods) launched from powerful botnets to overwhelm target resources.
  • New Attack Tactics Evade Traditional Defenses: Techniques like carpet bombing (distributing traffic across subnets) and DNS water torture (random hostname queries to overload recursive DNS servers) are designed to bypass conventional single-IP detection and mitigation strategies.
  • DDoS-for-Hire Services and AI Democratize Attacks: "Booter/stressor" platforms are making sophisticated, multi-vector attacks accessible to non-technical users. The future integration of AI/LLMs will further automate attack campaign coordination, target selection, and vector rotation, significantly lowering the barrier to launching complex DDoS operations.
  • Hybrid, Automated Defense is Essential: Effective defense requires a layered approach combining on-premise devices (for application-layer and smaller direct attacks, leveraging local knowledge and ML) with cloud-based scrubbing (for volumetric attacks) and continuous, AI-driven global threat intelligence.
  • Preparation and Training are Non-Negotiable: Beyond technology, organizations must prioritize network hardening, comprehensive SOC staff training, regular DDoS simulations, and well-defined incident response procedures to effectively withstand and recover from attacks. Botnet takedowns offer only temporary respite; the focus must be on resilient mitigation.

About the Speaker(s)

Andrew Cockburn is a specialist in DOS detection and mitigation solutions, working for NetScout. With over a decade of experience in the field, he possesses deep expertise in understanding the dynamics of Distributed Denial of Service attacks, analyzing global threat trends, and developing effective defensive strategies. His role at NetScout provides him with unique access to extensive internet traffic data, informing his insights into the evolving tactics of threat actors and the future of DDoS defense.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

This is a vendor intelligence briefing dressed as conference research — competent, data-rich, but ultimately a NetScout product pitch with DEF CON staging. The findings are real but the conclusions are predictable, the 'AI future' section is speculative hand-waving, and nothing here would surprise anyone who reads the ATLAS or Cloudflare radar reports quarterly.

Heather Calloway (CISO) — WEAK

Solid threat intelligence wrapped in a vendor presentation that never escapes its own promotional frame. The data is real and the trend analysis is credible, but the talk stops at describing the problem and gestures at solutions that conveniently require NetScout's product stack. Security leaders leave with a better picture of the threat and no clearer sense of what decisions to make.

→ Top-rated talks at DEF CON 33

All talks from DEF CON 33