
DEF CON 33 - DDoS: The Next Generation - Andrew Cockburn
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 38:12
Revised Summary: NetScout's DDoS Threat Report Analysis: Attack Evolution, Motivations, and Defense Strategies
Summary
Andrew Coburn from NetScout presents findings from their latest DDoS threat report, revealing a 12% increase in global attack frequency to 8-9 million attacks. While the maximum recorded attack reached 995 Gbps, most attacks are smaller and shorter: 75% are under 1 Gbps and 70% last under 15 minutes. This trend indicates attackers optimize resources for efficiency rather than deploying maximum capacity.
Key Findings
Attack Evolution
Attack patterns have shifted dramatically from amplification-based attacks to direct path flag attacks:
- Top Attack Vectors: Now dominated by direct path attacks: ACT, TCP, TCP SYN, ICMP, and TCP RST. DNS amplification remains in the top five due to mitigation difficulty.
- Reasons for Shift:
- Service providers implemented effective anti-spoofing measures
- Attackers now leverage botnets of compromised high-power servers
- Flag attacks (like SYN floods) are more efficient and harder to mitigate
- DNS amplification persists because it's notoriously difficult to block
- Trend Data: Direct path attacks have surpassed volumetric reflection amplification attacks over the past 2-3 years.
Attack Motivations
Two primary drivers fuel DDoS attacks:
- Monetization: Extortion campaigns and DDoS-for-hire services.
- Geopolitical Activities: Clear correlations exist between specific world events and attack spikes, including:
- Dark Storm (Iran-linked) attacks during Israel's Rafah operations
- Attack surge coinciding with the UK's new government session
- Attacks during Mexico's national elections
- Attacks during political protests in Mozambique
DDoS-for-Hire Services Evolution
These services have evolved significantly from simple tools to sophisticated platforms:
- Advanced Capabilities:
- **Carpe
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Okay, let's get it uh started. Um, my name is Andrew Coburn and I work for a company called NetScout and we specialize in DOS detection and mitigation solutions. So, >> Mike, >> I'm going to stand like this for the entire thing. Awesome. All right, this is going to be fun. Can I use a handheld? >> Yeah, much prefer. >> Check. One, two. >> All right. How's this? Okay. So, now you have to remind me to hold it up to my mouth, but I can I can pace, but only this far. Okay. All good. All right. Andrew Coburn, work for a company called NetScout. Uh, we do DOS detection and mitigation solutions. How many people know what DOS is? Awesome. How many people have actually experienced a DOS attack? All right. Okay. You guys are in the right place and I'm in the right place. So, so what we want to talk …