The New Normal: 200-400 Gbps DDoS Attacks
Over the past four years, KrebsOnSecurity has been targeted by countless denial-of-service attacks intended to knock it offline. Earlier this week, KrebsOnSecurity was hit by easily the most massive and intense such attack yet …
Context & Ripple Effects
KrebsOnSecurity is a repeat target: Brian Krebs has spent the past four years documenting denial-of-service assaults aimed at taking his own site offline, and this week's strike was easily the largest he has faced. The speed and breadth of pickup — SC Magazine, Computerworld, Threatpost and Gartner all carried the story within about a day — suggests the security trade read the 200-400 Gbps figure less as one blogger's misfortune than as a new benchmark for what attackers can field.
Why it matters: if attacks at this scale are 'the new normal,' then every organization sizing its defenses against yesterday's peak is under-provisioned, and the burden of surviving them falls on whoever supplies the victim's transit and scrubbing capacity.
First-order effects
- KrebsOnSecurity's hosting and mitigation stack must absorb its biggest attack in four years of targeting, with the site's uptime riding entirely on the headroom of whoever scrubs its traffic.
- Any customer sharing that same mitigation capacity inherits the cost of infrastructure sized for hundreds of gigabits, lifting baseline defense spending across the board.
Second-order effects
- Mitigation and CDN providers face immediate pressure to expand scrubbing capacity beyond prior peaks, since buyers now size contracts against 200-400 Gbps events rather than tens of gigabits.
- A successful, highly publicized assault on a prominent security journalist raises the odds of copycat campaigns against other researchers and small publishers who lack comparable protection.
Third-order effects
- If multi-hundred-gigabit attacks are ordinary, independent sites cannot realistically defend themselves alone, pushing internet publishing toward consolidation behind large-scale scrubbing networks.
- Sustained attacks at this volume typically rely on spoofed amplification from third-party servers, sharpening pressure on network operators and regulators to filter spoofed traffic at source.
The trend: DDoS attack volumes keep ratcheting upward as attackers tap ever-larger pools of reflectable bandwidth, turning record-scale assaults into routine events measured in months rather than years.