/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

World's largest DDoS attack reached 400Gbps, says Arbor Networks

NTP amplification fuelling era of super-massive DDoS  —  Share Twitter Facebook LinkedIn Google Plus Email this article  —  Some time in December 2014 an unnamed ISP experienced an NTP reflection DDoS attack that peaked …

Techworld.com John E Dunn

Context & Ripple Effects

Arbor Networks' disclosure that a December 2014 NTP reflection attack peaked at 400Gbps against an unnamed ISP was, at the time, a world record — and its warning that NTP amplification would fuel 'super-massive' DDoS proved prescient. Within two years, Brian Krebs' site was hit by a sustained 620Gbps attack nearly twice anything Akamai had seen before.

A decade on, the arc holds: Cloudflare mitigated a 7.3Tbps attack in mid-2025 and then a 31.4Tbps Aisuru/Kimwolf botnet attack in late 2025, while Amazon, Google, and Cloudflare jointly disclosed a volumetric record driven by a new protocol flaw rather than raw bandwidth. Each new amplification vector — from open NTP resolvers to fleets of 100K+ misconfigured middlebox servers — resets the ceiling.

First-order effects

  • The unnamed target ISP had to absorb junk traffic at 400Gbps, forcing real-time traffic scrubbing and making Arbor's attack telemetry immediately valuable to every operator sizing its own defenses.

Second-order effects

  • Every record-setting reflection technique pushes carriers and content networks toward upstream filtering and outsourced mitigation, shifting the defense market toward high-capacity scrubbing providers like Cloudflare, Akamai, Google, and Amazon — the same firms later disclosing the biggest attacks.

Third-order effects

  • The pattern Arbor flagged in 2015 — attackers renting amplification from misconfigured internet infrastructure rather than building botnets big enough on their own — has become structural: each new exploitable protocol (NTP, then middlebox reflection, then application-layer flaws) reopens the arms race regardless of defensive progress, with disclosed records climbing roughly two orders of magnitude in a decade.

The trend: DDoS attacks keep scaling by hijacking misconfigured internet infrastructure as amplifiers, and mitigation keeps consolidating into the hyperscale scrubbing networks best positioned to absorb them.