Verisign: The number of DDoS attacks increased 85% in Q4 2015, compared to Q4 a year ago
Danny Palmer / ZDNet :
Context & Ripple Effects
Verisign's Q4 2015 tally is the earliest data point in this corpus's running record of DDoS activity, and it set the template for how the industry now tracks the threat: quarterly vendor telemetry, year-over-year comparisons. What came after shows why that baseline matters — Kaspersky Lab's 2018 trends report found raw attack counts falling even as average attack duration nearly doubled within the year, and FS-ISAC's 2023 banking-sector survey recorded a 22% annual rise in attacks on financial firms, concentrated in Europe.
First-order effects
- Organizations hit in Q4 2015 faced a materially higher frequency of attack traffic than the prior-year quarter, straining whatever on-premises or ISP-level defenses they had in place at the time.
- Verisign, which sits on DNS infrastructure and sells managed DDoS protection, converts its network visibility into both the dataset and the sales case for mitigation services.
Second-order effects
- Rising counts push buyers toward always-on cloud scrubbing rather than reactive response, expanding the market for providers like Verisign and later entrants such as Cloudflare whose telemetry becomes a competitive marketing asset.
- Competing security vendors respond by publishing their own quarterly DDoS reports — Kaspersky, FS-ISAC, and Cloudflare all followed with trend studies — turning attack statistics into a recurring PR battleground where each firm's network footprint shapes what it measures.
Third-order effects
- If the pattern holds, the industry's focus shifts from counting attacks to measuring their size and persistence — exactly the evolution visible from Kaspersky's duration-growth finding to Cloudflare's packets-per-second records — as volumetric capability keeps ratcheting upward.
- Sector concentration, seen later in the banking-targeted FS-ISAC data, points toward DDoS becoming a persistent operational cost for critical industries rather than an episodic nuisance, with regulation and resilience planning likely to follow.
The trend: DDoS is maturing from an episodic nuisance into industrial-scale, persistently measured attack traffic, with each successive vendor report resetting the ceiling on volume and duration.