/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Kaspersky Lab's DDoS trends report: number of DDoS attacks dropped 13% YoY in 2018, but the average duration of attacks grew from 95 min in Q1 to 218 min in Q4

Securelist :

Securelist

Context & Ripple Effects

Kaspersky Lab's 2018 tally marks a reversal in the DDoS arc: after years of volume growth — Verisign logged an 85% year-over-year jump in attacks for Q4 2015 — the attack count fell 13% in 2018. What replaced volume is staying power: average attack duration more than doubled across the year, from 95 minutes in Q1 to 218 minutes in Q4.

The prior coverage also shows what longer attacks are built on: the Mirai-era IoT botnets that were already being repurposed in 2017 to harry the WannaCry kill-switch domain demonstrated that commodity botnet capacity could sustain pressure on a single target rather than spray-and-pray bursts. Fewer, longer attacks is the signature of that capacity being aimed, not just fired.

First-order effects

  • Targets hit in late 2018 faced outages lasting over twice as long as those early in the year, so a single successful attack now costs more downtime per incident even though incidents are rarer.
  • Mitigation vendors tracking this market — Verisign among them — see demand shift from absorbing sheer packet volume toward sustaining defense through multi-hour sieges.

Second-order effects

  • Pricing and SLAs for DDoS protection get renegotiated around duration and persistence rather than peak bandwidth, since a 218-minute attack stresses scrubbing capacity and incident response differently than a 95-minute one.
  • Botnet operators holding Mirai-lineage IoT fleets have an economic incentive to lease capacity for sustained campaigns against specific targets, competing on uptime of the attack rather than size of the burst.

Third-order effects

  • If the pattern holds, the industry's headline metric migrates from attack counts — the number Verisign made famous in 2015 and Kaspersky just cut by 13% — to time-to-mitigate and total downtime, reshaping how insurers, regulators, and buyers judge resilience.
  • Sustained attacks favor defenders with always-on filtering over on-demand scrubbing, nudging the market toward continuous protection architectures and making periodic 'burst' mitigation products look structurally mismatched.

The trend: DDoS is maturing from a high-volume, high-frequency nuisance into a lower-count, longer-duration pressure tactic, with botnet capacity increasingly rented for sustained targeting rather than mass spraying.