Kaspersky Lab's DDoS trends report: number of DDoS attacks dropped 13% YoY in 2018, but the average duration of attacks grew from 95 min in Q1 to 218 min in Q4
Context & Ripple Effects
Kaspersky Lab's 2018 tally marks a reversal in the DDoS arc: after years of volume growth — Verisign logged an 85% year-over-year jump in attacks for Q4 2015 — the attack count fell 13% in 2018. What replaced volume is staying power: average attack duration more than doubled across the year, from 95 minutes in Q1 to 218 minutes in Q4.
The prior coverage also shows what longer attacks are built on: the Mirai-era IoT botnets that were already being repurposed in 2017 to harry the WannaCry kill-switch domain demonstrated that commodity botnet capacity could sustain pressure on a single target rather than spray-and-pray bursts. Fewer, longer attacks is the signature of that capacity being aimed, not just fired.
First-order effects
- Targets hit in late 2018 faced outages lasting over twice as long as those early in the year, so a single successful attack now costs more downtime per incident even though incidents are rarer.
- Mitigation vendors tracking this market — Verisign among them — see demand shift from absorbing sheer packet volume toward sustaining defense through multi-hour sieges.
Second-order effects
- Pricing and SLAs for DDoS protection get renegotiated around duration and persistence rather than peak bandwidth, since a 218-minute attack stresses scrubbing capacity and incident response differently than a 95-minute one.
- Botnet operators holding Mirai-lineage IoT fleets have an economic incentive to lease capacity for sustained campaigns against specific targets, competing on uptime of the attack rather than size of the burst.
Third-order effects
- If the pattern holds, the industry's headline metric migrates from attack counts — the number Verisign made famous in 2015 and Kaspersky just cut by 13% — to time-to-mitigate and total downtime, reshaping how insurers, regulators, and buyers judge resilience.
- Sustained attacks favor defenders with always-on filtering over on-demand scrubbing, nudging the market toward continuous protection architectures and making periodic 'burst' mitigation products look structurally mismatched.
The trend: DDoS is maturing from a high-volume, high-frequency nuisance into a lower-count, longer-duration pressure tactic, with botnet capacity increasingly rented for sustained targeting rather than mass spraying.