**Observing Trends on Distributed Denial of Service (DDoS) Attacks on Websites**

**HIGHLIGHTS**

  - DDoS is an attempt to disrupt a networked service by overloading the web server.

  - DDoS attacks involves Internet Service Providers, mitigation service providers, and hardware providers.

  - Challenges in overcoming DDoS attacks are holding the perpetrator accountable and filtering incoming requests.

  - A DDoS attack could damage the target’s monetary gains and their reputation.

ABSTRACT

This paper aims to observe trends on Distributed Denial of Service attacks, or DDoS attacks on websites. DDoS is an effort to prevent a service from serving its customers by overloading the server with a large number of requests. The actors involved in an attack are ISPs as the provider of the internet connection, hardware providers and mitigation service providers. All actors should act to mitigate DDoS attack. Several motivations of DDoS attacks range from attacking a server for showing off a skill to gaining financial profits and ideological beliefs. The trend of the attack is most of the DDoS attack is originating from United States. The targets of DDoS attack could experience monetary losses and damaged credibility.

*Keywords: DDoS, Network, Mitigation, Service*

# INTRODUCTION

Distributed Denial of Service attack, or DDoS attack is an attempt to disrupt a networked service by flooding the web server with excessive amount of network packets, sent by several systems. A DDoS attack is not limited to web servers but could impact all networked systems. DDoS attack could disrupt Internet of Things (IoT) systems connected to a house, causing inconveniences (Tushir et. al., 2020), and services offering cloud computing systems, endangering their customers’ sensitive data (Mahjabin, 2018). There are several methods of DDoS attacks. The examples are:

SYN Flood Attacks

As shown in Figure 1, The handshake system of the TCP network protocol is exploited in SYN attacks. The client sent a SYN message to the server as part of a standard TCP handshake. The server then responds with a SYN-ACK message to the client, acknowledging the client's request. Finally, the client sends an ACK message to the server to confirm the connection, and the connection is established. (Wong & Tan, 2014).

> ![](205-1-621-1-2-20210513_media/media/image1.png)

**Figure 1:** A Normal TCP Handshake Process (Wong & Tan, 2014).

In a SYN flood attack, the attacker sent excessive amount of SYN messages to the server. The server then tries to respond to all incoming SYN messages with a SYN-ACK message. When a legitimate user attempts to connect to the server, the server is preoccupied with responding to the attacker's SYN request, effectively preventing legitimate users from connecting, as seen in Figure 2.

> ![](205-1-621-1-2-20210513_media/media/image2.png)

**Figure 2:** A SYN Flood Attack Process (Wong & Tan, 2014).

UDP Flood Attacks

UDP Flood is an attack that utilizes User Datagram Protocol (UDP) packets to attack the target’s random ports (Arshi et. al, 2020). The result of this attack is that the host would stop responding to legitimate users that requests the service due to the overload.

ICMP Flood Attacks

ICMP attacks works using Internet Control Message Protocol. ICMP based attacks is divided into two attacks, Smurf attacks and Ping of Death attacks. Smurf attacks works by sending large numbers of ICMP packets and flooding the target’s system with ping messages (Yusof et. al., 2017). Ping of Death attack works by sending a malformed ping packet larger than the maximum acceptable size. This attack will cause memory overflow and burdening the target’s server system, effectively disabling the system.

HTTP Flood Attack

HTTP attacks works by utilizing the application layers (Layer 7) of a network. This attack is done by sending a HTTP request, such as GET requests, and formulating it to maximize the attack intensity (Alomari et. al., 2012). Botnets, which is the distributed system used to attack a server, are usually used and can generate 10 valid requests per second (Kesavamoorthy et. al., 2020). If conducted properly, this attack is difficult to detect, due to the requests become very similar to legitimate web traffic (Alomari et. al., 2012).

In this paper, Section 1 introduces the definition and challenges of DDoS attacks, Section 2 explains the actors and motivations of an attack, Section 3 explains the consequences of an attack to DDoS target, Section 4 explains the literature review, Section 5 is the conclusion of the paper.

**ACTORS AND MOTIVATIONS**

**Actors Related to DDoS Attacks**

DDoS attacks involves several actors from network providers, service providers, and hardware manufacturers. For example, several networking services starting to offer DDoS attack mitigation services, such as Cloudflare. The service works by filtering incoming packets and forwarding the legitimate packets to the client (Lavrenovs, 2021). However, device manufacturers often cut corners to make their products as cheap as possible to maximize profits while often sacrificing quality and security. Therefore, manufacturers are encouraged to minimize or mitigate the occurrence of DDoS attacks on their clients (Lavrenovs, 2021). Internet Service Providers (ISP) currently did little about mitigating DDoS attacks, since they are the least impacted party in the event of a DDoS attack. Therefore, ISPs should engage in the activity of preventing or mitigating DDoS attack to protect their customers.

**Motivations of Attack**

DDoS attackers usually are motivated to launch an attack to a website. The motivations usually vary, but usually the attacker’s main goal is to deny other users to access the attacked website. The motivations are including, but not limited to:

  - Financial or economical gain

This attack is launched by the attacker to gather economical gain. This attack is mainly concern of corporation and require more skills and experience (Prasad et al., 2014). A potential scenario for this attack is a website owner launched an attack to their competitor doing business in the same field. The victim will effectively be unable to serve their potential customers and depriving them of financial gain. The customers are expected to use the perpetrator’s business.

  - Intellectual Challenge

This attack is usually performed by enthusiasts who want to demonstrate their skills on launching a DDoS attack (Prasad et al., 2014).

  - Ideological Goal

In this attack, the attacker is inspired by their own beliefs to target a website (Prasad et al., 2014). The website attacked likely hosts contents that is opposing to the attacker’s beliefs, and the attacker aims to prevent other people to access the victim’s contents. The examples of the groups that use DDoS as a method to enforce their ideologies are Al-Qassam Brigade Cyber Fighters, Cyber Berkut and others (Wueest, 2014).

**DDoS Trends**

**2012**

In 2012, it is observed that DDoS attacks are conducted with SYN flood attacks, contributing 24 percent of the attacks, with UDP flood attacks being the second most used type of attacks, at 20 percent, as shown in Figure 3.

![](205-1-621-1-2-20210513_media/media/image3.png)

**Figure 3:** Percentage of DDoS attack types in Q1 2012 (Aamir & Arif, 2013).

Most of the attacks in 2012 are originated from China, making up 30.59 percent of the attacks, with USA contributing 19.2 percent of the attacks, shown in Figure 4.

![](205-1-621-1-2-20210513_media/media/image4.png)

**Figure 4:** Top ten source of countries of DDoS attacks in 2012 Q1 (Aamir & Arif, 2013).

**2018**

In 2018 most of the DDoS attack originated from United States, making up 30 percent of the origin of the traffic (Chakraborty et. al., 2019), based on Table 1.

**Table 1:** Percentage of Worldwide DDoS Attacks Traffic Between November 2017 and April 2018 by Countries (Chakraborty et. al., 2019).

| **Countries**    | **US**  | **China** | **UK** | **India** | **Spain** | **Russia** | **Brazil** | **Korea** | **Japan** | **Ecuador** |
| ---------------- | ------- | --------- | ------ | --------- | --------- | ---------- | ---------- | --------- | --------- | ----------- |
| **Total (100%)** | **30%** | **16%**   | **5%** | **4%**    | **3%**    | **3%**     | **3%**     | **3%**    | **3%**    | **2%**      |

When looked by the type of the attack, 56 percent of the attack is conducted with UDP protocol, with TCP attacks as the second most common attack, at 26 percent. Third most used method in DDoS attack is IP fragment method at 10 percent (Chakraborty et. al., 2019), as shown in Figure 5. This shows that throughout the time, DDoS attackers are more interested in aiming their attacks at the infrastructure layer of the target by using UDP and TCP, compared to attacking the application layer (Layer 7) of the target’s network.

![](205-1-621-1-2-20210513_media/media/image5.png)

**Figure 5:** Percentage of DDoS Attacks by Types in Q2 2018 (Chakraborty et. al., 2019).

**CONSEQUENCES OF AN ATTACK**

**Effects on the Targets**

While the main noticeable effect of a DDoS attack is degradation on the target’s service by reducing its ability to serve their users (Tang & Kuang, 2019), there are several impacts that could affect DDoS targets. The impacts include, but not limited to financial impacts that could happen to, for example, an online store website that has been attacked. The store could potentially see a decrease on profits because their customers are not able to access the store. Victim’s credibility is also potentially damaged due to their inability to service their clients. Potential customers may become frustrated and lose confidence in the brand (Wueest, 2014). The brand trust and financial impact may be connected; therefore, it is important for businesses to preserve their customers’ trust by preventing or mitigating DDoS attacks to be able to constantly serve their customers.

**Mitigations and Responses**

There are several actions that a server administrator can perform in the event of a DDoS attack. Factors that affect mitigation efforts are attack scale and duration (Somani et. al., 2017), which can be used as a guide for deciding what is needed to mitigate the attacks.

The basic action that can be done is to trace back the attacker by tracking the IP address of the attacker. With this method, the attacker could be found and held accountable for their actions. However, if the attack is performed by botnets, it is difficult to find the original attacker’s origin IP address.

The administrator can also control the intensity of the attacks using a security system known as “honey pots” (Yuvaraj et. al., 2019). This system consists of several decoy servers that directs some of the malicious packets away from the main working server, minimizing the impact of the attack. Some type of honey pots can also trace the attacks in various levels of information (Yuvaraj et. al., 2019), but using honey pots as DDoS mitigation are costly and causes processing delays (Fakeeh, 2016), due to the packets need to travel through several proxy servers.

Another method is to put the attacker’s previous IP address in a database and acknowledges the incoming packets from that IP address accordingly (Mahajan & Sachdeva, 2013). This prevents repeat attack from that same attacker, but a proficient attacker could evade this method of filtering by altering their IP address to fits the system’s database.

Other methods to mitigate DDoS attacks are proposed and developed, such as using machine learning techniques, such as data mining and statistical approach (Osanaiye et. al., 2016). Several algorithms are also used, such as Decision Trees, Genetic Algorithms, PageRank, and many others (Sanmorino, 2019).

**CONCLUSION AND RECOMMENDATIONS**

**DDoS is an attack that aims to deny a network service by overloading a server, distributed by several systems. Attackers are motivated by several goals, from small goals such as demonstrating a skill to big objectives such as gathering financial gains from the victim. DDoS prevention and mitigation are challenging, and several measures are already implemented, but does not completely prevent services from being attacked. Several actors involved in a DDoS attack should act in the interest of the DDoS targets. Recommendation for future research is to explore the effects of DDoS to the targets from various aspects, financially or psychologically.** Distributed Denial of Service (DDoS) attacks on website is a problem experienced by many website owners. Based on the survey conducted by Prasad et. Al. (2014), the motivations for conducting a DDoS attack varies, from amateur enthusiasts demonstrating their skills, to achieving larger objectives, such as financial gains or ideological mission. This problem is exacerbated by the Internet Service Providers having no motivations to address the issue (Lavrenovs, 2021). Current mitigation methods such as traceback is still insufficient to mitigate DDoS attacks due to the origin of attack is distributed through several machines, but several mitigation methods have been researched, such as Mitigating Real-time attacks using collections of datasets (Abubakar Et. al., 2020). Machine learning capabilities plays critical role in making suitable measures to limit DDoS attacks (Arshi et. Al., 2020). However, there are still a lack of research regarding the consequences of a DDoS attack to the actors involved in an attack.

**ACKNOWLEDGMENTS**

**REFERENCES**

A. Fakeeh, K. (2016). An Overview of DDoS Attacks Detection and Prevention in the Cloud. *International Journal of Applied Information Systems,* *11*(7), 25-34. doi:10.5120/ijais2016451628

Aamir, M., & Arif, M. (2013). Study and Performance Evaluation on Recent DDoS Trends of Attack & Defense. *International Journal of Information Technology and Computer Science,* *5*(8), 54-65. doi:10.5815/ijitcs.2013.08.06

Abubakar, R., Aldegheishem, A., Faran Majeed, M., Mehmood, A., Maryam, H., Ali Alrajeh, N., . . . Jawad, M. (2020). An Effective Mechanism to Mitigate Real-time DDoS Attack Using Dataset. *IEEE Access,* *8*, 126215-126227. doi:10.1109/access.2020.2995820

Alomari, E., Manickam, S., B. Gupta, B., Karuppayah, S., & Alfaris, R. (2012). Botnet-based Distributed Denial of Service (DDOS) Attacks on Web Servers: Classification and Art. *International Journal of Computer Applications,* *49*(7), 24-32. doi:10.5120/7640-0724

Arshi, M., Nasreen, M., & Madhavi, K. (2020). A Survey of DDoS Attacks Using Machine Learning Techniques. *E3S Web of Conferences,* *184*, 01052. doi:10.1051/e3sconf/202018401052

Azahari Mohd Yusof, M., Hani Mohd Ali, F., & Yusof Darus, M. (2018). Detection and Defense Algorithms of Different Types of DDoS Attacks. *International Journal of Engineering and Technology,* *9*(5), 410-444. doi:10.7763/ijet.2017.v9.1008

Chakraborty, S., Kumar, P., & Sinha, B., Dr. (2019). A Study on DDoS Attacks, Danger and its Prevention. *IJRAR,* *6*(2).

D, Y., M, S., Uvaze Ahamed, A. M., & S, N. (2019). Some Investigation on DDoS Attack Models in Mobile Networks. *International Journal of Interactive Mobile Technologies (iJIM),* *13*(10), 71. doi:10.3991/ijim.v13i10.11304

Lavrenovs, A. (2021). Towards Remediating DDoS Attacks. *Conference: 16th International Conference on Cyber Warfare and Security (ICCWS 2021)*.

Mahajan, D., & Sachdeva, M. (2013). DDoS Attack Prevention and Mitigation Techniques-A Review. *International Journal of Computer Applications*, *67*(19).

Mahjabin, S. (2018). Implementation of DoS and DDoS Attacks on Cloud Servers. *Periodicals of Engineering and Natural Sciences,* *6*(2), 148-158.

Osanaiye, O., Choo, K. K. R., & Dlodlo, M. (2016). Distributed denial of service (DDoS) resilience in cloud: Review and conceptual cloud DDoS mitigation framework. *Journal of Network and Computer Applications*, *67*, 147-165.

Prasad, K. M., Reddy, A. R., & Rao, K. V. (n.d.). DoS and DDoS Attacks: Defense, Detection and Traceback Mechanisms -A Survey. *Global Journal of Computer Science and Technology: E Network, Web & Security,* *15*(7).

Rajamannar, K., P, A., Suganya, R., & Pandi, V. (2020). Classifications of DDoS Attack - A Survey. *83*, 12926-12932.

Sanmorino, A. (2019). A Study for DDoS Attack Classification Method. *Journal of Physics: Conference Series,* *1175*, 012025. doi:10.1088/1742-6596/1175/1/012025

Somani, G., Gaur, M. S., Sanghi, D., Conti, M., Rajarajan, M., & Buyya, R. (2017). Combating DDoS Attacks in the Cloud: Requirements, Trends, and Future Directions. *IEEE Cloud Computing*, *4*(1), 22–32. https://doi.org/10.1109/mcc.2017.14

Tang, D., & Kuang, X. (2019). Distributed Denial of Service Attacks and Defense Mechanisms. *IOP Conference Series: Materials Science and Engineering,* *612*, 052046. doi:10.1088/1757-899x/612/5/052046

Tushir, B., Dalal, Y., Dezfouli, B., & Liu, Y. (2020). A Quantitative Study of DDoS and E-DDoS Attacks on WiFi Smart Home Devices. *IEEE Internet of Things Journal,* 1-1. doi:10.1109/jiot.2020.3026023

Wong, F., & Tan, C. X. (2014). A Survey of Trends in Massive DDoS Attacks and Cloud-Based Mitigations. *International Journal of Network Security & Its Applications,* *6*(3), 57-71. doi:10.5121/ijnsa.2014.6305

Wueest, C. (2014). The continued rise of DDoS attacks. *White Paper: Security Response, Symantec Corporation*.
