DDoS attacks continue to grow as 25 of the attacks in the first quarter of 2015 globally were larger than 100 Gbps, according to the latest statistics from DDoS mitigation company Arbor Networks.
The majority of recent attacks used a reflection technique to amplify them using the Network Time Protocol (NTP), Simple Service Discovery Protocol (SSDP), and DNS servers.
SSDP attacks with enhanced reflection have become all the rage. In Q1 2015 we had 126,000 such attacks, up from 83,000 in Q4 last year and just three in Q1 2014. The largest attack reached 138Gbps
Enhanced Reflection is a technique that allows an attacker to magnify the amount of traffic they can generate, while also being able to hide the source of the attack.
The tactic relies on the lack of protection of Internet-connected devices that provide UDP services. Sending a fake request with a spoofed address to the target creates a response, much larger in size than the original request. These requests are directed to the main target, which is overwhelmed by legitimate requests.

The technique is possible because many service providers still do not implement filters on their network that can block traffic from "fake" IP addresses.
The largest size record was already broken in 2015 by an attack in India that reached 334Gbps, surpassing the previous record of 325Gbps. The US is home to the most targets of such attacks, more than any other single country.
Attacks are generally getting shorter in duration, but their intensity is immense. The majority of attacks (about 90%) last less than an hour.
“DDoS attacks that have an intensity of over 200Gbps can be extremely dangerous for network operators and can cause collateral damage to all services, such as cloud hosting and enterprise networks,” said Darren Anstee, a technician at Arbor Networks.
Arbor Networks ' statistics come from the company's ATLAS service, which monitors about a third of all internet traffic from 330 customers, mainly telephone companies and ISPs.
Source: secnews.gr

