
Security firm Incapsula's annual "DDoS Threat Landscape Report" reveals that distributed denial-of-service (DDoS) attacks can lead to financial losses of $40,000 per hour, theft of sensitive data, and loss of intellectual property.
“Today, given that a large proportion of attacks last for days and attacks against specific targets are half as repetitive, a hit can result in losses of hundreds of thousands – if not millions – of dollars,” the researchers report.
According to the report's findings, hiring specialized botnets to carry out DDoS attacks has now become easier and less expensive, with the average cost reaching $38/hour, and botnets are now responsible for 40% of all attacks carried out at the network level.
The infographic below presents the main findings of the report in detail:
Incapsula's analysis also highlights two interesting, yet conflicting, trends in both network-layer and application-layer DDoS attacks:
On the one hand, there are complex, multi-phased, and long-lasting attacks, similar to advanced persistent threats (APTs). Attacks of this type utilize various methods and can last for days, weeks, or even months. On the other hand, there are short and rudimentary attacks, which usually last no more than 30 minutes. This type of attack is dominant in the modern DDoS threat landscape.
According to the researchers, the above types of attacks point to two basic archetypes of perpetrators: the first is professional cybercriminals, while the second is “botnet-for-hire” service providers, who rent out the so-called “booters” or “stressers” to interested parties. This subscription-based model of carrying out DDoS attacks offers anyone the ability to launch multiple, short-term DDoS attacks for just a few tens of dollars per month.

