August 15, 2026 04:02 am (IST)
Follow us:
facebook-white sharing button
twitter-white sharing button
instagram-white sharing button
youtube-white sharing button
Ajit Doval breaks silence on Operation Sindoor in Discovery’s explosive new docuseries | Rahul Gandhi's 'mock hug' taunt sparks row; Centre stresses 'mutual respect' with Italy | Delhi on high alert: Bomb threat to High Court, airport and multiple locations ahead of I-Day | ‘Who are they to interfere?’: CJI Surya Kant slams Bar Council of India over NALSAR students’ enrolment row | 'Shows how low Congress has sunk': BJP slams Rahul Gandhi over Modi foreign policy jibe | From guns to glamour: Former women Maoists walk the ramp in Chhattisgarh | Netaji row: Suvendu Adhikari govt strips BJP MP Anant Maharaj of state honour | Sukhbir Badal attacked by Nihang Sikh with kirpan at Maharashtra gurdwara; assailant detained | ‘If you cannot do it, we will pass an order’: Supreme Court’s final warning to Centre on food labels | ‘Time to move on’: Bombay HC sends strong message in Vijay Mallya-bank dispute

Arbor reports spike in DDoS attack driven by NTP

| | Apr 29, 2014, at 07:04 pm
Bangalore, Apr 29 (IBNS): Software company providing network security, Arbor Networks Inc., on Tuesday noted an unprecedented spike in volumetric attacks, driven by the proliferation of Network Time Protocol (NTP) reflection/amplification attacks.

Arbor, the provider of distributed denial-of-service (DDoS) and advanced threat protection solutions for enterprise and service provider networks, on Tuesday released the global DDoS attack data derived from its Active Threat Level Analysis System (ATLAS) threat monitoring infrastructure.

NTP is a User Datagram Protocol (UDP)-based protocol used to synchronize clocks over a computer network.

Arbor noted that any UDP-based service including DNS, SNMP, NTP, chargen, and RADIUS is a potential vector for DDoS attacks because the protocol is connectionless and source IP addresses can be spoofed by attackers who have control of compromised or ‘botted’ hosts residing on networks which have not implemented basic anti-spoofing measures.

NTP is popular due to its high amplification ratio of approximately 1000x. Furthermore, attacks tools are becoming readily available, making these attacks easy to execute, the company said.

Arbor said that ATLAS is a collaborative partnership with nearly 300 service provider customers who share anonymous traffic data with the company in order to deliver a comprehensive, aggregated view of global traffic and threats.

ATLAS collects 80TB/sec of traffic and provides the data for the Digital Attack Map, a visualization of global attack traffic created by Google Ideas.

The global DDoS attack data stated that the average NTP traffic globally in November 2013 was 1.29 GB/sec, by February 2014 it was 351.64 GB/sec.

The report said that the NTP was used in 14 percent of DDoS events overall, but 56 percent of events over 10 GB/sec and 84.7 percent of events over 100 GB/sec.

Arbor noted that US, France and Australia were the most common targets overall, while US and France were the most common targets of large attacks.

Arbor Networks Director of Solutions Architects Darren Anstee said, "Arbor has been monitoring and mitigating DDoS attacks since 2000. The spike in the size and frequency of large attacks so far in 2014 has been unprecedented."

"These attacks have become so large, they pose a very serious threat to Internet infrastructure, from the ISP to the enterprise," Anstee said.

Support Our Journalism

We cannot do without you.. your contribution supports unbiased journalism

IBNS is not driven by any ism- not wokeism, not racism, not skewed secularism, not hyper right-wing or left liberal ideals, nor by any hardline religious beliefs or hyper nationalism. We want to serve you good old objective news, as they are. We do not judge or preach. We let people decide for themselves. We only try to present factual and well-sourced news.

Support objective journalism for a small contribution.