TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

F5 Labs

Denial-Of-Service and Password Login Attacks Top Reported Security Incidents, 2018-2020

2021-03-23 · Read original ↗

ATT&CK techniques detected

13 predictions
T1110.004Credential Stuffing
82%
“by year, as shown in figure 6. figure 6. password login attacks as a percentage of all reported f5 sirt incidents ( 2018 - 2020 ). accounting for the slight dip in 2019, password login attacks account for 32 % of all reported sirt incidents over the past three years. we also saw …”
T1498Network Denial of Service
72%
“incidents reported in 2020. figure 7. dos attacks as a percentage of all reported f5 sirt incidents ( 2018 - 2020 ). most dos attacks are network volumetric floods, which are commonly tcp syn or udp floods. f5 sirt also receives reports of “ slow post / slowloris ” attacks, which…”
T1498.001Direct Network Flood
60%
“a food service organization? the attackers weren ’ t after tasty fried dough but stored - value gift cards, which are fungible instruments easily sold on darknet markets. this made dunkin ′ donuts look a lot more like a financial organization to attackers than a restaurant or ret…”
T1499Endpoint Denial of Service
58%
“and japan ( apcj ) had the highest percentage ( 57 % ) of reported denial - of - service ( dos ) attack incidents, followed by organizations based in europe, the middle east, and africa ( emea ) at 45 %. - financial service organizations had the highest percentage ( 46 % ) of rep…”
T1110.003Password Spraying
54%
“in apcj and emea, while u. s. / canada only grew slowly. latam dodged the bullet and did not suffer enough dos attacks to calculate a significant trend line. f5 sirt incidents by industry sector breaking this data out by industry sector reveals some interesting differences. looki…”
T1110.004Credential Stuffing
53%
“services organization to know if a consumer is reusing their password somewhere else, especially somewhere with weaker security. what we ’ re seeing is attackers concentrating their efforts on seeking out the weakest link. new york puts organizations on notice about credential st…”
T1498.001Direct Network Flood
49%
“incidents reported in 2020. figure 7. dos attacks as a percentage of all reported f5 sirt incidents ( 2018 - 2020 ). most dos attacks are network volumetric floods, which are commonly tcp syn or udp floods. f5 sirt also receives reports of “ slow post / slowloris ” attacks, which…”
T1498Network Denial of Service
43%
“and japan ( apcj ) had the highest percentage ( 57 % ) of reported denial - of - service ( dos ) attack incidents, followed by organizations based in europe, the middle east, and africa ( emea ) at 45 %. - financial service organizations had the highest percentage ( 46 % ) of rep…”
T1498Network Denial of Service
42%
“a food service organization? the attackers weren ’ t after tasty fried dough but stored - value gift cards, which are fungible instruments easily sold on darknet markets. this made dunkin ′ donuts look a lot more like a financial organization to attackers than a restaurant or ret…”
T1498.001Direct Network Flood
40%
“and japan ( apcj ) had the highest percentage ( 57 % ) of reported denial - of - service ( dos ) attack incidents, followed by organizations based in europe, the middle east, and africa ( emea ) at 45 %. - financial service organizations had the highest percentage ( 46 % ) of rep…”
T1499Endpoint Denial of Service
38%
“denial - of - service and password login attacks top reported security incidents, 2018 - 2020 the f5 security incident response team ( f5 sirt ) helps customers tackle security incidents in real time. in 2020, we wrote about what happened in the beginning of the pandemic based on…”
T1498Network Denial of Service
35%
“denial - of - service and password login attacks top reported security incidents, 2018 - 2020 the f5 security incident response team ( f5 sirt ) helps customers tackle security incidents in real time. in 2020, we wrote about what happened in the beginning of the pandemic based on…”
T1499Endpoint Denial of Service
31%
“a food service organization? the attackers weren ’ t after tasty fried dough but stored - value gift cards, which are fungible instruments easily sold on darknet markets. this made dunkin ′ donuts look a lot more like a financial organization to attackers than a restaurant or ret…”

Summary

Three years of reported security incidents shows continued growth in denial-of-service and password login attacks such as brute force and credential stuffing.