The new report prepared by experts at A10 Networks shows that IoT devices based on Machine-to-Machine communication are increasingly usable as attack sources.
A10 Networks (NYSE: ATEN), a company specializing in Application Visibility Performance and Security, has published the results of a new report on the current state of DDoS attacks, which shows the growing use of IoT devices in synchronized attacks on global targets. The report describes the potential for attackers to use an IoT-related protocol, the so-called Constrained Application Protocol (CoAP), deployed on IoT devices for systemic attacks.
The A10 Networks report on the main sources of DDoS weapons, in relation to the first quarter of 2019, analyzes the type of attacks and weapons that can be used and where they come from. The report highlights the fact that while the most popular types of weapons leverage other more established technologies and internet protocols such as Network Time Protocol (NTP), Domain Name System (DNS) resolvers and Simple Services Discovery Protocol (SSDP), CoAP-based devices represent a new type of weapon in the arsenals of botnet networks.
The most common type of attack that uses many of these weapons is an amplification attack reflective, through which attackers spoof a target's IP address and send requests for information to vulnerable servers, which then send amplified responses to the victim's IP address, completely eliminating the defense capabilities of the targeted server.
“DDoS attacks are increasing in frequency, intensity and sophistication,” he said Rich Groves, director of research and development of A10 Networks. "Malware-infected systems and vulnerable servers continue to generate particularly powerful attacks against vulnerable targets. The growth of IoT devices using protocols like CoAP represents a new, fast-growing attack area that we expect to play a major role in DDoS attacks in the future. Like other types of weapons, CoAP is inherently susceptible to IP address spoofing and packet amplification, the two main factors that enable the amplification of a DDoS attack."
CoAP is a Machine-to-Machine (M2M) protocol that can run on smart devices where memory and computing resources are scarce. The latest report from A10 revealed that over 400,000 weapons are used in the attacks.
Types and location of DDoS attack weapons sources.
A10 Networks report recorded approximately 22.9 million DDoS weapons in the first quarter of 2019:

- The first five types of weapons to monitor are: 1) DNS resolvers; 2) NTP-based weapons; 3) SSDP-based weapons; 4) SNMP (Simple Network Management Protocol) devices; 5) TFTP (Trivial File Transfer Protocol) devices.
- China is the first country in the world in terms of quantity of weapons hosted within it, followed by the United States, with 6,179,850 and 2,646,616 weapons tracked respectively. Other important host countries, in order of power, are Spain, Russia, the Republic of Korea, Italy and India.
“Having an always updated inventory of the millions of DDoS weapons is a fundamental part of any DDoS defense strategy” continues G

roves, highlighting the importance of DDoS weapons monitoring around the world. "By creating complete blacklists of suspected IP addresses, it is possible to activate countermeasures to block attacks in their tracks. To this end, A10 Networks, together with partners expert in identifying DDoS threats, analyzes the data emerging from the various investigations, tracks the activities of bot herders and scans the network to identify all possible weapons in real time.
In addition to comprehensive and constant monitoring through threat intelligence, A10 Networks is a driver of innovation in DDoS detection and mitigation solutions. The company recently further enhanced its Thunder® 14045 Threat Protection System, which offers industry-leading attack mitigation capabilities. These new capabilities deliver the highest performance on the market with 500 Gpbs of defense in a single device. The smaller form factor reduces the number of devices needed, while creating scalable DDoS defenses that effectively meet the challenge of new attacks.




