Hi everyone, my name is Osman Celik. I'm a Research Analyst at KuppingerCole. Today I'm joined by Andrey Leskin from Qrator Labs.
Hi Andrey, how are you doing? Hello, thank you. It's such a pleasure to be here.
Yeah, same here. So today we are going to have a small chat about DDoS attacks. This is going to be our main theme of today. We will discuss what are the DDoS attacks, and how is the DDoS attack landscape look like currently, and what are the trends. And we are also going to discuss a bit what Qrator Labs bring to the table. And I'm excited to see what Andrey has to share with us, and I will also share my insights when time allows.
Cool, I'm looking forward to that. Yeah, so yeah, I have to give this introduction for those people who are very keen on understanding, because I know that nowadays people just quickly go through the videos, right Andrey? So maybe they just wanted to see what we are talking about in the beginning.
But you know, I think that our audience should be from every stakeholders, from different departments, and maybe we should already give them a quick introduction, like for example, what are the DDoS attacks, what are the difference between the layers, and maybe which one of them actually address specifically. So maybe we can talk about it in general a bit. That's a great question, and let's set up a foundation so we can continue later. So with the technical foundations, we have different layers where attacks are going to affect your infrastructure.
There are seven layers, we're going to talk about three of them, number three, four, and seven. And what are these so-called layers? Layer number three is the IP network layer, where your routing decisions happen, and where we see most massive bandwidth attacks like UDP amplification and IP floods and so on. Layer four is the layer above that with some specific details, it's transport layer, and TCP and UDP protocols, mostly connections. So the HTTP3 works on UDP, HTTP1 and HTTP2 works on TCP, and there are lots of other layer seven that I'm going to talk later that work over there.
And here we have lots of connection exhaustion attacks or TCP-related or UDP-related attacks here. Last but not least, layer seven, it's the application layer where you have your actual business logic and dealing with lots of HTTP requests or sophisticated attacks. And these attacks are usually mimicking the legitimate user behavior. And going there, we have the landscape over here changed through the years. So initially, for example, maybe four or five years ago, so-called sin floods attacks or spoofed attacks were very, very often.
And nowadays we see them quite rarely, but they're still present nowadays. But mostly it's due to community and organizations who now, most of them implemented BCP38 recommendation from the community. And this essentially means they started blocking spoofing traffic that is going to affect your infrastructure. And this created sort of cascading effect across the threat landscape. So nowadays internet service providers start filter spoofing IP addresses, and so we need to deal with network layer attacks and application layer attacks mostly.
But sin floods evolved into TLS, like SSL and TLS-related attacks. So this, you have TCP connection and over a TCP connection, you have a TLS connection, an encrypted one. And this protocol has some vulnerability, well, not vulnerabilities, but there are some resources involved that are quite easy to exhaust by the attacker. So if we are talking about layer seven and its evolution, nowadays, these kinds of attacks represent even more significant of a threat and they are becoming the preferred method for the most sophisticated attacks for three critical reasons.
These are accessibility, stealth, and cost effectiveness. First of all, the tools needed to craft effective layer seven attack are widely available and available more than ever.
Second, these attacks are incredibly difficult to detect because they mimic legitimate user behavior. And instead of sending obviously malicious traffic, attackers send what appears to be normal HTTP request, normal API calls on normal user interactions.
Third, you can cause significant damage with relatively few resources. Instead of needing massive botnets to overwhelm network capacity, you can target specific vulnerabilities with much smaller, more focused attack. And vectors of attacks are quite different. So you have denial of service, distributed denial of service, you have different vulnerabilities of your application, you have damages caused by data scraping that is going to cost you money as well. So this is concerning, but this is not the end. And nowadays, attackers aren't just targeting your front door anymore.
They're studying your entire business ecosystem and going after the weakest links in your supply chain. Well, for example, you have an e-commerce company that protects its main website perfectly. But if attackers target the payment gateway or the connection to the banking system, customers can browse your site, but they can't make any purchases. And from a business perspective, this is often more damaging than having your website temporarily down.
Well, I know I was also looking at the maybe resources to see actually what is changing in the landscape also. And I've seen that the attacks are down by 74% year over year. So it's quite a good indicator for why we should be aware and why we should be careful with the layer 7 attacks, such as HTTP floods, maybe. These are one of the prominent ones. But I also noticed that last month, actually June 2025, two months ago, we had one of the biggest layer 3, 4 volumetric attacks that was mitigated by Cloudflare. So what is your take on this?
And then do you think that we should also expect some record-breaking attacks targeting application layer? Definitely. This is definitely the case. We see record-breaking attacks year by year. So every year is something new. And nowadays, the biggest volumetric attacks are over one to like, this is terabits per second. And this is not a rare exception anymore. It's our new reality. And what's perhaps most alarming is the persistence of these attacks. If recently, last year, two years ago, we have attacks that lasted for three days.
Nowadays, they can last for maybe weeks. And that's really concerning. And speaking of records and different personal, let's call it personal records, behind these massive attacks and behind layer 7 massive attacks are increasingly powerful botnets. For example, the one that we encountered twice this year.
First, we saw it in February and it has 1.5 million compromised devices. So we investigated this attack, made some decisions. So when we saw this botnet for the second time, it broke our record because in the end, we had 4.5, 4.6 million of compromised devices. And it evolved in waves. So the first wave were approximately 2 million devices. Then when attackers saw that there is no effect on that, they added another 1.5 million. And the third wave, they probably sent everything they could, like mobilize everything they have left. And the geographic distribution is telling.
The vast majority originates from South America with Brazil alone, alone contributing 1.3 million devices. And this fits perfectly into our predictions, our like black magic ball that we established. And it tells that developing regions becoming gold mines for botnet requirements because they have excellent connectivity, but they unfortunately lack expertise in cybersecurity and upgrading their software and so on. And what specifically makes this botnet particularly dangerous is its versatility. It's capable of multiple attack types simultaneously.
So sophisticated HTTP requests, floods, at the application layer, then TCP garbage floods to exhaust connection resources, and connection and TLS handshake floods as well to overwhelm network infrastructure. And aside and add to that, you with like 4 or 5 million devices, you can generate like a massive bandwidth so you can easily overwhelm your network capacity. And in the light of these events, I mean, I think you can also observe what the end users are doing. What are each industries are heading to?
Could you maybe also give us some of your insights regarding your customers base and then what they are trying to achieve? And then what are the motivations of these end users to mitigate this kind of DDoS attacks? And maybe you can tell me some of the recent cases you have encountered among your customers.
Well, this is the most significant case I have just told you about. But speaking of our customers and target landscape nowadays, based on our statistics, now we have like almost quarter of the attacks are targeted towards financial sectors, so fintech companies and so on. Then it follows by e-commerce, where about 20%. And the third place takes media companies. This is like 13 for 15%. And this is not coincidence. These sectors where downtime translates directly to loss revenue and damaged customer trust. So there are some estimations based on like how much damage did the attack made to you.
So it's like maybe estimates from hundreds of thousands, like millions of revenue per hour. And this is not including the long-term damage to customer trust and brand reputation. And for fintech companies, especially the impact can be even higher due to regulatory compliance issues and critical nature of financial services. I know that you also generate reports based on this DDoS and bot attacks. And I assume that you share them with your customers, right? And what are the feedbacks they give you? Do you think that they can benefit from what Curator Labs offer them on top of your solution?
Because I know that you release monthly reports. We do. And this is what we do for community and to make our world a better place so everyone can access it and get some insights on the current level. Maybe this is just an idea.
Maybe, you know, one thing could be beneficial for this, such attacks is maybe kind of categorizing the attacks and then showing which industries are targeted and then which industry should be aware of more about which DDoS attacks more. So I think that this is something that will be useful for the end users, right? Because then, for example, when we think about the financial sector, the DDoS attacks that are targeting them might be very different than a company using OT services, for example, or OT platforms. So maybe this is just one of my insights that I could share with you.
And more about the DDoS types, I know that this application layer is the one that we are talking the most. But why do you think that we are switching from like layer three, layer four focus, from like a layer three, layer four focus to layer seven focus? Because you think that the application layer is more under danger than the networks nowadays? Because I was trying to understand this lately.
For me, networks are always like the layers that we should be trying to secure the most. But then I see this layer seven buzz everywhere. Maybe you could maybe clarify this with a couple of sentences. Why everyone is putting more emphasis on the layer seven, basically?
Well, in general, all these layer three and layer four network layers are well studied. They were invented quite like a long time ago and nothing changes since then.
Well, it's not quite true. There are some changes, but mostly over the years, the principle and the attacks are the same. On the other hand, layer seven is your application. It's your business logic. So we have lots of millions and trillions of companies all over the world. They have separate business logic. And attacker looking at this logic can find some vulnerabilities targeted specifically at your application and get it down due to that. This attack will work specifically for you, but it won't work for your competitor or any other company in the world.
So these tailor-made attacks are what make layer seven stand out. I got it. And one of the things I think that the end user is mostly concerned about is the mitigation of them. When I was doing my last research, you were also involved in the research, as you know. So one of the things that the customers are wondering, what are the differences between a scrubbing capacity and POP proximity?
This is, I think, an ambiguous topic for some of the customers trying to understand, especially when they are procuring a DDoS mitigation tool, let's say. Could you maybe give us your take on this? It's easy probably for you, but yeah, just for clarification.
Well, for clarification, these are one of the foundations that we talked earlier, but not these technical ones. So this is a fundamental distinction that many organizations don't fully grasp. So in a few words, scrubbing capacity refers to the volume of traffic that your protection system can process, analyze, and filter simultaneously.
So, for example, think of it as the size of your security checkpoint at an airport. How many passengers can you screen at the same time? The scale of the attack, let's say, right? That's about the scale of the attack. And the proximity, especially the point of presence proximity, is about the geographic distance between your protection infrastructure and your end users, like users of your customers. So this would be like having a small branch of your security checkpoint close to the specific location where a bunch of people are sitting there and they want to pass the security.
Somehow, I don't know how it's going to work regarding security. But with the proximity and the latency, it works like that. So the complex trade-off for that is if you increase your proximity, you most likely create bottlenecks in your scrubbing capacity and vice versa. The biggest scrubbing capacity is located in the internet exchanges, in the tier one operators, like the huge companies, but they are located in a couple of places, maybe quite far away from your end user. And actually, in the beginning, I think we both forgot to mention that you're located in Czech Republic.
And we know for a fact that you have a strong market presence in Eastern Europe. Can you maybe relate your scrubbing capacity and POPs, especially in Europe? Maybe is it something, a USP for your company that you might have this POP? POP is located in the close proximity of your end users, which is kind of, at the end, enabling a speed and more efficient mitigation of DDoS attacks and at the end, yielding clearer traffic.
Well, at Curator Labs, we design our infrastructure to optimize both of these factors. And we have to maintain high scrubbing capacity at strategically located points of presence worldwide. And in Europe, it's globally three major points where the separate branches where we need more precise proximity to our users. And our network is designed so that traffic doesn't have to travel excessive distances in general for protection. So each location has significant capacity to handle the largest attacks we have documented. And we have some estimates for the attack that can happen there.
And we have to have some scrubbing capacities to mitigate that as well. So this balanced approach means that during normal operations, your users expertise minimal latency. But when an attack occurs, we have assessing power to analyze and filter most massive attacks without degrading your user experience. Perfect. And maybe last question, where are your POPs located actually?
Well, we have points of presence in both Americas, North and South America. We have in Europe, to say specific, it's Frankfurt, Paris and Amsterdam and different location in like a couple of points of presence across these locations. We are present in the Asia as well and the Middle East. So we have points of presence all over the world. We work worldwide.
And maybe, yeah, we're getting close to the end of our webinar. Maybe you could mention a couple of other USPs that we should maybe highlight about Curator Labs and maybe we can then try to end our conversation. We tailor our protection mechanisms to our customer. So we just don't tell them that you have to use this one, this resource, this service and here you have to take something on premise to filter.
No, we just provide everything there. And we look closely at our customer application and adapt our filtration mechanisms based on your application behavior. So if it works normally, we usually do not interfere. But if we see it degrades or we see a massive spike in your traffic, so here we have to take some action. And our technical approach here combines multiple sophisticated layers for web application. We provide some different web application firewall protection, maybe some anti-bot for data scraping that might be of your concern.
And of course, there's DDoS mitigation when you have lots of HTTP requests that you have to mitigate. These are probably three different vectors that we have to address and we do mitigate them. And for our customers, we are just a single point of truth. So we do not force our customers to run around during the attack when nothing works and you have to make it work and you run around from vendor to vendor asking questions, trying to debug the solution.
No, no, no. You just come to us, straight to us, tell us the problem and we solve it usually. And apart from that, we understand that cybersecurity and mitigation, DDoS mitigation is not just a check mark in your sort of list. It's more of a process. And here we understand this and this is not just a set up and forget solution. It's a process that must evolve alongside your business. And as your business grows and your infrastructure configuration changes, your attack surface evolves as well. And DDoS mitigation have to evolve with it.
And this process usually requires mutual effort and this is where having a single provider becomes invaluable. Instead of coordinating across multiple vectors, you have one team that responds to you like 24-7 with real technical engineers on the other side.
Yeah, perfect. And then I know that lately we have been collaborating a lot on DDoS topic especially. We had a webinar a couple of months ago and we have an upcoming leadership compass on web application and API protection tools, which also includes Curator Labs.
Actually, it's going to be published in a couple of days. Maybe when this video is live, maybe you'll be able to have an access down below in the link. And then also you also have an access to other links we can provide you.
Well, I'm glad to have you here today, Andrei. And if you don't have any other final words, then I think that we can end our conversation today.
Well, let me just add some closing remarks. So the DDoS landscape is more complex and dangerous than ever before. It's like year to year, it's a mantra. And but with the right approach, understanding your infrastructure, implementing comprehensive ecosystem protection, and working with partners who view security as an evolving process rather than a static product, organization can build robust defenses against the most sophisticated attacks. Thank you very much, Osman. It's such a pleasure. Likewise.
Yeah, it was my pleasure, man. Yeah. Thank you very much. Thank you.