DDoS Attacks on the Rise, but Education Networks Largely Spared

In the first half of 2021, dedicated denial of service (DDoS) attacks were up by double digits. But somehow schools, colleges and universities, despite being favorite targets for ransomware and various other forms of malware, have been by and large overlooked — even as DDoS becomes a companion tool in ransomware incidents.

According to a report released this week by network security company NetSCOUT, everything about DDoS attacks increased in the first half of the year:

  • The total number of attacks increased to 5.35 million, up 11 percent  over the same period last year;

  • The average duration increased to 50 minutes, up 31 percent;

  • The largest attack in terms of bandwidth was 1.5 Tbps (against a German ISP), up 169 percent over the largest attack in the first half of last year; and

  • The fastest attack was 675 Mpps (million packets per second), targeted at a Brazilian broadband user and likely related to online gaming, up 16.17 percent.

In total there were four terabit-class DDoS attacks (none of them against a target in the United States).

According to the report, DDoS is increasingly being used as part of ransomware (as well as stand-alone extortion) campaigns, with actors using encryption and data theft, then adding more pressure on the IT/security organization through DDoS.

Amid all of this, however, the report noted that education didn't even crack the top 10 as a target. In addition, education (including both K–12 and higher ed) made up less than a third of a percentage point of all bottled nodes (defined as "devices/systems that have been compromised by malicious bot software") used in DDoS attacks in the first half of the year (0.3 percent), well behind businesses (at 4.47 percent), hosting services (8.45 percent), mobile (11.57 percent) and ISP (75.22 percent).

According to the report: "This is probably due to more stringent control over what devices are allowed on the network in these institutions. The top three source network profiles were ISP, mobile, and hosting, where device control is nearly nonexistent. That lack of control means that those ISP and mobile numbers really represent compromised subscribers."

The complete report, the NetSCOUT Threat Intelligence Report 1H 2021, which includes many additional statistics, best practices and further explanations of attack vectors and operating systems, can be found on NetSCOUT's site and is available in both interactive versions and static PDFs.

About the Author

David Nagel is the former editorial director of 1105 Media's Education Group and editor-in-chief of THE Journal, STEAM Universe, and Spaces4Learning. A 30-year publishing veteran, Nagel has led or contributed to dozens of technology, art, marketing, media, and business publications.

He can be reached at [email protected]. You can also connect with him on LinkedIn at https://www.linkedin.com/in/davidrnagel/ .


Featured

  • Two autonomous AI figures performing tasks in a tech environment; one interacts with floating holographic screens, while the other manipulates digital components

    Agentic AI Named Top Tech Trend for 2025

    Agentic AI will be the top tech trend for 2025, according to research firm Gartner. The term describes autonomous machine "agents" that move beyond query-and-response generative chatbots to do enterprise-related tasks without human guidance.

  • sleek fishing hook with a translucent email icon hanging from it

    Report Identifies Rise in Phishing-as-a-Service Attacks

    Cybersecurity researchers at Trustwave are warning about a surge in malicious e-mail campaigns leveraging Rockstar 2FA, a phishing-as-a-service (PhaaS) toolkit designed to steal Microsoft 365 credentials.

  • person signing a bill at a desk with a faint glow around the document. A tablet and laptop are subtly visible in the background, with soft colors and minimal digital elements

    California Governor Signs AI Content Safeguards into Law

    California Governor Gavin Newsom has officially signed off on a series of landmark artificial intelligence bills, signaling the state’s latest efforts to regulate the burgeoning technology, particularly in response to the misuse of sexually explicit deepfakes. The legislation is aimed at mitigating the risks posed by AI-generated content, as concerns grow over the technology's potential to manipulate images, videos, and voices in ways that could cause significant harm.

  • abstract technology icons connected by lines and dots

    Digital Layers and Human Ties: Navigating the CIO's Dilemma in Higher Education

    As technology permeates every aspect of life on campus, efficiency and convenience may come at the cost of human connection and professional identity.