CNS Corero Network Security

Short, Stealthy, Sub-Saturating DDoS Attacks Pose Greatest Security Threat to Businesses

The greatest DDoS risk for organisations is the barrage of short, low volume attacks which mask more serious network intrusions, according to the latest DDoS Trends and Analysis report from Corero Network Security (LSE: CNS), a leading provider of real-time DDoS defense solutions.

According to new Corero research, which highlights DDoS attack attempts against its customers, short, frequent, low-volume DDoS attacks continue to dominate. Despite several headline-dominating, high-volume DDoS attacks over the past year, the vast majority (98%) of the DDoS attack attempts against Corero customers during Q1 2017 were less than 10 Gbps per second in volume. In addition, almost three quarters (71%) of the attacks mitigated by Corero lasted 10 minutes or less.

Due to their small size, these sub-saturating attacks tend to go undetected by IT security staff and many DDoS protection systems. However, they are just disruptive enough to knock a firewall or intrusion prevention system (IPS) offline so that the hackers can target, map and infiltrate a network to install malware and engage data exfiltration activity.

Ashley Stephenson, CEO at Corero Network Security, explains: “Short DDoS attacks might seem harmless, in that they don't cause extended periods of downtime. But IT teams who choose to ignore them are effectively leaving their doors wide open for malware or ransomware attacks, data theft or other more serious intrusions. Just like the mythological Trojan Horse, these attacks deceive security teams by masquerading as a harmless bystander – in this case, a flicker of internet outage – while hiding their more sinister motives.”

Sub Saturating DDoS Attacks: The Calm Before The Storm

In total, Corero customers experienced an average of 124 DDoS attack attempts per month, equivalent to 4.1 attacks per day during Q1 of 2017. This is a 9 percent increase in attacks over Q4 2016.

Stephenson continues: “Rather than showing their capabilities in full view, through large, volumetric DDoS attacks that cripple a website, using short attacks allows bad actors to test for vulnerabilities within a network and monitor the success of new methods without being detected. Most cloud-based scrubbing solutions will not detect DDoS attacks of less than 10 minutes in duration, so the damage is done before the attack can even be reported.”

“As a result, the raft of sub-saturating attacks observed at the beginning of this year could represent a testing phase, as hackers experiment with new techniques before deploying them at an industrial scale.”

While low volume attacks remain the norm, Corero recorded a significant (55%) increase in large DDoS attacks of more than 10 Gbps per second, in Q1 of 2017, compared to the previous quarter. In addition, while the majority of attacks recorded lasted less than 10 minutes, the data also revealed a slight increase in attacks lasting 20 minutes or longer, with these attacks now accounting for nearly a quarter (22%) of all the attacks recorded.

Increased Risks For EU General Data Protection Regulation (GDPR)

From May 2018, any organization that operates in Europe or has European resident data could be subject to severe penalties of up to 4 percent of global turnover if they fail to protect the data of EU residents.

Stephenson states: “With GDPR on the horizon, the risk of data theft resulting from sub-saturating DDoS attacks is extremely serious, and claiming to be ignorant of malicious activity on your network will not substitute a defence. To keep up with the growing sophistication and organization of well-equipped and well-funded threat actors, it’s essential that organizations maintain a comprehensive visibility across their networks to detect and block any potential DDoS incursions as they arise.”

For access to the complete Corero DDoS Trends report, download it here.

About Corero Network Security

Corero Network Security is the leader in real-time, high-performance DDoS defense solutions. Service providers, hosting providers and online enterprises rely on Corero’s award winning technology to eliminate the DDoS threat to their environment through automatic attack detection and mitigation, coupled with complete network visibility, analytics and reporting. This industry leading technology provides cost effective, scalable protection capabilities against DDoS attacks in the most complex environments while enabling a more cost effective economic model than previously available. For more information, visit www.corero.com.

EN
05/06/2017

Underlying

To request access to management, click here to engage with our
partner Phoenix-IR's CorporateAccessNetwork.com

Reports on Corero Network Security

Hybridan Team ... (+2)
  • Hybridan Team
  • Jon Levinson

Hybridan Small Cap Feast

12th January 2026 @HybridanLLP Happy New Year! Wishing all our readers a happy and prosperous 2026 Our daily digest of news from UK Small Caps * A corporate client of Hybridan LLP. ** Potential means Intention to Float (ITF) or similar announcement has been made. ***Arranged by type of listing and date of announcement. ****Alphabetically arranged and priced on Share Price and Market Capitalisation during the time of writing on the day of Publ...

Bob Liao ... (+2)
  • Bob Liao
  • Carl Smith

Corero Network Security (CNS LN) - Strong close to FY25 - Corporate

Corero has issued a FY25 trading update showing a strong close to the year, with EBITDA well ahead of our expectations. Positive momentum generated in Q2 2025 has continued throughout the second half of FY25, with ARR growing by an impressive 23% in the year. We increase FY25 adjusted EBITDA forecast from a $1.3m loss to $1.0m profit. Our FY26 P&L estimates are unchanged, which are now likely conservative given the recent strong momentum. In our view, Corero has a superior and well-invested prod...

Hybridan Team ... (+2)
  • Hybridan Team
  • Jon Levinson

Hybridan Small Cap Feast: 05 November 2025

* A corporate client of Hybridan LLP. ** Potential means Intention to Float (ITF) or similar announcement has been made. ***Arranged by type of listing and date of announcement. ****Alphabetically arranged and priced on Share Price and Market Capitalisation during the time of writing on the day of Publication. Dish of the Day Admissions: Princes Group (PRN.L) a leading international platform in the UK and European food and beverage sector, announced the commencement of unconditional deal...

Hybridan Team
  • Hybridan Team

Hybridan Small Cap Feast: 16/09/2025

Our daily digest of news from UK Small Caps 16th September 2025 @HybridanLLP * A corporate client of Hybridan LLP. ** Potential means Intention to Float (ITF) or similar announcement has been made. ***Arranged by type of listing and date of announcement. ****Alphabetically arranged and priced on Share Price and Market Capitalisation during the time of writing on the day of Publication. Dish of the day Admissions: None Delistings: N...

Bob Liao ... (+2)
  • Bob Liao
  • Carl Smith

Corero Network Security (CNS LN) - Interim results - Corporate

Corero’s H1 results were well flagged during the July trading update (see research) and showcase the transition towards a higher quality revenue stream with ARR +25% yoy to $21.6m. The lengthening of sales cycles and delays to customers decisions in light of macro uncertainty has, however, weighed on the Group’s upfront license deals in H1, contributing to an 11% fall in Group revenue yoy. The shift in customer behaviour from capex deals towards opex deals is positive, in our view, and should im...

ResearchPool Subscriptions

Get the most out of your insights

Get in touch