Cloudflare has published statistics on the nature of traffic processed by its content delivery system from April 1, 2023, to March 31, 2024. Over the year, the share of suspicious, malicious, or spammy HTTP traffic that was blocked or redirected to verification pages for bot filtering (JavaScript checks or CAPTCHA) increased from 6% to an average of 6.8%. Peaks of such traffic reached 12% on certain days.
53.9% of the blocked or redirected traffic for further verification is attributed to malicious activity, attempted attacks, and bot activity, 37.1% to DDoS attack traffic, and 7.2% to requests from (the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community., which have poor reputations and are blacklisted.
While DDoS attacks remain the most popular type of web application attack that causes denial of service, there is an observed increase in attacks targeting the exploitation of unpatched vulnerabilities. Administrators are advised not to delay in installing updates that address critical vulnerabilities, as such attacks are becoming increasingly rapid. For instance, the JetBrains TeamCity product was attacked just 22 minutes after a prototype exploit for the unpatched vulnerability CVE-2024-27198 was publicly available, allowing access without authentication. Among the most active attacks are attempts to exploit vulnerabilities in Apache Struts (CVE-2023-50164), Apache Spark (CVE-2022-33891), Adobe ColdFusion (CVE-2023-29298, CVE-2023-38203, CVE-2023-26360), and MobileIron (CVE-2023-35082).
31.2% of all traffic is associated with bot activity, of which only 7% of bot requests are generated by known legitimate services such as search engines, while the remaining 93% are categorized as unknown bots that could potentially engage in malicious activities.
Trends also indicate an increase in traffic related to requests to Web APIs that return responses in JSON or XML formats. The share of such requests has reached 60% of all dynamically generated (non-cachable) traffic. According to Cloudflare, one-third of API requests are linked to 'shadow' API handlers, which are not accounted for by organizations (not explicitly presented as publicly available Web APIs) and are not adequately secured.
On average, Cloudflare's corporate clients use 47 third-party scripts in their web services. The most popular third-party script providers include Google (Tag Manager, Analytics, Ads, Translate, reCAPTCHA, YouTube), Meta (Facebook Pixel, Instagram), Cloudflare (Web Analytics), jsDelivr, New Relic, Appcues, Microsoft (Clarity, Bing, LinkedIn), jQuery, WordPress (Web Analytics, plugins), Pinterest, UNPKG, TikTok, and Hotjar.
During the operation of corporate web applications, there is an average connection to nearly 50 external services (as a rule, the used third-party scripts send data to external hosts, for instance, Google Analytics sends statistics to servers Google). Among the most popular external services that are connected to are: Google (Analytics, Ads), Microsoft (Clarity, Bing, LinkedIn), Meta (Facebook Pixel), Hotjar, Kaspersky, Sentry, Criteo, tawk.to, OneTrust, New Relic, and PayPal.
Source: opennet.ru
