
Web application attack activity While the number of web application attacks increased by 28% over the last quarter, the percentage of web application attacks sent over HTTP vs. HTTPS has remained relatively consistent for two quarters - 89% via HTTP in Q4 vs. 88% via HTTP in Q3.
The most frequently observed attack vectors for the quarter were LFI (41%), SQLi (28%) and PHPi (22%), followed by XSS (5%) and Shellshock (2%). RFI, MFU, CMDi, and JAVAi attacks comprised the remaining 2%. The relative distribution of the attack vectors over HTTP vs. HTTPS was similar, with the exception of PHPi; PHPi was seen in just 1% of the attacks over HTTPS.
Fifty-nine percent of the Q4 web application attacks targeted retailers, vs. 55% in Q3. The media & entertainment and hotel & travel industries were the next most frequently targeted, with 10% of the attacks each. This represents a change from Q3, when the financial services industry was the second most-targeted industry (15% of attacks), compared with just 7% of the attacks this quarter.
Continuing a trend from last quarter, the US was both the main source of web application attacks (56%) as well as the most frequent target (77%). Brazil was the next biggest attack source (6%) as well as the second most targeted country (7%), which seems to be related to the fact that a large cloud Infrastructure-as-a-Service (IaaS) provider opened new data centers there. Since the opening of the data centers, Akamai has seen a large increase in the amount of malicious traffic coming out of Brazil, and specifically from the aforementioned data centers. Most of those attacks were against a Brazilian customer in the retail industry.
For the Q4 report, we identified the top 10 sources of web application attack traffic by ASN, and analyzed the corresponding attack types, payloads and frequency. A description of 10 of the more interesting attacks - and their payloads, is included in Section 3.6.
Web application attack metrics
Compared with Q3 2015
28.10% increase in total web application attacks
28.65% increase in web application attacks over HTTP
24.05% increase in web application attacks over HTTPS
12.19% increase in SQLi attacks
Scanning and probing activity Malicious actors rely on scanners and probing to perform reconnaissance on their targets before launching attacks. Using firewall data from the perimeter of the Akamai Intelligent Platform, our analysis showed the most popular ports for reconnaissance were Telnet (24%), NetBIOS (5%), MS-DS (7%), SSH (6%), and SIP (4%). The top three sources of scanning activity were all located in Asia, as determined by ASN. We also saw active scanning for reflectors to abuse, including NTP, SNMP, and SSDP.
By looking at the top reflection sources by ASN, we saw that the most heavily-abused network reflectors were in China and other Asian countries. While most SSDP attacks tend to be from home connections, NTP, CHARGEN, and QOTD are generally from cloud hosting providers where those services run. SSDP and NTP reflectors were the most often abused reflectors at 41% each, followed by CHARGEN (6%) and RPC (5%). SENTINEL and QOTD followed at 4% each.
Download the report A complimentary copy of the Q4 2015 State of the Internet - Security Report is available for download at www.stateoftheinternet.com/security-report.
About stateoftheinternet.com Akamai's stateoftheinternet.com shares content and information intended to provide an informed view into online connectivity and cybersecurity trends as well as related metrics, including Internet connection speeds, broadband adoption, mobile usage, outages, and cyber-attacks and threats. Visitors to stateoftheinternet.com can find current and archived versions of Akamai's State of the Internet (Connectivity and Security) reports, the company's data visualizations and other resources designed to help put context around the ever changing Internet landscape.
About Akamai As the global leader in Content Delivery Network (CDN) services, Akamai makes the Internet fast, reliable and secure for its customers. The companys advanced web performance, mobile performance, cloud security and media delivery solutions are revolutionizing how businesses optimize consumer, enterprise and entertainment experiences for any device, anywhere. To learn how Akamai solutions and its team of Internet experts are helping businesses move faster forward, please visit www.akamai.com or blogs.akamai.com, and follow @Akamai on Twitter.
Most recent headlines
05/01/2027
Worlds first 802.15.4ab-UWB chip verified by Calterah and Rohde & Schwarz to be ...
04/08/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
04/07/2026
April 7 2026, 19:00 (PDT) Detective Conan: Fallen Angel of the Highway Opens in...
01/06/2026
January 6 2026, 05:30 (PST) Dolby Sets the New Standard for Premium Entertainment at CES 2026
Throughout the week, Dolby brings to life the latest innovatio...
02/05/2026
(L-R) Dustin Hoffman and Leo Woodall appear in Tuner by Daniel Roher, an official selection of the 2026 Sundance Film Festival. (Photo courtesy of Sundance In...
02/05/2026
Versatile re-amping tool announced
Warm Audio are best known for their recreations of sought-after vintage studio gear, but their latest release brings a ne...
02/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
02/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
02/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
02/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
02/05/2026
Scripps Research immunologist Dennis Burton elected to American Academy of Arts and Sciences A leader in broadly neutralizing antibodies, Burton has helped driv...
02/05/2026
Dalet, a leading technology and service provider for media-rich organizations, t...
01/05/2026
Ratings Roundup is a rundown of recent rating news and is derived from press rel...
01/05/2026
BKB Bare Knuckle Boxing ( BKB ), today announced the appointment of Will Wright ...
01/05/2026
Lawo has been at the center of the industry's transition to IP and other next-generation technologies. At NAB 2026, its story was the Edge One AV stagebox, ...
01/05/2026
HBA Media, acting on behalf of NBC Sports and Churchill Downs Incorporated, has announced broadcast and streaming distribution for Kentucky Derby 152, taking pl...
01/05/2026
By Bailey Pennick
One of the most exciting things about the Sundance Film Festi...
01/05/2026
Florals for spring? Groundbreaking. But a playlist that tells you which The Devi...
01/05/2026
One of the world's biggest popstars is headed to El Cl sico. Later this mont...
01/05/2026
Limited-edition model celebrates 15th anniversary
Heritage Audio's range of monitor controllers has just gained a new member, the Baby RAM Black Edition...
01/05/2026
Dumble recreation now available as UAD plug-in
Along with their renowned processing plug-ins, Universal Audio have been steadily introducing emulations of c...
01/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
01/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
01/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
01/05/2026
To celebrate the opening of its new showroom and office, Lightware UK hosted a dedicated launch event at the new London location. The event welcomed partners, c...
01/05/2026
Choice without compromise
The broadcast industrys transformation is accelerating, and traditional broadcasters are having to fundamentally reinvent how they o...
01/05/2026
Beam Dynamics will return to MPTS 2026 with its asset intelligence platform, helping systems integrators, live production teams, media facilities and profession...
01/05/2026
Best-in-class UX design and rapid, scalable delivery for next-generation viewing experiences
Leading video software provider, Synamedia, today announced a coll...
01/05/2026
Compact new cforce MAX lens motor brings unrivaled speed and responsiveness to t...
01/05/2026
Panavision welcomes Fritz Heinzle as Vice President of Sales
Brie Clayton May 1, 2026
0 Comments
Heinzle will support Panavision's global growth s...
01/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
01/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
01/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
01/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
01/05/2026
Share
Copy link
Facebook
X
Linkedin
Bluesky
Email...
01/05/2026
LONDON, APRIL 30, 2026 The Post Republic London's Re-recording Mixer and Dialogue Editor Dan Johnson has built a reputation for clean, emotionally resonan...
01/05/2026
Adobe Unveils Powerful New Innovations in Photoshop & Lightroom
Deepa Subramaniam April 30, 2026
0 Comments
Your most tedious creative tasks just got ea...
01/05/2026
Berklee Partners with Santander US to Establish Global Opportunity Fund The $400,000 grant offers students access to experiential learning opportunities withi...
01/05/2026
Student Spotlight: Keziah Thomas The Indian composer, who was named the 2026 student commencement speaker for Berklee College of Music, talks about how shes p...
01/05/2026
Friday 1 May 2026
Hannah Waddingham and Ncuti Gatwa to host the series final tw...
01/05/2026
Friday 1 May 2026
Got plans? Cancel them. Sky Sports Big Weekend is coming
Sky Sports is preparing for a bumper weekend of live action, including Manchester ...
01/05/2026
Friday 1 May 2026
Sky Sports to broadcast all matches from World Sevens Football London edition
Sky Sports will be the exclusive UK broadcaster of the women...
01/05/2026
Back to All News
NIAJ Fest Gets Los Angeles In on the Joke With Free Pop-Up Events
Entertainment
01 May 2026
GlobalUnited States
Link copied to clipboard
...
01/05/2026
RT Sport awarded first pick free-to-air on Wednesday nights
Champions League and Super Cup finals
Highlights on Wednesday nights
RT today (Thursday 30 Apri...
01/05/2026
January 5 2026, 18:30 (PST) NBCUniversal's Peacock to Be First Streamer to ...
30/04/2026
The Professional Women's Hockey League (PWHL) concluded its third regular season on Saturday, reporting growth across attendance, viewership, digital engage...
30/04/2026
NBC Sports will air national MLB coverage on Sundays beginning May 3, with MLB Sunday Leadoff on Peacock and NBCSN at 12:30 p.m. ET, followed by the debut of th...
30/04/2026
Clear-Com has appointed Brian Grahn as Market Outreach Manager of the Americas and Ben Turnwell as Business Development Manager for EMEA live.
Grahn joined Cle...
30/04/2026
ARRI has introduced the cforce MAX, a new lens motor for the Hi-5 lens control system. The cforce MAX is twice as fast as the cforce plus motor it replaces whil...
30/04/2026
Knuerr, Voxtronic, and IHSE will jointly present an integrated control room solu...