CERT Report May 2024

CERT Report May 2024

01. MONTHLY ATTACK TRENDS THROUGH STATISTICS

Attack Type Statistics

 

Attack type statistics lets you access statistical information on the top 9 attack types that occurred in the previous month, including the progression of each attack in terms of increase and decrease, as well as attack progression by industry sector and country.

 

Monthly Attack Type Statistics

 

According to the attack type statistics compiled for April, the total number of detections increased by 21,677 cases compared to the previous month, totaling 478,731 cases. The most frequently attempted Inject Unexpected Items attacks numbered 230,635, showing a 14,026 increase from the previous month and accounting for 48.2% of the overall attack type distribution for April. Collect and Analyze Information attacks ranked 2nd with 171,123 cases, Subvert Access Control attacks ranked 3rd with 37,206 cases, Manipulate Data Structures attacks ranked 4th with 30,286 cases, Employ Probabilistic Techniques attacks ranked 7th with 1,232 cases, Engage in Deceptive Interactions attacks ranked 8th with 21 cases, and Manipulate Timing State attacks ranked 9th with 0 cases, all maintaining the same rankings as the previous month. Manipulate System Resources attacks saw a 1-rank increase to 5th place with 6,907 cases. On the other hand, Abuse Existing Functionality attacks saw a 1-rank decrease to 6th place with 1,321 cases.


Figure 1. The attack type ratio in April

 


Figure 2. The percentage of attack types in the past 12 months
 

Rank Attack Type Fluctuation March April

12 Months 

Percentage

Count Ratio Count Ratio
1 Inject Unexpected Items 216,609 47.4% 230,635 48.2% 33.7%
2 Collect and Analyze Information 166,450 36.4% 171,123 35.7% 48.5%
3 Subvert Access Control 30,798 6.7% 37,206 7.8% 7.5%
4 Manipulate Data Structures 29,940 6.6% 30,286 6.3% 7.6%
5 Manipulate System Resources ▲1 5,954 1.3% 6,907 1.4% 1.0%
6 Abuse Existing Functionality ▼1 6,214 1.4% 1,321 0.3% 1.3%
7 Employ Probabilistic Techniques 1,054 0.2% 1,232 0.3% 0.3%
8 Engage in Deceptive Interactions 35 0.0% 21 0.0% 0.0%
9 Manipulate Timing State 0 0.0% 0 0.0% 0.0%
Total 457,054 100% 478,731 100% 100%

Table 1. The attack type statistics in April

※ Analytical events are categorized into 9 attack types based on attack patterns

※ The total ratio is calculated by rounding

 

The progression of attack types over the past 3 months is as follows. 

 


Figure 3. The trend of attack types in the last 3 months

 

 

IP

106[.]75[.]175[.]181
111[.]20[.]157[.]186
112[.]223[.]97[.]51
114[.]108[.]165[.]173
117[.]115[.]248[.]17