Core Insights - The report highlights a significant increase in web attacks, with 311 billion attacks recorded in 2024, marking a 33% year-over-year rise [1] - The surge in attacks is linked to the rapid adoption of AI applications, which expand attack surfaces and introduce new security challenges [1][2] - APIs have become primary targets, with 150 billion API attacks documented from January 2023 to December 2024, driven by the integration of AI tools [2] Attack Trends - There has been a dramatic rise in Layer 7 DDoS attacks, with quarterly attack volumes increasing by 94% year-over-year from Q1 2023 to Q4 2024 [3] - Monthly DDoS attack numbers rose from 500 billion in early 2023 to 1.1 trillion by December 2024, attributed to sophisticated bot-driven attacks and HTTPS flooding [3] - The high technology sector experienced 7 trillion Layer 7 DDoS attacks from January 2023 to December 2024, making it the most affected industry [6] Security Vulnerabilities - The report indicates that OWASP API Security Top 10-related incidents increased by 32%, highlighting authentication and authorization flaws [6] - Security alerts related to the MITRE security framework have risen by 30%, as attackers utilize advanced techniques like automation and AI to exploit APIs [6] - Shadow and zombie APIs are identified as particularly vulnerable attack vectors within complex API ecosystems [6] Recommendations and Insights - The report includes recommended mitigation strategies and unique insights on risk scoring and technical methods to assist frontline defenders [4] - Akamai emphasizes the importance of understanding the evolving landscape of web and API security, driven by AI advancements [5]
Akamai Research: Web Attacks Up 33%, APIs Emerge as Primary Targets