Attacks Moved From Bandwidth To Application Behaviour
Filling a pipe is expensive for an attacker and increasingly futile against scrubbing networks built for it, while exhausting a database connection pool costs almost nothing and works. Around 71% of outages now come from request floods that arrive at ordinary volumes and look like legitimate traffic. Defence requires behavioural modelling of what normal application use looks like, which is closer to fraud detection than to packet filtering. Providers whose capability was built around capacity are having to acquire or rebuild an entirely different technical discipline to stay relevant. Capacity heritage helps very little here.
Market Impact: Involves 34% of contracts








