Market & Threat Landscape

DDoS Is Growing Faster
Than Most Security Budgets.

Analyst coverage puts the DDoS protection market on an 14–18% annual growth path through the early 2030s — faster than most enterprise IT budgets grow. Here's what's driving that, what a DDoS attack actually is, and why a standard firewall — including Neurowall's own L3/L4 firewall — isn't the layer that stops one.

Global DDoS protection market size (Straits Research) $5.5B 2025 $9.0B 2028 $14.8B 2031 $24.4B 2034 // market outlook · cloudarmour.io
The Largest DDoS Attack of All Time

29.7 Tbps —
and mitigated automatically.

In Q3 2025, Cloudflare mitigated the largest DDoS attack ever reported — a scale that would have been unthinkable a decade ago, and one that keeps getting broken.

29.7 Tbps

Attributed to the Aisuru botnet, estimated at 1–4 million infected hosts globally. Cloudflare's network automatically mitigated the attack despite its unprecedented size — in previous decades, DDoS attacks had rarely exceeded 1–2 Tbps. The jump from "rare to see over 1–2 Tbps" to "a single attack over 29 Tbps" in under ten years is the whole story of why DDoS defense keeps needing to scale.

Famous DDoS Attacks

A 25-year history,
from gigabits to terabits.

The trend line matters more than any single record, since it keeps getting broken. Each entry below reflects a real, publicly documented incident.

2000
Mafiaboy
A 15-year-old known online as "Mafiaboy" (later identified as Michael Calce) knocked CNN, Dell, E-Trade, eBay, and Yahoo! — then the world's most popular search engine — offline, coordinating the attack from compromised university networks. The fallout directly led to the creation of many of today's cyber crime laws.
2007
Estonia
A sustained DDoS campaign hit Estonian government services, banks, and media — a serious blow to a country that was an early adopter of paperless, fully online government (including elections). Widely considered the first act of cyber warfare, it followed a political dispute with Russia over relocating a Soviet-era war memorial in Tallinn.
2013
300 Gbps
Anti-spam organization Spamhaus — which filters up to 80% of global spam — was hit at 300 Gbps. Cloudflare's mitigation held; the attackers then went after internet exchanges and bandwidth providers trying to bring Cloudflare down instead, causing major disruption at LINX (the London Internet Exchange). The attack was ultimately traced to a UK teenager hired to carry it out.
2015
GitHub
A politically motivated, multi-day attack injected malicious JavaScript into visitors of Baidu (China's largest search engine) via an intermediary service, turning ordinary browsers into an unwitting botnet aimed at two specific GitHub project pages built to circumvent Chinese state censorship. The attack adapted around GitHub's mitigation as it evolved.
2016
Mirai / Dyn
A Mirai-botnet attack on DNS provider Dyn knocked major sites offline for hours — Airbnb, Netflix, PayPal, Visa, Amazon, The New York Times, Reddit, and GitHub. Mirai compromised huge numbers of insecure IoT devices (cameras, smart TVs, DVRs, even baby monitors) into a botnet. Dyn resolved it within a day; the motive was never confirmed.
2017
2.54 Tbps
Google Cloud infrastructure was hit at 2.54 Tbps (disclosed by Google in 2020) — attackers spoofed packets to 180,000 web servers, which then flooded Google with responses. Part of a sustained campaign of attacks against Google's infrastructure over the prior six months.
2018
1.3 Tbps
GitHub was hit with a Memcached-amplification attack reaching 1.3 Tbps at 126.9 million packets/sec — abusing exposed Memcached caching servers for roughly 50,000x traffic amplification, no botnet required. GitHub's DDoS protection alerted within 10 minutes; the attack lasted about 20 minutes total.
2020
2.3 Tbps
AWS reported mitigating a 2.3 Tbps attack — the target customer was never disclosed. Attackers used hijacked CLDAP (Connection-less LDAP) directory servers, a protocol repeatedly abused for amplification attacks in recent years.
2021
3.47 Tbps
Azure mitigated what was then the largest DDoS attack ever recorded, at 3.47 Tbps from roughly 10,000 sources across at least 10 countries. Microsoft also mitigated two further attacks that year exceeding 2.5 Tbps each.
2022
46M RPS
A Google Cloud customer was targeted with HTTPS request-rate floods peaking at 46 million requests/sec, originating from more than 5,000 sources across 130+ countries — a shift toward request-rate attacks distributed globally rather than concentrated volumetric floods.
2023
201M–398M RPS
In August, Cloudflare mitigated thousands of hyper-volumetric HTTP attacks, 89 of which exceeded 100 million RPS — the largest at 201 million RPS, 3x the prior record (71M RPS, Feb 2023). In October, Google mitigated the largest DDoS ever at that point: a 398 million RPS "HTTP/2 Rapid Reset" attack, exploiting a protocol flaw where attackers flood a site with requests and immediately cancel them, repeated at massive scale.
2025
29.7 Tbps
Cloudflare mitigated the largest DDoS attack reported to date, attributed to the Aisuru botnet (an estimated 1–4 million infected hosts) — see above.

Source: Cloudflare — Famous DDoS Attacks. Figures are as publicly reported by the mitigating parties at the time; attack scale records are broken frequently and should be read as illustrative of trend, not a definitive all-time ranking.

Can Anyone Actually Stop Attacks This Size?

Network capacity decides
whether mitigation is even possible.

Whether a DDoS protection vendor can absorb an attack like the ones above comes down to one thing: does their network have more capacity than the attack generates? Cloudflare, for example, cites 321+ Tbps of network capacity — comfortably ahead of the largest attacks recorded. Cloudflare has also mitigated attacks with extreme packet rates (754 million packets/sec in June 2020) and extreme request rates (201M+ RPS in August 2023), plus HTTP/2 Rapid Reset specifically.

Most attacks are much smaller than the records

The vast majority of real-world DDoS attacks don't exceed 1 Gbps — nowhere near the terabit-scale headlines above. But even a small, unmitigated attack can take a site or application offline for extended periods if no DDoS defense is in place at all.

Why this matters for on-prem and gateway deployments

The upstream-capacity question (does the mitigating network out-scale the attack) is exactly the layer Neurowall is designed to complement, not replace — see where Neurowall fits below for the host/resource-exhaustion class of attack it's built to stop directly.

What Is a DDoS Attack?

Not one attack —
a category of them.

A Distributed Denial-of-Service (DDoS) attack floods a target with traffic from many sources at once, aiming to exhaust a resource — bandwidth, connection state, CPU, or application capacity — so legitimate users can't get through. "Distributed" is the key word: traffic arrives from thousands of hosts simultaneously, which is what makes source-IP blocking alone an incomplete defense.

Volumetric attacks
Saturate available bandwidth with sheer traffic volume — UDP floods, ICMP floods, DNS/NTP amplification. Measured in Gbps.
Protocol attacks
Exhaust connection-handling resources rather than bandwidth — SYN floods, ACK floods, RST floods, fragmented-packet attacks. Measured in packets per second (PPS).
Application-layer attacks
Target application logic directly — HTTP floods, slow-request attacks — consuming far less bandwidth but requiring far fewer resources to launch than a volumetric attack.
Attack Coverage

Seven attack patterns.
A dedicated answer for each.

Neurowall doesn't rely on one generic flood filter. Each attack shape gets its own detection logic, running at the XDP layer before the packet reaches connection state or application code.

Market Growth

Two independent analysts,
the same direction.

Market-size estimates vary by methodology and scope, but every major analyst agrees on the direction and the driver: attack frequency and sophistication are outpacing organic IT security spend.

Straits Research
$5.5B → $24.4B

2025 to 2034 forecast, 18.0% CAGR (2026–2034). North America holds 38.2% share in 2025; Asia-Pacific is the fastest-growing region.

View report
Expert Market Research
$4.6B → $16.8B

2025 to 2035 forecast, 13.9% CAGR (2026–2035). Software-based solutions are the strongest-growing offering segment.

View report
Grand View Research
$3.8B → $20.3B

2021 actual to 2033 forecast, 18.7% CAGR (2025–2033). North America leads regional growth momentum; Asia Pacific and MEA close behind.

View report
Source Base Year Base Size Forecast Year Forecast Size CAGR
Straits Research 2025 $5.5B 2034 $24.4B 18.0%
Expert Market Research 2025 $4.6B 2035 $16.8B 13.9%
Grand View Research 2021 $3.8B 2033 $20.3B 18.7%

Figures from Straits Research and Expert Market Research, plus Grand View Research's independent coverage. Different firms, different methodologies, different forecast windows — shown together to illustrate directional agreement (double-digit CAGR, sustained growth through the early 2030s), not to imply a single reconciled figure.

Straits Research — DDoS Protection Market Size, 2022–2034 (USD Billion)
$3.34B 2022 $3.95B 2023 $4.66B 2024 $5.50B 2025 $6.49B 2026 $7.66B 2027 $9.04B 2028 $10.67B 2029 $12.59B 2030 $14.85B 2031 $17.53B 2032 $20.69B 2033 $24.41B 2034
Source: Straits Research — Company Publications & Primary Interviews
Grand View Research — Market Size by Component, 2023–2033 (USD Billion)
$4.3B 2023 $4.7B 2024 $5.2B 2025 $5.6B 2026 $6.2B 2027 $7.2B 2028 $8.5B 2029 $10.5B 2030 $13.2B 2031 $16.5B 2032 $20.3B 2033
Services
Software
Hardware
Source: Grand View Research — segment values approximated from published chart proportions; total market size figures ($4.3B–$20.3B) as reported. CAGR 2025–2033: 18.7%
Cross-Report Agreement

Three methodologies.
The same conclusion.

Double-digit growth, every time

CAGR ranges from 13.9% (Expert Market Research) to 18.7% (Grand View Research) — no report puts growth in single digits.

Roughly 4–5x larger within a decade

Every forecast puts the market at 4 to 5 times its current size by the early-to-mid 2030s, regardless of the base year used.

Cloud and software lead the shift

Cloud-delivered and software-based protection are called out as the fastest-growing segments across all three reports — on-prem appliance spend is the slower-growing category.

North America leads, Asia-Pacific accelerates

North America holds the largest current share (regulatory drivers), while Asia-Pacific is consistently flagged as the fastest-growing region.

What's Driving Growth

The same forces analysts
keep citing.

Attack frequency is climbing fast

NETSCOUT recorded roughly 10 million DDoS attacks globally in 2022. India's CERT-In reported a 668% year-over-year increase in DDoS attacks the same year. Check Point Research found a 50% jump in attacks against healthcare specifically.

IoT keeps expanding the attack surface

Every new connected device is a potential botnet node. Analysts consistently name IoT proliferation as a structural driver, not a one-time spike.

Cloud migration changes the exposure model

Workloads moving to cloud and hybrid environments are directly internet-reachable in ways on-prem, perimeter-walled infrastructure wasn't — cloud deployment is the largest and fastest-growing segment in both reports.

Regulation is pulling budget forward

North America's lead share is tied partly to compliance mandates (HIPAA, CCPA) that push regulated industries — BFSI and healthcare especially — to formalize DDoS protection spend rather than treat it as discretionary.

Why a Firewall Alone Isn't Enough

No firewall stops DDoS
by being a firewall.

This applies to Neurowall's own L3/L4 firewall too, and it's worth being direct about why: a stateful firewall's job is to evaluate connections against policy — allow, deny, track state. That's a per-connection decision. A DDoS attack isn't a policy violation on any single connection; it's volume and rate across thousands of them at once. Stopping it requires dedicated flood detection and rate-limiting logic sitting in front of — or alongside — the firewall path, not the firewall rule engine itself.

Firewall Rule Engine Alone
evaluates each connection against policy
100K legitimate-looking SYNs/sec, each individually policy-compliant
Backlog exhausted — service degrades
no policy was ever violated

This is exactly why Neurowall ships DDoS protection as a distinct module set — token-bucket rate limiting plus SYN, ACK, ICMP, FIN, RST, and UDP-cost-specific flood detection — that runs at the XDP layer, ahead of and alongside firewall policy evaluation, not inside it.

Firewall ≠ DDoS Protection

A firewall answers "is this connection allowed?" DDoS protection answers "is this rate of allowed-looking traffic itself the attack?" They're different questions, and most gateway firewalls — commercial or open-source — don't ship an answer to the second one.

Where Neurowall Fits

Built for the flood conditions
the market is scaling toward.

Neurowall's DDoS protection runs at the XDP layer — the Linux network driver, before the kernel allocates memory for a packet. Malicious traffic is dropped before it costs anything downstream, while firewall policy and threat intelligence continue evaluating the traffic that's actually allowed through.

7
Dedicated DDoS protection modules — rate limiting, SYN, ACK, ICMP, FIN, RST, UDP cost filter
~96KPPS
SYN flood sustained with 375,000 policies loaded, system remained responsive
~83KPPS
ICMP flood sustained under the same 375,000-policy configuration
12Gbps
XDP + DDoS protection + 10,000 rules — no measured throughput drop versus firewall-only

Benchmarks measured on Neurowall's own test infrastructure — see the full benchmark summary for methodology. These figures reflect host/network-resource exhaustion scenarios (traffic that has reached the box), not upstream link-saturation attacks that fill a constrained internet connection before reaching any on-box mitigation — that class of attack needs ISP- or cloud-scrubbing capacity upstream, and Neurowall is designed to complement that layer, not replace it.

Get started

Growing into a market that's growing faster than you are?