NaWas
NaWas is a collective 24/7 DDoS mitigation service for providers of digital infrastructure and services. The service’s non-profit structure enables providers of all sizes to protect themselves against DDoS attacks at a relatively low cost.
Furthermore, the NaWas infrastructure has been further optimised and its capacity expanded. Following a successful beta phase, Splitflow 2.0 (sFlow) was launched at the end of 2025 as an add-on for participants. With Splitflow 2.0, participants can track the progress of the attack, know when it has ended, and gain improved insights. A GRE tunnel has also been added to NaWas as an add-on. This is particularly relevant for providers such as VoIP providers that are not connected to an internet exchange. They now have an alternative for receiving clean traffic back from NaWas during a DDoS attack.
Figures NaWas 2025
Top 5 attacks in 2025
HTTP Flooding
DNS Amplification
DNS Request Flood
TCP SYN Flooding
Malform TCP with port 0
Number of attacks per year
DDoS Trends 2025
Increase in prolonged attacks, spread over several days
A key trend in 2025 was that an increasing number of attacks were of a longer duration. In some cases, these attacks were spread over several days and involved multiple hosts within the same network. This involved a type of attack known as a ‘carpet bomb’. In ‘carpet bombing’, attacks are carried out on multiple IP addresses rather than a single IP address. These attacks often have a ‘low-and-wide’ effect. At first glance, it appears that a single IP address can handle the data traffic, as the limit (e.g. 20 Mbps) is not exceeded at the individual level. However, when the entire network is factored into the total, it can still be severely impacted. Awareness of this type of attack is particularly important for organisations with a public infrastructure and a large footprint. This is because such attacks can cause prolonged operational pressure.
More attacks that resemble normal traffic
In 2025, NaWas mitigated a greater number of attacks that resembled the normal traffic of the service targeted by the attacks. One example of this was UDP traffic passing through SIP gateways, which closely resembled expected telephone signalling. DDoS attackers adapt their methods accordingly by blending in with expected telephony signalling. This makes detection and filtering more difficult for providers offering real-time communication services or other specialised, internet-focused services.
Web applications remain the most targeted attack vector, with an increase in HTTP/3 and QUIC attacksHTTP/3 QUIC
Web applications remain the most targeted attack vector for attackers. Furthermore, HTTP request flooding remains the most used attack vector in 2025. There was also an increase in attacks on HTTP/3, based on the QUIC protocol, in 2025. Attackers are targeting the application layer (layer 7) and keeping pace with the modern protocols used by websites, APIs and digital platforms.